Resource

    Post-Market Surveillance under EU MDR: PMS, PSUR, PMCF

    Under EU MDR, compliance does not end when the device is CE marked. Manufacturers are expected to monitor what happens in the real world, detect trends early, and feed new knowledge back into their documentation. That system is called post-market surveillance, or PMS, and it is broader than many teams first expect.

    The MDR PMS framework in Articles 83 to 86

    Articles 83 to 86 of the MDR set out the post-market surveillance framework. At a high level, manufacturers must establish, document, implement, maintain, and update a PMS system that is proportionate to the risk class and appropriate for the device type. This system is meant to collect and assess experience gained from devices already on the market.

    The reason is simple: pre-market evidence is never the whole story. Real-world use reveals complaint patterns, usability issues, rare adverse events, and trends that may not have been obvious during development or conformity assessment. The MDR therefore expects manufacturers to actively look for signals rather than passively wait for serious incidents to force action.

    For many organisations, PMS is where quality, regulatory, clinical, and vigilance work finally converge. If that system is weak, updates to risk management, clinical evaluation, labelling, and corrective actions will also be weak.

    PMS Plan, PMS Report, PSUR, and PMCF: what each one does

    The PMS Plan describes how post-market surveillance will be carried out. It explains what data will be collected, where it will come from, how it will be evaluated, and how findings will be turned into action. Under the MDR, the PMS Plan sits within the technical documentation and should be tailored to the device rather than copied from a template.

    The PMS Report is generally used for Class I devices. It summarises the results and conclusions of PMS data, along with any preventive or corrective actions taken. For Class IIa, IIb, and III devices, the Periodic Safety Update Report, or PSUR, takes on that role. The PSUR is more formal and more demanding. It must summarise results and conclusions from PMS data, explain the rationale and description of any preventive and corrective actions, and integrate volume of sales, user population, and frequency of use where relevant.

    PMCF stands for Post-Market Clinical Follow-up. It is the part of the PMS system focused on generating or collecting additional clinical data after market placement. PMCF is not automatically a new clinical study in every case, but it does require a justified plan and a method for confirming safety, performance, and the continued acceptability of benefit-risk over time.

    Which device classes require which documents

    Class I manufacturers must maintain a PMS system and prepare a PMS Report where appropriate, but they do not prepare a PSUR in the same way higher-risk classes do. For Class IIa devices, PSURs are required and typically updated when necessary and at least every two years. For Class IIb and Class III devices, the PSUR expectation is more intensive, with at least annual updates and closer review by the Notified Body or competent authorities depending on the device.

    PMCF expectations also scale with risk, novelty, and uncertainty. If a device has limited clinical evidence, novel technology, new indications, or unresolved questions in benefit-risk, PMCF becomes more significant. Even where PMCF activities are limited, manufacturers still need a reasoned justification for that approach.

    The important point is that the MDR does not treat PMS as a paperwork tier added only to higher-risk devices. Every device needs a PMS system. The format and intensity change with class, but the obligation to learn from real-world performance applies across the board.

    What data sources manufacturers need to monitor

    Effective PMS depends on broad and relevant data sources. Complaints and service reports are obvious inputs, but they are only the beginning. Manufacturers may also need to review vigilance databases, field safety corrective actions, competent authority notices, published literature, clinical registries, user feedback, maintenance logs, distributor feedback, trend reports, and equivalent device information where relevant.

    The best PMS systems define in advance which sources are monitored, how often they are reviewed, who reviews them, and what criteria trigger escalation. Without that structure, teams drift into reactive behaviour: one spreadsheet for complaints, one consultant handling literature, one quality manager tracking CAPAs, and no clear connection between them.

    This fragmented approach creates blind spots. A literature trend that suggests a growing usability issue might never be compared with complaint records. A signal in a vigilance database may not make it into the next CER update. The MDR expects manufacturers to close those gaps.

    • Complaints and trend data from internal quality systems
    • Vigilance databases and field safety notices
    • Scientific and clinical literature
    • Registries, user feedback, and service records
    • PMCF outputs and equivalent real-world evidence sources

    How PMS feeds back into clinical evaluation and risk management

    PMS only creates value if it changes decisions. Under the MDR, findings from PMS should feed back into the risk management file, the clinical evaluation, labelling, instructions for use, and where necessary CAPA or design changes. That means PMS is not a reporting silo. It is part of the control loop that keeps the technical documentation current.

    For example, if complaint trending shows increased user confusion, that may trigger updates to usability risk controls and IFU wording. If literature reveals new adverse event patterns, the CER and benefit-risk analysis may need revision. If PMCF shows weaker-than-expected performance in a subgroup, intended use claims or clinical arguments may need to be narrowed or strengthened.

    This is why manufacturers increasingly need connected documentation rather than separate reports. PMS, PSUR, PMCF, CER, and risk management are supposed to inform each other. When they are maintained in isolation, consistency becomes hard to prove and updates become slow and expensive.

    Artifakt connects PMS data directly to your device file - so your documentation stays consistent. Talk to us.

    Talk to us