Engineering Change Order (ECO)

Engineering Change Order (ECO) is a formal, documented instruction that authorizes and records a change to a released medical device design, component, specification, or manufacturing process. It states what is changing, the reason, the risk and regulatory impact, and the approvals required before the change takes effect in production.


What is an Engineering Change Order (ECO)?

An Engineering Change Order is the controlled mechanism used to modify a design after it has been released or frozen. It sits within the broader change-control process and usually follows an Engineering Change Request (ECR), which proposes and justifies the change. Once approved, the ECO becomes the authoritative implementation record, linking the change to affected drawings, the bill of materials, specifications, and Device Master Record.

In a regulated environment, the ECO is not just paperwork. It is the evidence that a change was assessed, reviewed, and approved before reaching the patient-facing product. That traceability is what an auditor or notified body expects to see.


Why does an Engineering Change Order (ECO) matter in medical device development

A change to a medical device can shift its safety profile, performance, or regulatory status. An uncontrolled change can invalidate verification results, break a 510(k) clearance, or trigger a field action. The ECO keeps that risk contained.

Under the FDA Quality Management System Regulation (QMSR), effective February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, so design and document change requirements now flow from that standard. Weak change control is one of the most common findings in device audits, and it carries real consequences: warning letters, import holds, and recalls.

Cost matters too. Catching a change’s downstream impact late, after tooling or inventory commitments, costs far more than evaluating it up front.


How the Engineering Change Order (ECO) process works

A typical ECO moves through defined stages. The exact names vary by company, but the logic is consistent:

  • Request. Someone raises an ECR describing the problem or improvement and the proposed change.
  • Impact assessment. Engineering, quality, and regulatory evaluate the effect on form, fit, function, safety, usability, and applicable regulatory requirements. Risk management files under ISO 14971 are revisited.
  • Verification and validation. The team determines which V&V activities must be repeated. ISO 13485 Clause 7.3.9 requires design changes to be reviewed, verified, validated where appropriate, and approved before implementation. The ECO should record both the testing decision and its supporting rationale.
  • Approval. A cross-functional review signs off. Document control under ISO 13485 clause 4.2.4 governs the revision of affected records.
  • Manufacturing implementation. Approved drawings, BOMs, specifications, work instructions and Device Master Records are revised. Effective dates and inventory-disposition instructions are established, and the controlled change is communicated to production teams, suppliers and quality personnel.
  • Closure. Records are retained as objective evidence.

Software changes are governed through the maintenance and problem-resolution processes of IEC 62304, so a software ECO must remain connected to those lifecycle records. Devices already placed on the European market require an additional regulatory impact assessment: a significant change to the design or intended purpose may require notification to, or assessment by, the Notified Body before implementation. Manufacturers must similarly assess whether a US change requires a new 510(k).


Common challenges and best practices

The most frequent failure is treating the ECO as an administrative formality, completed after the change is already in the field. The impact assessment becomes a rubber stamp, and the risk file is never reopened.

A few patterns separate teams that handle change well:

  • Define change significance up front. Not every change needs full revalidation, but the criteria for deciding should be written down, not improvised.
  • Maintain one source of truth. Use a controlled product lifecycle record to keep the BOM, drawings, specifications, risk files, verification evidence and Device Master Record synchronized. When these records contain different revisions, the ECO can no longer demonstrate which configuration was actually approved and manufactured.
  • Pull regulatory in early. Whether a change is significant under EU MDR or affects a 510(k) basis under FDA rules is a question to ask before implementation, not after.
  • Control supplier changes. A supplier altering a component without notice is a classic source of unplanned, undocumented change. Quality agreements should require change notification.

How SJML helps with Engineering Change Order (ECO)

SJML supports change control as part of its design, engineering, and sustaining engineering services. Its phase-gate program management builds change governance into each development stage, with impact assessment, risk management under ISO 14971, and design transfer handled by cross-functional teams. For products already on the market, SJML’s lifecycle and regulatory sustenance work covers design changes, BOM review, supplier qualification, and the documentation needed to keep a device file audit-ready, structured to minimize unnecessary revalidation.


Frequently asked questions

What is the difference between an ECR and an ECO?

An Engineering Change Request (ECR) proposes and justifies a change; it is the question. An Engineering Change Order (ECO) authorizes and records the approved change; it is the answer. The ECR opens the evaluation, and once impact, risk, and verification are assessed and signed off, the ECO directs the change into production and updates every affected document.

Does every ECO require revalidation?

No. The level of verification and validation depends on the change. ISO 13485 clause 7.3.9 requires teams to assess each change and decide what V&V is appropriate before implementation. A minor, well-isolated change may need limited retesting, while a change affecting safety or performance can require full revalidation. The decision and its rationale must be documented.

How does an ECO relate to FDA and EU MDR requirements?

Under the FDA QMSR, effective February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016, so change control follows that standard’s design and document requirements. Under EU MDR 2017/745, a significant change to a device’s design or intended purpose can require notified body involvement before the change is placed on the market.

Who approves an Engineering Change Order?

Approval is cross-functional. Engineering owns the technical change, but quality and regulatory must confirm that it is assessed for safety, risk, and regulatory impact before implementation. Depending on the change, manufacturing, supply chain, and clinical functions may also sign off. The approving roles should be defined in the change control procedure and recorded on the ECO.


Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries