

2023 Regulatory performance report
Today at Rimsys, we unveiled the 2023 MedTech Regulatory Performance Report, a new set of insights into the state of medtech regulatory affairs. Compiled based on interviews with 200 regulatory professionals and executives, the study provides a detailed look into how regulatory teams are staffed, their processes, the tools they use, and ultimately how they perform.
Why did we create this study? There were two driving factors behind the research. The first was a common theme that we heard from a number of our customers: Regulatory leaders don’t have clear data and benchmarks. They don’t necessarily know how long a new market submission should take, and how to plan for or assess the work of their teams. While other studies look at the medtech industry broadly or the state of the regulatory profession, this study tries to build a comprehensive resource for regulatory (and company) leaders.
The second factor was really for ourselves and the team at Rimsys. As a company building solutions specifically for medtech regulatory affairs, we wanted more insight into where companies were successful, where they struggled, and where we can add value.
What did we find? Regulatory teams perform a lot of hero work and rate themselves highly for their accomplishments. At the same time there is a lot of opportunity for process improvements, and companies that invest in digital transformation for regulatory affairs see better performance.
Regulatory professionals are superheroes
Regulatory teams are generally pretty small. Most companies have less than 10 full-time regulatory professionals. These small teams complete an enormous amount of work. Last year on average, RA teams completed 50 license renewals, 50 license updates, and 10 new market submissions. This is impressive output.
Digging a bit under the covers, we found that this output relied heavily on the support of external consultants. 90% of companies use consultants to keep pace with their regulatory workload. Front-line employees also struggle with burnout. They were much more likely to report feeling under-resourced than regulatory leaders.
But process problems persist
A lot of regulatory work remains extremely manual. 70% of regulatory teams spend half their time or more on repetitive administrative tasks. All of this manual work increases the frequency of errors and required rework. 61% of companies reported a major non-compliance incident in the past 2 years.
Manual work also makes it difficult to complete regulatory projects in a timely fashion. Teams completed a lot of projects, but each took a long time. Over half of all companies spend 4 months or more on license renewals, license updates, and new market submissions.
Moving regulatory affairs forward
As regulatory requirements become more complex, there’s a natural question about how teams will work moving forward. MDR & IVDR in Europe have significantly increased the regulatory workload required to bring and keep products on the market. Will organizations be able to keep pace with the same resources, tools, and processes?
No, and the performance report shows that medtech companies are investing to improve their regulatory capabilities. The majority of companies are planning to increase the sizes of their RA teams in 2023, and 40% expect to increase their investments in regulatory software. Companies are increasingly adopting specialized software to better support regulatory processes.
Dig into the survey results
The full survey results provide insights into more aspects of regulatory performance. They show that companies need to take a deeper look into their processes and how regulatory resources are allocated. There are two ways to learn more:
- Visit the survey page to see the full results (the survey whitepaper can be downloaded at no cost)
- Watch the recording of our webinar with PA Consulting. We discuss the survey results in more detail and share our regulatory predictions for 2023

Post-market surveillance for medical devices in the European Union
This article is an excerpt from Post-market surveillance for medical device in the European Union.
Table of Contents
- What is post-market surveillance?
- What classes of medical devices require post-market surveillance?
- Components of a successful post-market surveillance plan
- PMS data requirements
- Post-market surveillance system goals
- Required post-market surveillance reporting
- Embracing post-market surveillance as an integral part of your quality program
- Getting started with post-market surveillance
Post-market surveillance (PMS) is designed to monitor the performance of a marketed medical device by collecting and analyzing field use data. Article 10 of the EU MDR and IVDR requires all device manufacturers to have a post-market surveillance system in place. The main elements of the PMS are laid out in Article 83, and additional details for lower-risk and higher-risk devices are covered in articles 84 and85, respectively.
In general, a PMS system consists of both proactive activities and reactive, or vigilance, activities. While post-market surveillance and vigilance are sometimes used interchangeably, vigilance consists of separate activities that feed post-market surveillance programs.
Post-market surveillance systems are used to collect and analyze data not only about the manufacturer’s device but also about related competitors’ devices that are on the market. Data collected through PMS procedures is then used to identify trends that may lead to, among other things, quality improvements, updates to user training and instructions for use, and identification of manufacturing issues.
Note that “market surveillance” encompasses activities performed by a Competent Authority to verify MDR compliance, and should not be confused with the topic of this ebook,“post-market surveillance," which is performed by the manufacturer.
All medical devices marketed in the EU require some level of post-market surveillance, and all medical device manufacturers must implement a post-market surveillance system (PMS). The requirements of the PMS, however, vary and should be “proportionate to the risk class and appropriate for the type of device” (MDR Chapter VII). In particular, the type and frequency of reporting vary based on a device’s risk class.
A post-market surveillance plan (PMS) is an integral part of a manufacturer’s quality management system and provides a system for compiling and analyzing data that is relevant to product quality, performance, and safety throughout the entire lifetime of a device. The PMS should also provide methods for determining the need for and implementing any preventative and corrective actions. A PMS system should include and define:
Surveillance data sources
With the increased focus on proactive risk identification in the MDR, it is important to design post-market surveillance systems that actively acquire knowledge and detect potential risks. It is not sufficient to rely solely on spontaneous reporting by healthcare providers, patients, and other stakeholders.

In addition to information coming from Clinical Evaluation Reports and complaint and adverse event reporting, typical sources of surveillance data include:
• Social media networks: Because many of your stakeholders may be communicating on social media networks, it is important to employ social listening techniques and/or tools to identify issues and concerning trends as they develop.
• Industry and academic literature: Any studies, academic papers, and other literature that addresses similar devices or the specific use cases for which your device is designed should be evaluated. In particular, risk factors and adverse events identified with similar devices should be closely examined. It is also important to identify newer technologies that may affect the benefit-risk ratio and establish a new definition of “state of the art” for the device type.
• EUDAMED: While the European Database on Medical Devices (EUDAMED) is not yet fully functional, it is intended to provide a living picture of the lifecycle of all medical devices marketed in the EU. Manufacturers should take special care to consider information for similar devices made available through the EUDAMED system in the future.
• Registries: Patient, disease, and device registries can provide information that informs the clinical evaluation process which provides input into the post-market surveillance system.
Data analysis methodology
A well-defined data analysis methodology will accurately identify trends and lead to defendable decisions in the application of post-market experience. Once the necessary information has been identified and collected, and potentially cleaned of incomplete or otherwise unusable data, the data needs to be analyzed.
The goal is to identify meaningful trends, correlations, variations, and patterns that can lead to improvements in the safety and efficacy of the device. There are many data analysis tools available that can assist with:
• Regression analysis that will identify correlations between data (e.g. the device location/geography correlates to battery life).
• Data visualization that can be useful in spotting trends in the data.
• Predictive analytics, which can be particularly useful with large data sets, to identify future trends based on historical data.
• Data mining, which is also normally used with large datasets, to organize data and identify data groups for further analysis.
Benefit-risk indicators and thresholds
The MDR requires that medical device manufacturers not only demonstrate the clinical benefit of their device but also quantify the benefit-risk ratio. The benefit of a device must be shown to clearly outweigh the risk for it to gain market approval. Article 2 (24) of the MDR defines the benefit-risk determination as “the analysis of all assessments of benefit and risk of possible relevance for the use of the device for the intended purpose when used in accordance with the intended purpose given by the manufacturer.”
A PMS system should clearly define benefit-risk calculations and the data used to support them. Post-market surveillance activities are critical in order to re-evaluate and maintain the benefit-risk calculations and determinations of a device throughout its life. Information that is gained through a PMS system can lead to:
• Identification of new risk factors.
• Adjustments to risk frequency and/or severity values based on actual use data.
• Adjustments to established risk calculations based on new “state of the art” technologies becoming available.
• Adjustments to established benefit calculations based on actual use data.
While complaint handling and other feedback tracking are more often described as part of post-market vigilance systems, they play a role in the more proactive post-market surveillance processes as well. A PMS system should define ...
To continue reading this ebook, download the full version.
Is a medical device accessory a medical device?
Rimsys’ own James Gianoutsos recently contributed an article on www.meddeviceonline.com discussing FDA’s guidance document describing accessories and classification pathways.
On Dec. 20, 2017, the FDA issued Medical Device Accessories – Describing Accessories and Classification Pathways: Guidance for Industry and Food and Drug Administration Staff, which applies to the Center for Devices and Radiological Health (CDRH) and Center for Biologics Evaluation and Research (CBER) for combination products.
The guidance document offers welcomed clarity on the role of an “accessory” and its regulatory relationship to its parent device. As always, guidance documents are not legally enforceable; rather, they describe the Agency’s current thinking on a topic and should be viewed only as recommendations, unless specific regulatory or statutory requirements are cited.
The guidance explains which devices FDA generally considers “accessories” and describes the processes under Section 513(f)(6) of the Federal Food, Drug, and Cosmetic Act (FD&C Act) to allow requests for risk- and regulatory control-based classification of accessories. In other words, it specifically details what is and is not an accessory, as well as the regulatory routes to classification.
The updated guidance was derived from an August 2017 amendment to section 513(f) of the FD&C Act (FDA Reauthorization Act of 2017 (Pub. L. 115-52)) to state that “the Secretary shall … classify an accessory under [section 513] based on the risks of the accessory when used as intended and the level of regulatory controls necessary to provide a reasonable assurance of safety and effectiveness of the accessory, notwithstanding the classification of any other device with which such accessory is intended to be used.”
The amendment allows for some accessories to have a lower risk profile than that of their parent device and, therefore, may warrant being regulated in a lower class. As classifications for accessories are now risk-based, it provides manufacturers with regulatory flexibility to loosen some of the regulatory burdens on accessories that may not have the same risk profile as their parent devices.
For example, an accessory to a class III parent device may pose lower risk that could be mitigated through general controls, or a combination of general and special controls, and thus could be regulated as class I or class II. A common example of this would be a ventilation system (parent device) with a face mask (accessory).
Additionally, the guidance details the applicable definitions within Section IV: Definitions:
- Accessory — “A finished device that is intended to support, supplement, and/or augment the performance of one or more parent devices.”
- Component (21 CFR 820.3(c)) — “[A]ny raw material, substance, piece, part, software, firmware, labeling, or assembly which is intended to be included as part of the finished, packaged, and labeled device.”
- Finished Device (21 CFR 820.3(l)) — “[A]ny device or accessory to any device that is suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized.”
- Parent Device — “A finished device whose performance is supported, supplemented, and/or augmented by one or more accessories.”
Accessory classification policy
The risks of an accessory are the risks it presents when used with the corresponding parent device as intended. To classify an accessory, FDA addresses the following two questions:
- Is the article an accessory? This can be answered by determining the intended use of the accessory. Is it intended for use with one or more parent devices, and does it support, supplement, and/or augment the performance of one or more parent devices?
- What is the risk of the accessory when used as intended with the parent device(s), and what regulatory controls are necessary to provide a reasonable assurance of its safety and effectiveness? This can be answered by providing a detailed risk assessment, outlining the potential hazards and reasonable regulatory and quality controls necessary to assure the accessory’s safety and effectiveness.
Individual accessories may be classified pursuant to the same regulation as a corresponding parent device, when appropriate, or be regulated independently.
Once an accessory has been classified, there is another consideration manufacturers need to decide: the Unique Device Identifier (UDI) rule. Not only does your parent device need to have a UDI, but any and all accessories each need to be assigned a UDI.
As 21 CFR 801 Labeling, Subpart B, Section 801.20(a) states: “(1) The label of every medical device shall bear a unique device identifier (UDI) that meets the requirements of this subpart and part 830 of this chapter,” and “(2) Every device package shall bear a UDI that meets the requirements of this subpart and part 830 of this chapter.”
Further, 21 CFR 830 UDI, Subpart A, Section 830.3 defines “finished device” and “device package” as follows:
- Finished device* means any device or accessory to any device that is suitable for use or capable of functioning.
- Device package means a package that contains a fixed quantity of a particular version or model of a device.
*Note that, although “medical device” and “finished device” are not consistent terminology used within the chapters, the terms are one and the same.
In short, any sellable finished device must bear a UDI, either on the device itself, on the device package, or both. Components to the finished device (i.e., service components and spare parts kits) are not considered accessories, and therefore are not required to bear a UDI.
What does this ultimately mean for manufacturers?
If there was any confusion as to whether a specific accessory is classified as a medical device, it has now been clarified, or at least partially clarified, depending on your specific situation. If there is still confusion among your engineering and regulatory teams, FDA recommends contacting them, via the accessory classification process outlined in the guidance, to classify the accessory appropriately. FDA will treat each accessory classification request as a Q-Submission. Requests may be for a new accessory type (new classification), an existing accessory type (reclassification), or classification of a new accessory type through the de novo process.
A gap analysis should be performed to identify a thorough and complete list of your current and future accessories to determine applicability to the guidance document. Justification also should be documented, should an accessory not apply to the guidance document. Additionally, internal procedures and the process associated with assigning UDIs may need to be updated to ensure there are no compliance gaps.
Podcast – Streamlining the MDSAP device marketing authorization and facility registration process
I had the opportunity to sit down with Jon Speer, Founder & VP of QA/RA at Greenlight Guru to record a podcast to discuss streamlining the MDSAP Marketing Authorization & Facility Registration Process.
If you are not familiar with this topic, you need to hear this.
We discuss:
- Why your regulatory team may be perceived as a bottleneck and why it is important everyone needs to be on the same page about when the product can be released.
- The connection between marketing authorization and facility registration required for various countries – United States, European Union, or elsewhere.
- The need to get organized, get better systems in place, and stay compliant when an auditor comes through your door or when you plan to sell into markets.
- Why small and large companies need to get organized now (i.e. small companies have too much information to maintain, organize, and track while large companies may have resources but suffer from miscommunication and disjointed processes.)
- The need to not be complacent and not be afraid to change systems. Rimsys was created to help regulatory professionals successfully and efficiently handle documentation.
You can hear the podcast below or at the Greenlight Guru blog.

