Guide · MDR

IVDR Technical Documentation Review: What Notified Bodies Check

A section-by-section reference to what Notified Bodies assess in IVDR technical documentation under Annex II and Annex III of Regulation (EU) 2017/746, including analytical performance, clinical evidence, stability and post-market surveillance.

By Conformo Editorial Team · Published

Overview

Technical documentation under Regulation (EU) 2017/746 (IVDR) is defined across two annexes: Annex II (Technical Documentation) and Annex III (Technical Documentation on Post-Market Surveillance). Both open with the same requirement — that the documentation be presented in a clear, organised, readily searchable and unambiguous manner.

This page sets out what a Notified Body assesses in each section, and where assessment most often stalls. It is the IVDR counterpart to our MDR Annex II and Annex III technical documentation checklist.

The structural difference from MDR is worth stating up front. MDR Annex II is organised around a device whose safety and performance are demonstrated through clinical evaluation. IVDR Annex II is organised around a device whose output is a measurement or detection result, and whose performance is demonstrated through a three-part evidence structure — scientific validity, analytical performance and clinical performance — assembled into a performance evaluation report under Annex XIII. Reviewers moving from MDR to IVDR files consistently underestimate how much of the assessment weight sits in Section 6.

Scope: which devices require Notified Body involvement

IVDR classification follows the rules in Annex VIII, producing Classes A, B, C and D. Notified Body involvement is required for Class A sterile, Class B, Class C and Class D devices. Class D adds two further layers: verification by an EU reference laboratory, and batch verification obligations. Companion diagnostics require consultation with the EMA or the relevant national competent authority.

The classification justification itself is part of the assessment. Annex II, Section 1.1, point (f) requires the risk class of the device and the justification for the classification rule(s) applied in accordance with Annex VIII. Classification disputes are a recurring source of delay, and they are best resolved before the assessment contract is signed rather than in month three.

Annex II, Section 1 — Device description and specification

1.1 Device description and specification

The Regulation lists thirteen elements, (a) through (m). The ones that most often prove insufficient in practice:

Point (c) — intended purpose. IVDR requires the intended purpose to be specified with a precision that has no MDR equivalent. It may include: what is to be detected and/or measured; the function (screening, monitoring, diagnosis or aid to diagnosis, prognosis, prediction, companion diagnostic); the specific disorder, condition or risk factor of interest; whether automated or not; whether qualitative, semi-quantitative or quantitative; the type of specimen(s) required; where applicable the testing population; the intended user; and for companion diagnostics, the relevant target population and the associated medicinal product(s).

This section governs the entire assessment downstream. Every performance claim, every element of the performance evaluation, and every general safety and performance requirement is assessed against the stated intended purpose. An imprecise intended purpose makes the rest of the file unassessable, and this is the single most consequential section in an IVDR file.

Point (b) — Basic UDI-DI as referred to in Part C of Annex VI, or, where the device is not yet identified through a UDI system, a clear identification by product code, catalogue number or other unambiguous reference allowing traceability.

Point (d) — the principle of the assay method, or the principles of operation of the instrument.

Point (e) — the rationale for qualification of the product as a device.

Point (g) — description of components and, where appropriate, reactive ingredients of relevant components such as antibodies, antigens, nucleic acid primers.

Points (h) to (m) apply where relevant: specimen collection and transport materials; assay characteristics for instruments of automated assays; instrumentation characteristics for automated assays; a description of any software to be used with the device; the configurations and variants intended to be placed on the market; and accessories and other products intended to be used in combination.

1.2 Reference to previous and similar generations of the device

Two elements: an overview of previous generations produced by the manufacturer where they exist, and an overview of identified similar devices available on Union or international markets where they exist.

Reviewers should note this is not optional where such devices exist. A file that omits it without establishing that no previous or similar generation exists is incomplete.

Annex II, Section 2 — Information to be supplied by the manufacturer

A complete set of the labels on the device and its packaging — single unit, sales and, where specific management conditions apply, transport packaging — in the languages accepted in the Member States where the device is envisaged to be sold, together with the instructions for use in those languages.

The language scope is assessed against the stated market. Files frequently supply English only while claiming EU-wide availability.

The check that matters here is consistency: the intended purpose in the IFU must match Section 1.1 point (c) exactly, and the performance claims in the IFU must be supported by the data in Section 6. Divergence between the IFU and the performance evidence is one of the most common substantive findings in IVDR assessment.

Annex II, Section 3 — Design and manufacturing information

3.1 Design information

Information sufficient to allow the design stages applied to the device to be understood, including:

  • a description of the critical ingredients — antibodies, antigens, enzymes, nucleic acid primers — provided or recommended for use with the device;
  • for instruments, a description of major subsystems, analytical technology such as operating principles and control mechanisms, dedicated computer hardware and software;
  • for instruments and software, an overview of the entire system;
  • for software, a description of the data interpretation methodology, namely the algorithm;
  • for devices intended for self-testing or near-patient testing, a description of the design aspects that make them suitable for that use.

The algorithm description requirement is explicit in the text and is frequently under-served, particularly for devices incorporating machine-learning-based interpretation. A reviewer is entitled to an account of the data interpretation methodology, not a statement that results are computed by proprietary software.

3.2 Manufacturing information

Information allowing the manufacturing processes — production, assembly, final product testing, packaging — to be understood, with more detailed information provided for the QMS audit; and identification of all sites, including suppliers and subcontractors, where manufacturing activities are performed.

Site identification here must reconcile with the site list underpinning the QMS audit programme and, under EU 2026/977 Article 1, with the site information the manufacturer supplied at quotation stage. Discrepancies between these three lists are a reliable early indicator of a file that will generate deficiencies.

Annex II, Section 4 — General safety and performance requirements

The documentation must demonstrate conformity with the general safety and performance requirements set out in Annex I applicable to the device given its intended purpose, including justification, validation and verification of the solutions adopted. It must include:

  • the GSPRs that apply, and an explanation as to why others do not apply;
  • the method or methods used to demonstrate conformity with each applicable requirement;
  • the harmonised standards, common specifications (CS) or other solutions applied;
  • the precise identity of the controlled documents offering evidence of conformity with each harmonised standard, CS or other method applied.

That final element is the one reviewers should hold firmly. The requirement is not a cross-reference to a document title; it is precise identification of the controlled document, which in practice means document number and version. A GSPR matrix pointing at "Design Verification Report" without a version identifier does not satisfy Section 4, and accepting it undermines traceability for the whole assessment.

The two recurring findings: requirements marked not applicable without justification, and references to superseded versions of harmonised standards.

Annex II, Section 5 — Benefit-risk analysis and risk management

Documentation of the benefit-risk analysis referred to in Sections 1 and 8 of Annex I, and of the risk management solutions adopted.

For an IVD, the benefit-risk analysis has a specific character worth spelling out, because reviewers coming from MDR files sometimes assess it as though harm were direct. IVD harm is generally indirect — it flows from a clinical decision made on the basis of an incorrect result. A false negative in a screening assay and a false positive in a confirmatory assay carry entirely different harm profiles, and both depend on the intended purpose, the testing population and the clinical pathway in which the device is used.

The assessment question is whether the risk analysis engages with the clinical consequence of erroneous results in the stated intended use context, or whether it treats the device as a piece of laboratory equipment. Risk documentation that addresses only operator safety, reagent handling and instrument failure modes has not addressed the principal risk of the device.

Annex II, Section 6 — Product verification and validation

This is the substantive core of an IVDR technical file and where the majority of assessment effort is spent.

6.1 Information on analytical performance of the device

6.1.1 Specimen type. The specimen types the device is validated for. Claims in the IFU must not exceed the specimen types validated here — a frequent and material finding.

6.1.2 Analytical performance characteristics, comprising six defined sub-sections:

SectionCharacteristic
6.1.2.1Accuracy of measurement
6.1.2.2Analytical sensitivity
6.1.2.3Analytical specificity
6.1.2.4Metrological traceability of calibrator and control material values
6.1.2.5Measuring range of the assay
6.1.2.6Definition of assay cut-off

Accuracy of measurement (6.1.2.1) covers trueness and precision. Section 6.1.2.4, metrological traceability, is the sub-section most often addressed inadequately: it requires an actual traceability chain for calibrator and control material values to available reference materials or reference measurement procedures, or a documented justification where no higher-order reference exists. A statement that calibrators are traceable to an in-house standard, without characterisation of that standard, does not close this out.

Section 6.1.2.6, definition of assay cut-off, requires the rationale for how the cut-off was established, the study supporting it, and its relationship to the intended population. For qualitative assays this determines the reported clinical performance and must be assessed alongside Section 6.2.

6.1.3 The analytical performance report referred to in Annex XIII.

6.2 Information on clinical performance and clinical evidence — Performance Evaluation Report

Clinical performance is the device's ability to yield results correlated with a clinical condition or physiological state in the target population, expressed through measures such as diagnostic sensitivity, diagnostic specificity and predictive values.

Under IVDR, scientific validity, analytical performance and clinical performance are the three pillars of performance evaluation. All three, their assessment, and the clinical evidence derived from them must be documented in the performance evaluation report referred to in Section 1.3.2 of Part A of Annex XIII, and that report forms part of the Annex II technical documentation.

What a reviewer checks:

  • Is there a performance evaluation plan as well as a report, and does the report execute the plan?
  • Are all three pillars addressed, or has scientific validity been asserted rather than demonstrated?
  • Are predictive values stated with the prevalence assumption made explicit? Positive and negative predictive value are prevalence-dependent, and a PPV quoted without the assumed prevalence of the testing population is not an interpretable claim. This is a routine finding.
  • Does the study population correspond to the intended testing population in Section 1.1(c)?
  • Where equivalence or literature is relied on rather than own-device data, is the justification adequate, and does it hold for the specific intended purpose claimed?

6.3 Stability (excluding specimen stability)

Three defined sub-sections:

  • 6.3.1 Claimed shelf-life
  • 6.3.2 In-use stability
  • 6.3.3 Shipping stability

Real-time stability data supporting the claimed shelf-life is required. Accelerated data may support an interim claim, but a file relying solely on accelerated studies for a final shelf-life claim should expect a finding. In-use stability (6.3.2) — open-vial and on-board stability — is frequently omitted for devices where it is plainly applicable.

Note that specimen stability is explicitly excluded from Section 6.3; it belongs with the specimen type and handling information.

6.4 Software verification and validation

Verification and validation of software in the device as designed, covering both software developed and off-the-shelf software incorporated. Assessment covers software lifecycle processes, verification and validation evidence, and the relationship between the software's data interpretation methodology (described under Section 3.1) and the performance claims in Section 6.

For devices incorporating adaptive or machine-learning components, the specific questions are whether the model is locked at release, what the validation dataset was and how it relates to the intended testing population, and how changes would be handled — a change to the interpretation algorithm is very likely a substantial change requiring notification.

6.5 Additional information required in specific cases

Device-specific additional requirements, including those applying to devices for self-testing or near-patient testing, devices incorporating tissues or cells of human or animal origin, and companion diagnostics.

Annex III — Technical documentation on post-market surveillance

Annex III applies to documentation drawn up in accordance with Articles 78 to 81, and comprises two sections.

Section 1 — The post-market surveillance plan (Article 79)

The manufacturer must demonstrate in a PMS plan that it complies with the Article 78 obligation.

Point (a) — the plan must address collection and utilisation of available information, in particular: information on serious incidents including from PSURs, and field safety corrective actions; records of non-serious incidents and data on undesirable side-effects; information from trend reporting; relevant specialist or technical literature, databases and/or registers; information including feedback and complaints from users, distributors and importers; and publicly available information about similar devices.

Point (b) — the plan must cover at least:

  • a proactive and systematic process to collect the information in point (a), permitting correct characterisation of device performance and comparison with similar products on the market;
  • effective and appropriate methods and processes to assess the collected data;
  • suitable indicators and threshold values for continuous reassessment of the benefit-risk analysis and risk management, as referred to in Section 3 of Annex I;
  • effective and appropriate methods and tools to investigate complaints and analyse market experience;
  • methods and protocols to manage events subject to trend reporting under Article 83, including methods to establish any statistically significant increase in frequency or severity of incidents, and the observation period;
  • methods and protocols to communicate with competent authorities, notified bodies, economic operators and users;
  • reference to procedures fulfilling the manufacturer's obligations under Articles 78, 79 and 81;
  • systematic procedures to identify and initiate appropriate measures including corrective actions;
  • effective tools to trace and identify devices for which corrective actions might be necessary;
  • a PMPF plan as referred to in Part B of Annex XIII, or a justification as to why PMPF is not applicable.

The two elements that most often fail assessment are the indicators and threshold values, and the PMPF plan.

On thresholds: the requirement is for suitable indicators and threshold values. A plan stating that data will be reviewed periodically and action taken if a concern arises has not specified thresholds. A reviewer should be able to identify what quantitative or qualitative trigger initiates reassessment of the benefit-risk determination.

On PMPF: the justification route is available but is genuinely demanding. A justification asserting that performance is well established, without addressing the residual uncertainty identified in the performance evaluation report, does not discharge it. Where the performance evaluation identifies gaps — limited data in a sub-population, reliance on equivalence, a cut-off validated in a single setting — those gaps are precisely what PMPF is expected to address, and the two documents must be assessed against each other.

Section 2 — PSUR and PMS report

The PSUR referred to in Article 81 and the post-market surveillance report referred to in Article 80.

Which applies depends on class: Class C and D devices require a PSUR, updated annually. Class A and B devices require a PMS report. For re-certification, EU 2026/977 Article 5(1)(b) makes the most recent PSUR and a summary of field safety corrective actions part of the required re-certification submission.

Where IVDR assessment stalls

Five patterns account for a substantial share of deficiencies:

  1. Imprecise intended purpose under Section 1.1(c), which makes the performance evidence unassessable because there is no defined claim to assess it against.
  2. Metrological traceability under 6.1.2.4 asserted rather than demonstrated.
  3. Predictive values quoted without prevalence assumptions, rendering the clinical performance claim uninterpretable.
  4. Missing in-use stability under 6.3.2 for devices where it plainly applies.
  5. PMPF justified away under Annex III without addressing the uncertainty the performance evaluation report itself identifies.

None of these is a complex scientific dispute. All are structural completeness problems detectable before substantive review begins — which is why front-loaded completeness screening has disproportionate effect on IVDR elapsed times. The Commission's Notified Bodies Survey consistently shows IVDR durations exceeding MDR: 90% of Notified Bodies report IVDR product certificates taking more than 13 months, with 40% reporting 19 to 24 months. See why MDR assessments still take 13–18 months for the mechanics of how round-trips accumulate.