The MDR does not use the phrase legal manufacturer
Everyone in the industry says legal manufacturer, and the term is useful, but it does not appear as a defined term in the regulation. What the MDR defines, in Article 2(30), is simply the manufacturer: a natural or legal person who manufactures or fully refurbishes a device, or has a device designed, manufactured or fully refurbished, and markets that device under its name or trademark.
Read that definition carefully, because it has two limbs joined by an and. The first limb covers building the thing, including having someone else build it for you. The second limb is the decisive one in practice: marketing it under your name or trademark.
Two consequences fall straight out of that. You can outsource every line of code and every unit of assembly and still be the manufacturer, because you are the one whose name is on it. And a contract developer who writes the software but never markets it under their own name is not the manufacturer, however much of the engineering they did.
What the manufacturer actually carries
Article 10 is where the obligations live, and it is worth being blunt about the scale of them, because the decision to be the manufacturer is the decision to take all of this on. The manufacturer is responsible for the quality management system, the technical documentation, the risk management process, the clinical evaluation, the declaration of conformity and the CE marking, registration of the device and the economic operator, UDI assignment, the post-market surveillance system, and vigilance reporting.
Two obligations get underestimated by smaller companies in particular. Article 10(16) requires manufacturers to have measures in place providing sufficient financial coverage for their potential liability for defective devices. And Article 15 requires a person responsible for regulatory compliance. There is a concession for smaller companies on the second: micro and small enterprises are not required to have that person within the organisation, but they must have one permanently and continuously at their disposal.
None of this is delegable in the sense that matters. You can contract other parties to perform the work, and most manufacturers do, but the responsibility for it remains with the manufacturer.
One product can have more than one manufacturer
This is the part that surprises people. Because the definition turns on whose name the device is marketed under, the same underlying product can reach the market through several routes, each with a different manufacturer, each carrying the full weight of Article 10 for the version they place on the market.
The practical implication for anyone considering a private label or own brand arrangement is significant. If you take another company's device and put your name on it, you become a manufacturer, which means you need the full technical documentation to support what you have placed on the market. Most original manufacturers will not hand that over, and that reluctance is the single biggest reason private label arrangements that worked comfortably under the old directives have become difficult under the MDR.
Article 16: when a partner becomes the manufacturer
Article 16 sets out when a distributor, importer or other person assumes the obligations of a manufacturer. There are three triggers. The first is making the device available on the market under their own name, registered trade name or registered trade mark. The second is changing the intended purpose of a device already on the market. The third is modifying a device already on the market in a way that may affect its compliance.
There is an important carve-out on the first trigger. It does not bite where a distributor or importer has an agreement with the manufacturer under which the manufacturer is identified as such on the label and remains responsible for meeting the manufacturer requirements. In other words, the arrangement can be papered, but it has to be papered properly and it has to be reflected on the label.
Article 16 also protects some ordinary commercial activities from counting as compliance-affecting modification. Providing information supplied by the manufacturer, including translating it, does not trigger manufacturer status. Nor do changes to the outer packaging of a device already on the market. Those carve-outs come with conditions: the party doing it needs a quality management system covering the accuracy of translations and the preservation of the device's original condition, has to identify itself and the activity carried out, and has to inform the manufacturer and the competent authority at least 28 days beforehand, together with a notified body certificate covering that quality management system.
For software companies the second trigger is the one to watch. A reseller who markets your triage tool for a population or an indication you never claimed has changed the intended purpose, and has quietly become a manufacturer.
| Situation | Who is the manufacturer |
|---|---|
| You design and market software under your own name | You, even if a contractor wrote all of it |
| An agency builds software that you sell under your brand | You. The agency is not the manufacturer |
| Your algorithm ships inside an OEM device, under the OEM's brand | The OEM, for that device as placed on the market |
| You license your software to a partner who sells it under their brand | The partner, unless the agreement names you on the label per Article 16(1)(a) |
| A distributor markets your device for a new indication | The distributor, via Article 16(1)(b) |
| A distributor translates your IFU or changes the outer packaging | Still you, provided the Article 16(2) to (4) conditions are met |
What this means if your product is software
The SaMD and SiMD distinction runs straight into this. If your software is placed on the market in its own right, under your name, you are the manufacturer of that software and you carry Article 10 for it. If your algorithm reaches the market as an integral part of someone else's device, under their brand, the manufacturer of that device is the OEM, and what you have is a supply relationship governed by contract rather than by your own CE certificate.
That is why the commercial questions raised by an OEM deal are really regulatory questions in disguise. Who is named on the label. Who holds the technical documentation and who can see it. Who decides whether a model update is a change that requires reassessment. Who bears the cost and the delay when it does. Whose post-market surveillance system captures complaints about your algorithm, and how that information reaches you.
There is one more trap specific to software. Because updates ship continuously, the intended purpose can drift without anyone formally deciding to change it. A new feature that answers a slightly different clinical question, or a marketing page that claims a little more than the last one, can move you across a line in Article 16 or change your classification. The regulation does not care that it happened incrementally.
If you are outside the EU
A manufacturer established outside the Union that wants to place a device on the EU market must designate an authorised representative under Article 11. The authorised representative is not a substitute for the manufacturer and does not absorb the manufacturer's obligations, but it does carry defined responsibilities of its own, including verifying that the declaration of conformity and technical documentation have been drawn up and keeping a copy available for the authorities.
The mandate between manufacturer and authorised representative is a real legal instrument, not a formality, and it is worth reading closely before signing. It defines what your representative is obliged to do, and equally what it is not.
Getting this right early
The manufacturer question is best settled at the point of designing the commercial model, not after the first customer contract. It determines who needs a quality management system, who needs a PRRC, who needs the financial coverage, whose name is on the certificate, and who takes the call when a competent authority asks a question.
The most common failure we see is a company assuming that because a partner is closer to the patient, or because a contract manufacturer did the building, the regulatory burden sits with them. Under Article 2(30) it usually does not. It sits with whoever put their name on it.
- Identify, in writing, who markets the device under their name; that is your manufacturer
- If you are that party, budget for the whole of Article 10, not just the technical file
- Check Article 15 for the PRRC, and the concession available to micro and small enterprises
- In any private label or OEM arrangement, settle technical documentation access before signing
- Use the Article 16(1)(a) carve-out properly if a partner sells under their brand but you remain the manufacturer
- Watch for intended purpose drift, especially in marketing copy and in feature releases