MDR Annex II / III are the two annexes of EU Regulation 2017/745 that define the technical documentation a medical device manufacturer must compile to show conformity. Annex II sets out the core technical file, covering design, manufacturing, and clinical evidence. Annex III sets out the documentation for post-market surveillance.
What is MDR Annex II / III?
MDR Annex II / III refers to two linked annexes of the EU Medical Device Regulation (MDR), Regulation (EU) 2017/745. Annex II lists the technical documentation demonstrating that a device meets the regulation; Annex III lists the documentation for post-market surveillance (PMS). Article 10(4) requires every manufacturer, except makers of custom-made devices, to prepare and keep this documentation up to date, regardless of risk class.
Together, the two annexes form what most teams call the technical file. It is the evidence base that a notified body reviews before issuing a CE certificate for Class IIa, IIb, and III devices. Class I manufacturers self-certify but still maintain the same file.
Why MDR Annex II / III matters in medical device development
A weak technical file is one of the most common reasons a notified body raises nonconformities and stalls certification. No accepted file means no CE certificate, and without the CE mark, the device cannot legally reach the EU market.
The file is also a standing audit target. Notified bodies sample it during surveillance audits, and competent authorities can request it. Since the MDR replaced the Medical Device Directive, expectations on clinical and post-market data have risen sharply, and a file that passed under the MDD often fails under Annex II without rework.
How the MDR Annex II / III technical documentation is structured
Annex II is organized into defined sections, and a file built to it usually contains:
- Device description and specification, including variants, accessories, and reference to earlier device generations.
- Information supplied by the manufacturer: labeling and instructions for use in the required EU languages.
- Design and manufacturing information, covering design stages and the production sites and processes.
- General safety and performance requirements (GSPR), the Annex I checklist, mapped to the solutions adopted and the harmonized standards applied.
- Benefit-risk analysis and risk management, aligned with ISO 14971.
- Product verification and validation: preclinical and clinical data; biocompatibility per ISO 10993; electrical safety and EMC per the IEC 60601 series; software lifecycle records per IEC 62304; usability per IEC 62366-1; and the clinical evaluation report.
Annex III covers the post-market side: the PMS plan; the periodic safety update report (PSUR), or PMS report, depending on device class; and the post-market clinical follow-up (PMCF) plan and evaluation. Classification under Annex VIII sets the conformity assessment route in Annexes IX to XI, which determines how deeply a notified body examines the file.
The MDR also requires the file to be clear, organized, readily searchable, and unambiguous. Many teams structure submissions in line with MDCG and Team NB guidance to meet reviewer expectations.
Common challenges and best practices
The frequent failure is treating the technical file as a one-time deliverable written near the submission deadline. By then, the design rationale and test context have faded, and reconstructing them is slow. GSPR justifications are identified as the top nonconformity: teams mark a requirement as met without citing the evidence or standard that supports it.
Clinical evidence is the second pressure point. Equivalence claims that worked under the MDD now face hard scrutiny, and thin PMCF planning in Annex III triggers questions that delay the review.
Good practice is to build the file alongside development, not after it. Keep a traceability matrix linking user needs, design inputs and outputs, risk controls from the ISO 14971 file, and verification and validation results. Treat it as living: changes to design, suppliers, or clinical data should update both annexes. Map every GSPR line to a named piece of evidence, not a generic statement.
How SJML helps with MDR Annex II / III
SJML supports EU MDR technical documentation as part of its compliance services for medical device manufacturers. The team helps with device classification, CE marking strategy, and building or remediating the technical file and design history file across Class I, II, and III devices. Work spans GSPR mapping, ISO 14971 risk files, biocompatibility and usability documentation, clinical evaluation, and post-market surveillance planning, including PMCF and EUDAMED-related activity. Engineering, design, and in-house test capability sit alongside the regulatory function, so verification and validation evidence and the documentation that cites it are developed together.
Talk to SJML’s QARA team to learn more.
Frequently asked questions
Annex II defines the main body of technical documentation demonstrating that a device conforms to the EU MDR 2017/745, covering design, manufacturing, GSPR, risk management, and clinical evidence. Annex III defines the documentation specific to post-market surveillance: the PMS plan, the periodic safety update report (PMS report), and the post-market clinical follow-up plan and evaluation.
Under Article 10(4) of the EU MDR 2017/745, every medical device manufacturer, except makers of custom-made devices, must prepare and maintain technical documentation in accordance with Annexes II and III. This applies to all risk classes. Class I manufacturers self-certify without a notified body but still keep the same file ready for inspection.
In practice, yes. The MDR technical file, also called the technical documentation or design dossier, is built directly from Annexes II and III. Annex II provides the skeleton for the core file; Annex III adds the post-market surveillance sections. Together, they define what constitutes a complete EU MDR technical file.
It should be a living record. Update it whenever the design, materials, suppliers, labeling, or clinical evidence change, and review it according to the schedule set in your PMS plan. Annex III outputs, such as PSURs and PMCF reports, feed back into Annex II, so the two annexes are maintained together throughout the device lifecycle.
Related terms
EU MDR 2017/745
Design History File
General Safety and Performance Requirements
Clinical Evaluation Report
Post-Market Surveillance