The regulatory system needs to deal with all of that.
Post-market surveillance is an evidence system
The MDR and IVDR require manufacturers to establish a post-market surveillance system appropriate to the device.
Its purpose is not simply to collect complaints.
Post-market surveillance (PMS) brings together information that can tell you whether assumptions made before launch remain true.
Depending on the product, sources may include:
- complaints
- incidents
- customer feedback
- service and maintenance data
- returns
- literature
- registry data
- user feedback
- trend information
- clinical or performance follow-up
- information about comparable devices
- regulatory and safety information
- real-world performance data
The information should then feed back into the regulatory system.
A useful way to think about it is:
market information → analysis → regulatory conclusion → action where needed
The European Commission's MDCG 2025-10 now provides dedicated guidance on post-market surveillance under the MDR and IVDR.
Start with a PMS plan
Before launch, determine:
- what information you will collect
- where it will come from
- who will review it
- how often it will be reviewed
- what constitutes a signal
- how trends will be identified
- when escalation is required
- how findings feed into risk management
- how findings affect clinical or performance evaluation
- how findings affect CAPA and product development
The PMS plan should reflect the risks, novelty, use and evidence base of the actual product.
A low-risk established physical device and a novel AI-enabled clinical decision-support system should not have identical post-market strategies.
Complaints are not the same as vigilance
A complaint is information that needs to be evaluated.
It does not automatically mean that a reportable incident has occurred.
Manufacturers need a process for determining whether information represents, for example:
- a complaint
- a nonconformity
- a serious incident
- a trend
- a safety signal
- a need for corrective action
- a potential field safety corrective action
The key is having a documented process that allows information to be assessed consistently and escalated when necessary.
The Commission's MDCG 2023-3 Rev.2 provides Q&A guidance on important vigilance concepts, and device-specific vigilance guidance also exists for certain product categories.
Keep the evidence alive
Post-market information should not sit in a separate quality-system folder.
It should feed back into:
- risk management
- clinical evaluation or performance evaluation
- benefit-risk assessment
- usability
- cybersecurity
- instructions and labelling
- PMCF or PMPF
- CAPA
- product development
This is one of the most important lifecycle principles in medical-device regulation:
Pre-market evidence and post-market evidence should form one continuous evidence system.
PMCF and PMPF
Where appropriate, manufacturers may need structured post-market clinical follow-up (PMCF) for medical devices or post-market performance follow-up (PMPF) for IVDs.
These activities are not simply studies performed because a regulation says “collect more data”.
They should address specific questions or residual uncertainties.
Ask:
- What remains uncertain after conformity assessment?
- Is there a question that can only realistically be answered in broader clinical use?
- Are particular populations underrepresented?
- Are there long-term performance questions?
- Is the technology or clinical practice changing?
- Is new evidence needed to confirm continued benefit-risk acceptability?
Good follow-up has a reason.
Report what the system is finding
Depending on device classification and regulation, PMS outputs may include documents such as:
- PMS reports
- Periodic Safety Update Reports (PSUR)
- PMCF evaluation reports
- PMPF evaluation reports
- updated clinical evaluation reports
- updated performance evaluation reports
- trend reports
- vigilance reports
These should not become annual documentation exercises performed independently of each other.
They should tell a consistent story about what has happened to the device since the previous review.
Treat change as a regulatory process
Products change after approval.
That is normal.
What matters is understanding the regulatory consequence of the change before implementing it.
Examples include:
- software releases
- algorithm changes
- new functionality
- new intended uses
- changed claims
- manufacturing changes
- new critical suppliers
- material changes
- packaging changes
- cybersecurity updates
- changes to clinical workflows
- changes to performance specifications
A change-control process should therefore ask more than:
“Does it work?”
It should also ask:
- Does this affect the intended purpose?
- Does it affect classification?
- Does it introduce or change risks?
- Does existing verification and validation still support the device?
- Does the clinical or performance evidence remain applicable?
- Does documentation need to change?
- Does the Notified Body need to be involved or notified?
- Does a regulatory submission or registration need to be updated?
The answer will depend on the device, certificate, regulatory pathway and nature of the change.
Software and AI make this particularly important
Software development assumes iteration.
Medical-device regulation also allows products to evolve, but change needs to be controlled.
For software and AI-enabled products, establish early:
- what constitutes a product change
- how changes are risk assessed
- when regression testing is required
- when clinical or performance evidence needs reconsideration
- how cybersecurity updates are handled
- what documentation needs updating
- when the change may affect the approved intended purpose or conformity assessment
The objective is not to prevent development.
It is to create a regulatory system in which the product can continue to develop without losing control of its conformity.
Useful starting resources
You can build much of the system directly from primary sources.
Good starting points include:
- MDR Articles 83–92 and Annex III
- IVDR Articles 78–87 and Annex III
- MDCG 2025-10 on post-market surveillance
- MDCG 2023-3 Rev.2 on vigilance terminology and concepts
- MDCG 2022-21 on MDR PSURs
- applicable PMCF and PMPF guidance
- device-specific vigilance guidance where available
- your Notified Body's change-notification requirements
- ISO 14971 for the connection back into risk management
- ISO 13485 for complaint handling, CAPA and change control
The Commission maintains its current PMS and vigilance guidance together in the MDCG guidance library.
The EUDAMED Vigilance and Post-Market Surveillance module is still under development as of October 2026, so manufacturers should follow the currently applicable reporting channels and Commission or competent-authority instructions until that module becomes mandatory.
Where Fabola comes in
The difficult part is not writing a PMS procedure.
It is deciding what information matters, what it means, and when it requires action.
Fabola can help you:
- design proportionate PMS systems
- develop PMS, PMCF and PMPF strategies
- establish complaint and vigilance processes
- assess potential serious incidents
- assess trends and safety signals
- prepare or review PSURs
- connect post-market evidence to risk and clinical or performance evaluation
- assess regulatory implications of product changes
- establish change-control frameworks for software and AI
- determine when Notified Body or regulatory involvement may be required
- help teams respond to regulatory and Notified Body questions when something changes
The aim is not to freeze the product at the point of CE marking.
It is to create a regulatory system that allows the product to learn, change and improve while remaining safe, supported by evidence and under regulatory control.