Compliance & Regulations/European Union/MDR / IVDR
Healthcare · European Union

EU MDR / IVDR

EU regulations on medical devices and in-vitro diagnostics — clinical, technical, and increasingly cybersecurity requirements.

Regulator
Notified Bodies under European Commission oversight
Jurisdiction
European Union
Status
MDR active since May 2021; IVDR May 2022 with phased transition through 2027.
In force since
Active
Regulator's source
Who it applies to

Manufacturers, authorised representatives, importers, and distributors of medical devices and IVDs in the EU.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What MDR / IVDR actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Cybersecurity per MDCG 2019-16 Rev 1 (MDR) and equivalent guidance for IVDR.

02

Risk management to ISO 14971 incorporating cybersecurity.

03

Software life-cycle to IEC 62304 and risk management to IEC TIR 60601-4-5 where applicable.

04

Post-market surveillance and vigilance, including cybersecurity incident handling.

05

Unique Device Identification (UDI) and EUDAMED registration.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Software bill of materials and component lifecycle tracking for IEC 62304.

MDCG 2019-16 control crosswalk with continuous evidence.

Vigilance reporting workflow with EUDAMED-compatible export.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

MDCG 2019-16 cybersecurity package.

Software lifecycle records per IEC 62304.

Post-market cybersecurity surveillance reports.

Ready for MDR / IVDR?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing