mdr and ivdr

Beyond MDR and IVDR: 6 Critical Regulations Shaping Medical Device Compliance

Introduction

Medical Device Compliance in the European Union goes beyond MDR and IVDR. Manufacturers must assess the complete regulatory environment that applies to their product, including requirements related to artificial intelligence, radio equipment, data protection, batteries, hazardous substances, and electronic waste.

Regulation (EU) 2017/745 (MDR) has applied to medical devices since 26 May 2021, while Regulation (EU) 2017/746 (IVDR) has applied to in vitro diagnostic medical devices since 26 May 2022. These regulations establish the core framework for safety, performance, clinical evidence, conformity assessment, and post-market obligations.

However, a connected, software-enabled, battery-powered, or electrically operated medical device may also be subject to other EU legislation.

Ready to Simplify MDR and IVDR Compliance?

Is MDR and IVDR compliance enough?

No. MDR and IVDR may not cover every regulatory obligation applicable to a medical device. Depending on the device’s technology, intended purpose, components, connectivity, materials, and data processing activities, manufacturers may also need to assess legislation such as the EU AI Act, Radio Equipment Directive, GDPR, Batteries Regulation, RoHS, REACH, and WEEE.

This article explains six important areas manufacturers should consider when developing a comprehensive Medical Device Compliance strategy.

What Are MDR and IVDR?

The Medical Device Regulation (MDR 2017/745) establishes requirements for medical devices placed on the EU market, including classification, technical documentation, clinical evaluation, conformity assessment, post-market surveillance, and responsibilities of economic operators.

The In Vitro Diagnostic Medical Device Regulation (IVDR 2017/746) applies specifically to IVDs and introduced a risk-based classification system, stronger performance evaluation requirements, and greater involvement of notified bodies.

MDR and IVDR therefore form the foundation of EU medical device regulation—but they may need to be considered alongside other EU laws.

1. EU AI Act – Important for AI-Enabled Medical Devices

Why Does the EU AI Act Matter for Medical Devices?

Medical devices incorporating artificial intelligence or machine-learning functionality may need to comply with requirements under the EU AI Act (Regulation (EU) 2024/1689) in addition to applicable MDR or IVDR requirements.

The key issue is that AI-related obligations do not simply disappear because the software is already regulated as a medical device.

Manufacturers should assess:

  • Whether the product contains an AI system
  • The role of AI within the medical device
  • Applicable AI risk classification
  • Data governance requirements
  • Technical documentation
  • Transparency obligations
  • Human oversight
  • Accuracy, robustness, and cybersecurity considerations

2. Radio Equipment Directive (RED) – For Wireless Medical Devices

When Does RED Apply to Medical Devices?

Medical devices containing wireless communication functionality may require assessment under the Radio Equipment Directive (2014/53/EU) in addition to applicable medical-device requirements.

Examples can include:

  • Bluetooth-enabled patient monitors
  • Wi-Fi-connected medical devices
  • Wireless wearable devices
  • Connected diagnostic equipment
  • Remote monitoring systems

 

Manufacturers should evaluate requirements related to:

  • Radio spectrum
  • Electromagnetic compatibility
  • Electrical safety
  • Wireless performance
  • Cybersecurity-related requirements applicable to radio equipment
  • User information and labeling

Identify Hidden EU Regulatory Requirements Before Market Entry

Get Your Medical Device Compliance Assessment.

3. GDPR – Data Protection for Connected Medical Devices

Does GDPR Apply to Medical Devices?

GDPR can apply when a medical device or its associated software processes personal data. Connected medical devices can collect significant amounts of information, including:

  • Patient identification information
  • Health information
  • Diagnostic results
  • Physiological measurements
  • Remote monitoring data

 

Manufacturers and other organizations involved in processing this data should assess applicable GDPR obligations.

Key considerations may include:

  • Lawful processing
  • Data minimization
  • Data security
  • Privacy by design and by default
  • Data subject rights
  • Data retention
  • Data processing agreements
  • Cross-border data transfers

4. EU Batteries Regulation – For Battery-Powered Medical Devices

What Is the EU Batteries Regulation?

The EU Batteries Regulation (EU) 2023/1542 establishes requirements concerning battery sustainability, safety, labeling, marking, information, producer responsibility, and waste-battery management. It has applied since 18 February 2024, subject to specific provisions and implementation dates.

This is particularly relevant to manufacturers whose products contain:

  • Rechargeable batteries
  • Portable batteries
  • Battery-powered accessories
  • Connected medical equipment

The regulation includes specific provisions relevant to professional medical imaging and radiotherapy equipment, including exceptions concerning battery removability and replaceability in certain circumstances.

Compliance Considerations

Manufacturers should assess:

  • Battery type and chemistry
  • Labeling requirements
  • Safety requirements
  • Sustainability obligations
  • Producer responsibilities
  • Battery removability or replaceability requirements where applicable
  • Waste management obligations

Battery compliance should therefore be considered during product design rather than treated as a final-stage documentation activity.

5. RoHS and REACH – Chemical and Material Compliance

Why Are RoHS and REACH Important?

Medical device manufacturers must also evaluate environmental and chemical requirements applicable to the materials and components used in their products.

RoHS

The Restriction of Hazardous Substances (RoHS) Directive 2011/65/EU restricts specified hazardous substances in electrical and electronic equipment. RoHS applies to medical devices and certain related equipment within its scope.

REACH

REACH (Regulation (EC) No 1907/2006) addresses the registration, evaluation, authorization, and restriction of chemicals in the EU.

Manufacturers should therefore evaluate:

  • Plastics
  • Metals
  • Electronic components
  • Cables
  • Coatings
  • Adhesives
  • Batteries
  • Other substances and materials

 

Important Point

Biocompatibility compliance does not automatically mean environmental or chemical compliance.

6. WEEE – Electrical and Electronic Equipment Waste

What Is WEEE Compliance?

The Waste Electrical and Electronic Equipment (WEEE) Directive 2012/19/EU establishes requirements concerning the collection, treatment, recovery, and disposal of waste electrical and electronic equipment.

For applicable medical electrical and electronic equipment, manufacturers should assess their responsibilities regarding:

  • Product marking
  • Producer registration
  • Collection systems
  • Waste treatment
  • Reporting
  • End-of-life management

Certain products and applications may have specific exclusions or exemptions, so applicability should be assessed based on the product and intended use.

MDR and IVDR vs Other EU Regulations: What Is the Difference?

Important: Applicability depends on the specific product, its intended purpose, technology, components, and market role. Manufacturers should not assume that every regulation listed above applies to every medical device.

How Should Manufacturers Build a Medical Device Compliance Strategy?

A comprehensive Medical Device Compliance strategy should begin during product development.

Step 1: Define the Intended Purpose

Clearly document what the device is designed to do, who will use it, and the intended patient population.

Step 2: Determine MDR or IVDR Applicability

Establish whether the product is a medical device, IVD, accessory, or another regulated product.

Step 3: Determine Device Classification

Apply the relevant MDR or IVDR classification rules based on intended purpose and risk.

Step 4: Identify Additional EU Regulations

Evaluate whether the device also falls within the scope of:

  • EU AI Act
  • RED
  • GDPR
  • Batteries Regulation
  • RoHS
  • REACH
  • WEEE
  • Other applicable EU legislation

 

Step 5: Perform a Regulatory Gap Assessment

Map each applicable requirement against:

  • Product design
  • Technical documentation
  • Risk management
  • Software
  • Clinical evidence
  • Labeling
  • Manufacturing
  • Supply chain
  • Post-market activities

 

Step 6: Maintain Regulatory Traceability

Ensure that requirements, design controls, verification activities, risk controls, and technical documentation remain connected throughout the product lifecycle.

Common Medical Device Compliance Mistakes

Manufacturers frequently encounter compliance problems because they:

1. Focus Only on MDR or IVDR

MDR and IVDR are fundamental, but they may not represent the complete regulatory landscape.

2. Assess Regulations Too Late

Additional requirements should be identified during product design, not immediately before market launch.

3. Ignore Software and Connectivity

Wireless functionality, cloud platforms, AI, and cybersecurity can introduce additional compliance considerations.

4. Treat Materials Only as a Biocompatibility Issue

Materials may also require assessment under RoHS, REACH, Batteries Regulation, or other environmental requirements.

5. Separate Regulatory and Engineering Teams

Regulatory requirements should be integrated with engineering, software, quality, clinical, and supply-chain activities.

Medical Device Compliance Checklist

Before placing a device on the EU market, manufacturers should ask:

  • Is MDR or IVDR applicable?
  • Has the device been correctly classified?
  • Is the intended purpose clearly defined?
  • Is clinical or performance evidence adequate?
  • Is the risk management process complete?
  • Does the product contain AI?
  • Does it have wireless functionality?
  • Does it process personal data?

EUDAMED is now a particularly important part of the EU regulatory landscape, with mandatory use of certain modules beginning on 28 May 2026.

How Operon Strategist Supports Medical Device Compliance

Navigating MDR and IVDR alongside other applicable EU regulations requires coordination across regulatory, quality, engineering, software, clinical, and manufacturing functions. Operon Strategist supports medical device manufacturers with an integrated regulatory approach covering product development through market entry.

Our support includes:

 

By integrating regulatory requirements early, manufacturers can identify compliance gaps before they become costly redesigns, documentation deficiencies, or market-entry delays.

Is Your Medical Device Compliant Beyond MDR and IVDR?

Talk to Our Medical Device Regulatory Experts Today.

FAQ's

No. MDR and IVDR provide the core medical device framework, but additional EU legislation may apply depending on the device’s technology, connectivity, software, materials, batteries, and data processing activities.

Depending on the product, manufacturers may need to consider the EU AI Act, Radio Equipment Directive (RED), GDPR, Batteries Regulation, RoHS, REACH, and WEEE.

Yes, certain AI-enabled medical devices and IVDs may be subject to the EU AI Act in addition to MDR or IVDR requirements. Applicability depends on the AI system and its intended use

GDPR may apply when a medical device, software platform, or associated organization processes personal data, including patient or health information.

RED may apply when a medical device incorporates radio or wireless communication functionality, such as Wi-Fi, Bluetooth, or other radio technologies.