You can prepare for a Notified Body assessment yourself
There is no secret Notified Body checklist.
The MDR and IVDR describe what your technical documentation and quality system must contain, and the European Commission publishes extensive guidance on how the requirements are interpreted.
A good starting point is to review your own submission as if you were the assessor.
1. Start with what the Notified Body will actually assess
For medical devices, look at:
- MDR Annex I for the General Safety and Performance Requirements
- MDR Annexes II and III for technical documentation and post-market documentation
- MDR Annex IX for conformity assessment based on the quality management system and technical documentation
- MDR Article 10(9) for the manufacturer's quality-management-system obligations
The IVDR follows a similar structure, with Annexes I, II, III and IX providing the corresponding requirements for IVDs.
The MDR requires technical documentation to be clear, organised, readily searchable and unambiguous. That is a useful readiness test in itself.
An assessor should be able to understand what the device is, what it is intended to do, what risks it presents, what evidence supports it and how those elements connect without reconstructing the regulatory argument themselves.
2. Check the chain across your documents
Many difficult Notified Body questions do not arise because a document is completely missing.
They arise because different documents tell slightly different stories.
Check that the same logic runs through:
intended purpose → claims → classification → risks → requirements → verification and validation → clinical or performance evidence → conclusions → post-market activities
For example:
- Does the intended purpose in the IFU match the clinical or performance evaluation?
- Are claims supported by evidence?
- Are important risks connected to appropriate controls and verification?
- Do validation acceptance criteria relate to the requirements they are intended to demonstrate?
- Does the clinical or performance conclusion actually support the intended purpose?
- Are PMS and PMCF or PMPF activities addressing remaining uncertainties?
A technically complete file can still be difficult to assess if these connections are unclear.
3. Use the MDCG guidance
The European Commission maintains the MDCG guidance library, which contains guidance covering clinical evidence, software, classification, vigilance, post-market surveillance, Notified Bodies and many other aspects of MDR and IVDR implementation.
You do not need to read every MDCG document.
Identify the guidance that applies to your technology and conformity assessment questions and check whether your documentation reflects it.
For software and AI-enabled devices, this often means looking across several areas rather than treating software documentation, risk management and clinical evidence as separate workstreams.
4. Check the relevant standards
Standards provide useful structures and accepted methods for demonstrating conformity.
Depending on the product, this may include standards such as:
- ISO 13485 for the quality management system
- ISO 14971 for risk management
- IEC 62304 for medical device software lifecycle processes
- IEC 62366-1 for usability engineering
- relevant product, electrical safety, cybersecurity, clinical or laboratory standards
The European Commission publishes the current lists of harmonised standards under the MDR and IVDR.
Using a standard does not remove the need to understand the regulatory requirement. It gives you an established way of addressing particular requirements and demonstrating state of the art.
5. Check your Notified Body's scope
Not every MDR or IVDR Notified Body can assess every product.
Use the Commission's NANDO database to check the organisation's designation and relevant device and technology codes.
For manufacturers selecting a Notified Body, this is worth doing before investing substantial time in discussions or applications.
You can also search the public EUDAMED Notified Bodies and Certificates module to see certificate information registered by Notified Bodies.
6. Understand what the Notified Body can and cannot help you with
A useful distinction is that your Notified Body can explain its process and engage in appropriate structured dialogue, but it must remain independent.
It cannot become the consultant who prepares the documentation that it will later assess.
European MDCG guidance specifically distinguishes legitimate pre-application interaction from activities such as gap analyses, readiness reviews or partial conformity assessments that could compromise the Notified Body's impartiality.
That means the manufacturer needs to arrive at conformity assessment able to defend its own regulatory reasoning.
Before submitting, ask yourself
Can an independent assessor quickly answer:
- What is this product?
- What is its precise intended purpose?
- Why does it qualify as a medical device or IVD?
- Why is it in this classification?
- Which conformity assessment route applies?
- Which claims are being made?
- Where is the evidence supporting each important claim?
- What are the significant risks and how are they controlled?
- How has the device been verified and validated?
- What uncertainties remain?
- How will those uncertainties be monitored after market entry?
If those answers are difficult to find, the assessor is likely to have questions too.
Where Fabola comes in
Fabola reviews the submission from the perspective of an external conformity assessment rather than simply checking whether documents exist.
We look for the things that often become visible only when the whole submission is read together:
- contradictions between documents
- intended-purpose or claims drift
- weak regulatory rationales
- evidence that does not quite support the conclusion being drawn from it
- missing traceability
- risk controls that are not adequately verified
- software, clinical or performance documentation that tells a different story from the core technical file
- conclusions that an assessor is likely to challenge
Where useful, we formulate the questions we would expect an assessor to ask and help the team work through the underlying issue before submission.
We can also help strengthen the regulatory narrative across the submission, including the intended purpose, classification rationale, conformity assessment rationale and the connection between claims, risks and evidence.
The aim is not to make the documentation larger.
It is to make it easier to assess, internally consistent and easier to defend when the Notified Body starts asking questions.