Engineering Change Request (ECR)

Engineering Change Request (ECR) is a formal, documented proposal to modify a released medical device, component, process, or specification. It records the problem, the proposed change, and the reason, then triggers an impact assessment and approval workflow before any change is authorized, verified, validated where needed, and implemented under change control.


What is an Engineering Change Request (ECR)?

An Engineering Change Request is the starting point of formal change management. A team raises one when something about a released design needs to change: a part that fails in the field, a discontinued component, a usability issue discovered after launch, or a specification correction. The ECR describes the problem and proposes a solution, but it does not authorize the change.

Once raised, an ECR moves through the review and impact assessment process. If approved, it is converted into an Engineering Change Order (ECO), sometimes called an Engineering Change Notice, which authorizes the change and directs how affected drawings, specifications, work instructions, BOMs and Device Master Records must be updated. In a medical device organization, the ECR is part of the design change process governed by ISO 13485.


Why does an Engineering Change Request (ECR) matter in medical device development

A change to a regulated device can ripple into patient safety, regulatory status, and supply continuity. An uncontrolled change that skips review is one of the most common and most serious audit findings. If a part substitution alters biocompatibility, or a software fix changes how an alarm behaves, the effect reaches the risk file, verification evidence, and labeling.

The ECR forces those questions before the change ships. It creates the traceable record auditors and notified bodies expect: what changed, why, who assessed the impact, and what testing confirmed it was safe. Skip the step and you risk a nonconforming product, recalls, or a significant change in shipping without the required notification.


How the Engineering Change Request (ECR) process works

Engineering change management follows a defined sequence. Gates vary by company, but the core steps are consistent:

  • Raise the request. Someone documents the problem, the affected items, the proposed change, and the justification.
  • Assess impact. Conduct a cross-functional design impact assessment covering design inputs and outputs, form, fit and function, risk controls, usability, software, verification evidence, labelling, manufacturability and supplier implications.
  • Classify the change. Complete a documented regulatory change assessment to determine whether the proposal is minor or significant, whether it requires Notified Body involvement under EU MDR, and whether it could require a new US 510(k) or another market-specific submission.
  • Approve or reject. Authorized reviewers sign off. Approval converts the ECR into an ECO.
  • Define implementation evidence. Identify the documents, tooling and production records that would need updating, and determine which verification or validation activities must be completed before the approved change can be released.

Clause 7.3.9 of ISO 13485 requires that design and development changes be reviewed, verified, validated where appropriate, and approved before implementation. Since the FDA QMSR took effect in February 2026, 21 CFR Part 820 incorporates ISO 13485 by reference, so this discipline now anchors US compliance too. For software, IEC 62304 adds change and problem-resolution requirements.


Common challenges and best practices

The most frequent failure is treating an ECR as paperwork rather than a risk decision. Teams approve a change quickly to keep a line running, then find the risk file and verification evidence were never updated. Another common gap is a missing significant-change assessment.

Good change control routes every request through an explicit impact assessment that identifies affected design outputs and risk controls. Make the significant-change determination a mandatory, recorded step. Keep the ECR and resulting ECO connected within a controlled product lifecycle record, so the decision, implementation and verification evidence remain traceable during an audit. Where software is affected, connect the request to IEC 62304 configuration-management and problem-resolution records. Unrelated changes should be submitted as separate requests.


How SJML helps with Engineering Change Request (ECR)

SJML manages engineering changes as part of its design, manufacturing, and regulatory services for medical devices. Its teams run phase-gate programs with built-in change control, assessing each proposed change against design inputs, risk management files, and verification evidence. For products already on the market, SJML’s sustaining engineering and regulatory sustenance services handle change governance, value engineering, and obsolescence-driven changes while minimizing revalidation and rework. Quality and regulatory specialists assess whether a change is significant enough to need a notified body or FDA notification, so decisions are recorded rather than missed.


Frequently asked questions

What is the difference between an ECR and an ECO?

An Engineering Change Request (ECR) is the proposal stage. It captures the problem and the suggested change for review. An Engineering Change Order (ECO), sometimes called an Engineering Change Notice (ECN), is the approved instruction that authorizes the change and directs how to update documents, drawings, and production. The ECR comes first; the ECO implements what the ECR requested.

Which standard governs engineering changes for medical devices?

ISO 13485:2016 clause 7.3.9 governs control of design and development changes. It requires each change to be identified, reviewed, verified, validated where appropriate, and approved before implementation. Since February 2026, the FDA QMSR (21 CFR Part 820) incorporates ISO 13485 by reference, so the same change-control discipline now applies to devices marketed in the United States.

Does every engineering change need regulatory notification?

No. Only significant changes require notification. Under EU MDR 2017/745, changes to design or intended purpose can trigger a new conformity assessment or notified body review. For US devices, a change that affects safety or effectiveness may require a new 510(k). Run a documented significant-change assessment on every ECR so notification decisions are deliberate and recorded.

What should an Engineering Change Request include?

A complete ECR states the affected item or document, the current condition, the proposed change, and the reason for it. It should reference impacted design outputs, the risk management file, and any verification or validation the change affects. Strong requests also note cost, schedule, and inventory impact so reviewers can prioritize and approve with full context.


Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries