Traceability

Traceability is the ability to link a finished medical device back to the materials, components, processes, equipment, and personnel that produced it, and forward to where it was distributed. In device development, it also means requirements traceability: connecting user needs to design inputs, outputs, verification, validation, and risk controls.


What is traceability in medical devices?

The word carries two meanings inside a device company, and teams often blur them.

Product traceability, also called material or lot traceability, runs in both directions. A serial or lot number on a shipped unit resolves to its Device History Record (DHR), which resolves to component lots, supplier certificates of conformance, operator identities, equipment, and process parameters. Run the chain the other way, and you get the recall question: which shipped units contain resin lot 4471?

Requirements traceability is the design-side version. A traceability matrix links user needs to design inputs, inputs to outputs, outputs to verification, and the finished device to validation and to the risk controls specified under ISO 14971. Software teams do the same under IEC 62304.


Why traceability matters in medical device development

Recall scope is the sharpest reason. When a supplier reports a bad lot, the width of your traceability decides whether you retrieve four hundred units or forty thousand. Weak links force a conservative recall, and that gets expensive.

Investigation speed is the second. Root cause analysis starts by asking what was different about that build. If the DHR does not carry process parameters, operator, and incoming lots, the CAPA that follows is a guess dressed as a conclusion.

Audit exposure follows. Notified bodies and investigators test traceability by picking a device off the shelf and asking the manufacturer to walk the record backward, live.


How traceability works: identifiers, records, and systems

Traceability is assembled in layers.

  • Identification. ISO 13485:2016 clause 7.5.8 requires product identification through realization and status identification. Unique Device Identification (UDI) sits on top, mandated by FDA 21 CFR Part 830 and EU MDR 2017/745 Article 27.
  • Records. The Device Master Record (DMR) defines how the device is built. The DHR and batch record capture what was actually built, from which lots, by whom, under what conditions.
  • Extent. Clause 7.5.9.1 requires the manufacturer to define the extent of traceability and the records needed. Risk drives scope. A Class I dressing needs less than a Class III implantable.
  • Implantables. Clause 7.5.9.2 adds records for implantable devices covering components, materials, and work environment conditions that could cause the device to miss its safety and performance requirements. Distributors must keep distribution records available for inspection.
  • Systems. ERP, MES, and PLM tools hold the links. Software used in the quality system must be validated for intended use under ISO 13485 clause 4.1.6, proportionate to risk.
  • Downstream. EU MDR Article 25 obliges economic operators to identify who supplied them and who they supplied. Devices on the EU market must be registered in EUDAMED, whose first four modules became mandatory on 28 May 2026.

One recent change matters here. Since February 2, 2026, FDA 21 CFR Part 820 has incorporated ISO 13485:2016 by reference under the Quality Management System Regulation, and 820.10(d) extends the implantable traceability requirements of clause 7.5.9.2 to life-supporting and life-sustaining devices.


Common challenges and best practices

The failure most teams hit first is undefined extent. Nobody wrote down what gets traced, so shop-floor practice drifts. Put the decision in a procedure, justify it against the risk file, and audit it.

The second failure lives at the supplier boundary. A certificate of conformance arrives as a PDF, gets filed by date, and never gets tied to the lot number that entered the line. Incoming inspection is where the chain is welded or broken.

Other patterns worth watching:

  • Rework and nonconforming units re-entering the flow without their original lineage.
  • Traceability matrices assembled retroactively before a submission prove little.
  • UDI data in label artwork that disagrees with the database of record.

Good practice is unglamorous: one system of record, identifiers captured at the point of work rather than transcribed later, and periodic trace-back drills on a random serial number.


How SJML helps with traceability

SJML treats traceability as a production control rather than a records exercise. Manufacturing runs under an ISO 13485 quality system with SAP-integrated MES, so lot and serial data captured at SMT, molding, precision machining, box build, and packaging stays linked to the device history record. Supplier qualification, dual sourcing, and obsolescence management keep incoming material lineage intact. Engineering and QARA teams maintain requirements traceability across design controls, ISO 14971 risk files, and IEC 62304 software lifecycle records, and support DHF remediation where the chain has gaps.

Talk to SJML’s manufacturing team →


Frequently asked questions

What is the difference between identification and traceability?

Identification tells you what something is. Traceability tells you where it came from and where it went. ISO 13485:2016 separates them: clause 7.5.8 covers product and inspection status identification, while clause 7.5.9 covers the records that reconstruct a device’s history. Identification is the label; traceability is the record set behind it.

Does ISO 13485 require full traceability for every device?

No. Clause 7.5.9.1 requires the manufacturer to define the extent of traceability and keep records supporting it, and that definition should follow from the risk analysis. Implantable devices carry the extra requirements of clause 7.5.9.2, covering components, materials, work environment conditions, and distribution records. Lower-risk devices can justify a narrower scope in writing.

What did the FDA QMSR change about traceability?

The Quality Management System Regulation took effect on February 2, 2026, replacing most legacy Quality System Regulation text with ISO 13485:2016 incorporated by reference. Section 820.10(d) requires manufacturers of life-supporting and life-sustaining devices to meet the implantable traceability requirements of clause 7.5.9.2, widening the set of devices needing material-level records.

What is a traceability matrix?

A traceability matrix is a table linking user needs to design inputs, inputs to design outputs, and outputs to the verification and validation evidence that closes them. Risk controls from the ISO 14971 file are linked in the same way, so every mitigation has a test behind it. Software projects keep an equivalent structure under IEC 62304.

How long must traceability records be kept?

ISO 13485:2016 clause 4.2.5 requires retention for at least the device lifetime as defined by the manufacturer, and no less than two years from release, unless a regulation specifies longer. EU MDR 2017/745 requires technical documentation to be kept for ten years after the last device is placed on the market, and fifteen years for implantable devices.


Related terms

  • Device History Record (DHR)
  • Device Master Record (DMR)
  • Unique Device Identification (UDI)
  • Batch Record
  • Supplier Qualification

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant