Published On: 18. August 2026

Navigating the MDR jungle

Key Insights for Medical Software Development

The European Medical Device Regulation (MDR) is a complex landscape with many regulations and hidden challenges. We have navigated this terrain successfully and help manufacturers develop innovative, compliant medical software solutions.

Thanks to our many years of experience with software solutions for regulated environments—including BAYOOSOFT Access Manager for the compliant management of access rights and BAYOOSOFT Themis for structured compliance and risk management— we have hands-on experience with the requirements of the MDR environment and understand what matters most when developing and operating certifiable software.

The challenges under MDR

Developing medical software under the MDR is like trekking through a dense rainforest—full of obstacles, but also full of opportunities for those equipped with the right tools. Below, you’ll learn how we’ve learned to overcome the biggest challenges:

UDI System and QMS Integration
Implementing a UDI (Unique Device Identification) system is not just a matter of regulatory compliance; it must be seamlessly integrated into the quality management system (QMS) and, ideally, into the development pipeline as well. This integration minimizes manual effort and ensures consistency.

Unannounced Audits
Preparing for unannounced audits is essential. Establish standard operating procedures (SOPs) that describe how you should respond in such situations: Ensure a pleasant environment, offer refreshments, and immediately gather your experts to answer the auditors’ questions. This preparation will help you remain calm and efficient during the audits.

Clinical Evaluation
Clinical evaluations under the MDR require verifiable safety and performance endpoints, which are difficult to substantiate retrospectively. Establishing equivalence—particularly for software—often requires deep insight into the core algorithm. Be prepared for a thorough review if you choose this path.

It’s insufficient to rely solely on a single scientific database. Utilize diverse scientific publication databases to ensure comprehensive coverage and avoid overlooking critical studies.

Cybersecurity measures
Auditors expect state-of-the-art cybersecurity measures, including vulnerability scans and penetration tests, even if these are not explicitly required. It is advisable to implement these measures proactively.

Guidance Document MDCG 2019-16 rev.1 provides a framework that emphasizes the traditional risk management cycle: plan, analyze, evaluate, and mitigate. In addition, the FDA guidelines offer more detailed examples and can serve as valuable supplements.

The level of detail in an inspection depends on the inspector’s expertise. If the inspection focuses on cybersecurity, you should be prepared for detailed discussions about risk assessments. We have found that the use of the Common Vulnerability Scoring System (CVSS) has been satisfactory for auditors so far.

Usability and Risk Management
Usability studies and risk management are of central importance for MDR compliance, even though usability is mentioned in the MDR only in connection with post-market surveillance (PMS). Auditors are increasingly focusing on documentation and traceability and require that all measures—even best practices—be explicitly documented. Keep the original records from your suppliers, as they may be requested during future inspections.

This iterative process extends over the entire product life cycle. A one-page summary of tests carried out with a small group is insufficient; comprehensive documentation is required.

Post-Market Surveillance
For software, post-market surveillance involves collecting data from support channels, monitoring the Software Bill of Materials (SBOM), reviewing crash reports, and conducting compatibility tests with new operating systems or devices. Changes to SOUP (Software of Unknown Provenance) components or the underlying operating systems occur frequently and require constant vigilance. The more your product gains prominence in the market, the more feedback you can expect, which requires thorough documentation and analysis.

Trend analyses and effective data collection methods are essential for preparing the Periodic Safety Update Report (PSUR) and maintaining compliance. Selecting the right statistical methods is crucial. Recommended methods include Weibull analysis (as recommended in ISO 24971), the Nelson rules (as recommended in ISO/TR 20416), the Mann-Kendall test, or the Neumann trend test (for normally distributed populations).

Survival tips for the MDR landscape

  • Start small, iterate quickly
    Start with a Minimum Viable Product (MVP) to test usability and user acceptance. This approach helps control risks and accelerate progress.

  • Incorporating Agile Compliance
    By integrating compliance into agile development cycles, your process remains adaptable while staying in line with MDR requirements.

  • Documentation is essential, but keep it concise
    Think of documentation as your bike. It records every step and ensures you have evidence to present when auditors inquire about your process.

  • Collaborate Early and Often
    Involve the Notified Bodies, cybersecurity experts, and other stakeholders early on to effectively manage the complexity.

Conquering the MDR landscape

The MDR landscape is complex and full of challenges. With the right tools, thorough preparation, and the right mindset, you can develop groundbreaking software solutions that make a real difference.

Are you ready to embark on your journey through the MDR landscape, or do you need some help? We’d be happy to assist you. Just contact us.

Klingt spannend? Teilen Sie diesen Beitrag doch mit Ihrem Netzwerk.