Why post-market surveillance matters more under EU MDR

Under MDD, post-market surveillance was broadly defined and inconsistently enforced. Many companies maintained minimal PMS systems — a complaint log, an annual literature search, and a brief summary — and passed NB audits without difficulty. EU MDR fundamentally changed this. The regulation introduces specific, named post-market documents with defined content requirements, mandatory update frequencies, and direct linkage to the clinical evaluation that must be maintained throughout the device's lifetime.

For SaMD specifically, post-market surveillance has a dimension that hardware devices do not: the product is continuously updated, and each update creates a data point relevant to real-world performance. A SaMD company with an active user base has more post-market clinical data available than almost any hardware manufacturer — but only if the PMS system is designed to capture it.

The most common post-certification audit finding: NBs consistently cite PMS systems that exist on paper but have not generated actual data. A PMS plan that describes data collection methods but shows no collected data, no complaint trend analysis, and no PSUR prepared on schedule is treated as evidence that the PMS system is not functioning — regardless of whether the device has performed safely in the market.

The four documents: what they are and how they connect

EU MDR creates four distinct but interconnected post-market documents. They are not interchangeable, and the failure to understand the difference between them is itself a common audit finding.

EU MDR Article 84 · Annex III
PMS Plan
The master plan for all post-market data collection. Defines data sources, collection methods, analysis approach, and thresholds that would trigger action. Must be in place before market entry.
Updated when device or context changes
EU MDR Article 86 · Annex III
PSUR
Periodic Safety Update Report. Synthesises all PMS findings into a benefit-risk conclusion. For Class IIa/IIb: annual. Integrates complaint trends, vigilance events, PMCF findings, and CER update.
Annual (Class IIa/IIb)
EU MDR Annex XIV Part B
PMCF Plan
Post-Market Clinical Follow-up Plan. Defines systematic clinical data collection activities — literature surveillance, studies, registries, real-world data analysis. Required where CER identifies evidence gaps.
Updated per PMCF cycle
EU MDR Annex XIV Part B
PMCF Report
Documents findings from PMCF activities conducted per the PMCF Plan. Feeds directly into CER update. If findings reveal new risks or performance variation, CER and risk file must be updated.
Annual or per PMCF Plan schedule
The hierarchy: The PMS Plan is the umbrella. The PMCF Plan sits inside it as the clinical data collection component. The PSUR integrates outputs from both, plus complaint data and vigilance information, into a periodic benefit-risk conclusion. The PMCF Report documents what PMCF activities actually found. The CER is updated using PMCF Report findings. Each document feeds the next in a continuous loop.

What each document must contain for SaMD

PMS Plan

The PMS Plan must specify proactive and reactive data collection methods. For SaMD, this typically includes: complaint handling and trend analysis (classification, severity, frequency thresholds triggering escalation); adverse event and near-miss reporting per MDR Article 87; post-market literature surveillance covering the clinical domain and comparable devices; PMCF activities as specified in the PMCF Plan; and data from user feedback channels. Critically, the plan must define thresholds — specific criteria that, when met, trigger a defined response (design change, field safety notice, NB notification, CER update). A PMS Plan without thresholds is a data collection plan, not a surveillance plan.

PSUR (Class IIa/IIb — annual)

The PSUR must include: a summary of PMS data collected since the last PSUR; complaint analysis with trend conclusions; vigilance events and regulatory actions; literature surveillance findings; PMCF findings summary; conclusions of the current benefit-risk analysis (not just a statement that the benefit-risk is acceptable, but the actual analysis); and the conclusions of the current clinical evaluation. For most Class IIa SaMD, the first PSUR is due 12 months after initial certification. If the PSUR identifies a new risk or a change in the benefit-risk profile, this must trigger a CER update and — if significant — NB notification.

PMCF Plan

The PMCF Plan for SaMD should specify: the specific clinical questions or evidence gaps it is designed to address (taken directly from the CER conclusions); the data collection methods to be used and why they are appropriate; timelines and responsible parties for each activity; acceptance criteria that would confirm or refute the clinical hypotheses; and what will happen when the PMCF Report is completed (how findings feed back into the CER). For software, PMCF activities often include systematic literature surveillance (most efficient for SaMD teams with limited field study capacity), analysis of usage logs linked to clinical outcomes, and structured user feedback with clinical performance dimensions.

PMCF Report

The PMCF Report documents what was actually done per the PMCF Plan and what was found. It must conclude whether the PMCF findings confirm the clinical evaluation's benefit-risk analysis or whether a CER update is required. If findings reveal unexpected adverse effects, performance variation across patient subgroups, or new evidence about the clinical domain, the PMCF Report triggers a CER revision — which may in turn require NB notification if the revision constitutes a significant change.

The post-market lifecycle timeline for Class IIa SaMD

Certification (Month 0)
PMS Plan and PMCF Plan already in place as part of technical file. Complaint handling system live. Literature surveillance scheduled.
Months 1–12
PMS data collection ongoing: complaints logged and classified, literature surveillance executed, PMCF activities underway. Each software release reviewed for change control significance.
Month 12
PSUR due. Synthesise all PMS data collected. Update benefit-risk analysis. Prepare PMCF Report from Year 1 PMCF activities. Update CER if PMCF findings require it. Submit PSUR to NB if required by QMS/NB agreement.
NB Surveillance Audit (typically Month 12–18)
NB reviews PMS system in operation. Checks complaint records, PSUR content and timeliness, PMCF activities against Plan, vigilance reporting, and whether PMS findings triggered any required QMS or design changes.
Year 2 onward
Annual PSUR cycle continues. PMCF Plan reviewed and updated. CER updated at least once per PMCF cycle. PMS Plan updated if device, indication, or user base changes materially.

Connecting PMS to real-world SaMD operations

For SaMD teams, the practical challenge is that post-market regulatory obligations run in parallel with normal product development. The same engineering team managing sprint cycles and software releases is also the source of post-market performance data. Designing the PMS system to capture this data without creating separate manual processes is both possible and important.

Specifically for SaMD, operational data that can serve PMS purposes includes: support ticket classification by symptom type and clinical impact severity; error rate telemetry on algorithm outputs where clinical impact can be assessed; user-reported discrepancies between algorithm output and clinical judgement; and usage patterns that indicate the device is being used outside its validated intended use. None of this requires building a separate regulatory data collection process — it requires designing the existing operational systems to retain and classify data in a way that feeds PMS analysis.

The PMS–QMS loop: EU MDR Article 83 explicitly requires that PMS findings feed back into the QMS and the risk management process. If complaint analysis identifies a new use-related hazard, the risk file must be updated. If PMCF findings reveal a performance issue in a patient subgroup, the CER and potentially the technical file must be updated. The PMS system is not a documentation exercise — it is the mechanism by which real-world data maintains the accuracy of your certified technical file over time.

What NBs look for in PMS surveillance audits

Based on NB audit experience, the most frequently cited PMS deficiencies for SaMD under EU MDR are:

Official sources & references