Resource

    EU MDR compliance for small medical device makers

    The MDR affects all manufacturers, but it does not affect all manufacturers equally. Small and mid-sized companies face the same legal framework as multinationals while operating with fewer people, less budget, and less organisational redundancy. That imbalance is one of the central realities of modern medical device compliance in Europe.

    Why the MDR feels heavier for SMEs

    For an SME, regulatory work is rarely confined to a large specialist department. One person may handle submissions, vigilance coordination, consultant management, change assessments, and quality documentation all at once. When the MDR raised expectations around clinical evidence, PMS, traceability, and lifecycle control, many smaller organisations suddenly needed enterprise-level discipline without enterprise-level infrastructure.

    This creates a structural problem. The documentation obligations are extensive even for low-volume portfolios, and many tasks do not scale down neatly with company size. A single Class IIa device can still require substantial technical documentation, CER maintenance, PMS planning, UDI management, and Notified Body interaction. The fixed cost per device therefore hits SMEs much harder than larger manufacturers spreading that cost over bigger portfolios.

    The result is often a constant sense of compliance fragility: the company is meeting obligations, but only through heroic effort, consultant dependency, and repeated manual updates across disconnected files.

    The main pressure points: people, consultants, and Notified Bodies

    Limited regulatory headcount is usually the first pressure point. When one key person is overloaded or leaves, the compliance system can stall. SMEs then become more dependent on consultants, which solves an expertise gap but introduces new costs and coordination problems. Consultants often deliver excellent work, but if knowledge remains outside the company, every update becomes another paid project.

    Notified Body capacity is another major challenge. Even when a manufacturer is ready, review slots may be limited and timelines may stretch. For SMEs with fewer resources and less bargaining power, delays are especially damaging. A certificate bottleneck can threaten revenue, investment plans, and even the long-term viability of a device line.

    The commercial impact is real. Some manufacturers have already reduced portfolios or withdrawn products because the cost of maintaining MDR compliance was too high relative to expected return. For SMEs, this is not just a regulatory inconvenience. It can reshape what products remain available on the market.

    What the December 2025 revision proposal signals

    In December 2025, the European Commission’s targeted MDR revision proposal acknowledged the pressure the system places on smaller manufacturers. That matters because the burden on SMEs is no longer only an industry complaint. It is part of the policy conversation. The proposal recognised that the regulatory system must remain robust while also being workable enough to preserve innovation and device availability.

    That acknowledgement should not be read as a sign that the compliance burden will disappear. Instead, it confirms something SMEs have been experiencing for years: the issue is not only whether the rules are defensible in theory, but whether companies with limited resources can implement them sustainably in practice.

    For manufacturers, the practical takeaway is to build for resilience rather than waiting for policy relief. Timelines and targeted measures may change, but documentation quality, evidence quality, and lifecycle control will remain central expectations.

    Practical steps SMEs should take now

    The first step is to identify where compliance knowledge currently lives. If critical device information is scattered across Word files, spreadsheets, consultant folders, and email chains, the company should map that fragmentation explicitly. Many SMEs know they have a documentation problem, but they have never listed the exact points where consistency breaks down.

    The second step is prioritisation. Not every document can be rebuilt at once. Manufacturers should focus first on intended purpose, classification rationale, core technical documentation structure, CER maintenance, PMS inputs, and the links between risk management and post-market data. These are the areas where inconsistency tends to cause the most serious downstream issues.

    Third, SMEs should reduce dependence on memory and manual handoffs. Standardised data fields, reusable evidence sources, controlled review cycles, and a documented owner for each compliance process can dramatically improve stability even before new software is introduced.

    • Map where device data and evidence currently live
    • Prioritise high-risk documentation dependencies first
    • Reduce consultant-only knowledge by improving internal structure
    • Create repeatable review cycles for CER, PMS, and risk updates
    • Treat compliance infrastructure as a business capability, not only a regulatory cost

    What a better SME compliance model looks like

    The long-term goal is not to make SMEs operate like bloated corporations. It is to give smaller teams the control, traceability, and consistency they need without adding unnecessary overhead. That usually means one shared device file structure, one clear version of intended purpose and classification rationale, one way of linking PMS signals to clinical and risk documentation, and one operational view of what needs updating when something changes.

    SMEs that build this kind of infrastructure are often more agile than large organisations because they can change direction quickly once the underlying data is structured. The challenge is reaching that point without drowning in manual rework first.

    That is why the future of SME MDR compliance is likely to be less about producing more isolated documents and more about connecting the ones that already exist. The manufacturers that do that well can preserve speed while still meeting regulatory expectations.

    Artifakt is purpose-built for SME manufacturers. Get the compliance infrastructure of a large company without the overhead. Talk to us.

    Talk to us