Vigilance

Vigilance is the medical device process for detecting, evaluating, and reporting serious incidents and field safety corrective actions to regulators after a product reaches the market. Under EU MDR 2017/745 (Articles 87 to 92) and FDA 21 CFR Part 803, manufacturers must report qualifying events within fixed timelines to protect patients.


What is vigilance?

Vigilance sits inside post-market surveillance, the broader system a manufacturer uses to monitor a device once it is in clinical use. Where post-market surveillance gathers data continuously, vigilance is the reporting layer that acts on the events that matter most: deaths, serious injuries, and malfunctions that could cause them.

The term appears in two regulatory worlds with different meanings. In the European Union, MDR refers to the Medical Device Regulation, and vigilance is defined in Articles 87 to 92. In the United States, MDR stands for Medical Device Reporting, codified in 21 CFR Part 803. Both describe the same duty: notify the appropriate regulatory authority when a device is linked to serious harm or a reportable malfunction.


Why vigilance matters in medical device development

A missed or late vigilance report is one of the fastest ways to trigger regulatory action. FDA warning letters and Form 483 observations frequently cite failures in Medical Device Reporting (MDR), while EU Competent Authorities may escalate issues to the Notified Body or impose market restrictions. Delayed reporting also postpones identification of safety signals, potentially allowing unsafe devices to remain in clinical use.

Vigilance also directly influences engineering and quality activities. Reported incidents become inputs to ISO 14971 risk management, potentially requiring updates to risk files, labeling, design controls, verification activities, or manufacturing processes. A single Field Safety Corrective Action (FSCA) may lead to product recalls, field upgrades, design changes, and significant commercial impact.

Building vigilance into the quality management system from the beginning reduces regulatory risk and minimizes costly post-market remediation.


How vigilance works

Vigilance typically operates as a structured workflow integrated with complaint handling and CAPA processes.

A typical process includes:

  • Intake and triage. Complaints, service reports, customer feedback, and returned devices are screened to determine whether they meet the regulatory definitions of a reportable event.
  • Reportability assessment. A qualified reviewer evaluates whether the event qualifies as a serious incident (EU) or reportable death, serious injury, or malfunction (US), documenting both the decision and the awareness date that starts the reporting timeline.
  • Regulatory reporting. Manufacturers submit the required reports using the appropriate regulatory reporting system and provide follow-up reports as additional investigation results become available.
  • Corrective action. Where necessary, manufacturers initiate Field Safety Corrective Actions (FSCAs), issue Field Safety Notices (FSNs), monitor implementation, and update risk management documentation.

Regulatory reporting timelines are strictly defined.

Under EU MDR Article 87:

  • Serious public health threat: Immediately, and no later than 2 calendar days
  • Death or unanticipated serious deterioration in health: No later than 10 calendar days
  • Other serious incidents: No later than 15 calendar days

Under FDA 21 CFR Part 803:

  • Death, serious injury, or reportable malfunction: Within 30 calendar days
  • Events requiring remedial action to prevent substantial public harm: Within 5 working days

Reporting mechanisms differ between jurisdictions.

Within Europe, although the first four EUDAMED modules became mandatory on 28 May 2026 under Commission Decision (EU) 2025/2371, the Vigilance Module remains under development. Until it becomes operational, manufacturers continue submitting serious incident reports directly to national Competent Authorities using the Manufacturer Incident Report (MIR) form.

In the United States, reports are submitted electronically through the FDA eMDR system and become part of the public MAUDE database.


Common challenges and best practices

One of the most common failures is inconsistent reportability assessment. Organizations either over-report non-reportable events or fail to recognize reportable incidents within the required timelines. Clearly documented decision criteria and designated reviewers significantly reduce these errors.

Another common weakness is poor integration between complaint handling, vigilance, CAPA, and risk management. When each function maintains separate records, inconsistencies arise that auditors and regulators readily identify.

Successful manufacturers generally:

  • Define clear reportability criteria and document every decision.
  • Assign responsibility for reportability assessment to trained personnel.
  • Integrate complaints, vigilance, CAPA, and risk management into a single controlled process.
  • Establish predefined thresholds for trend reporting under EU MDR Article 88.
  • Maintain complete audit trails for both reportable and non-reportable events.
  • Feed vigilance outcomes directly back into the ISO 14971 risk management process and post-market surveillance activities.

How SJML helps with vigilance

SJML delivers vigilance management through its Compliance-as-a-Service offering as part of a comprehensive post-market surveillance program. Its QARA specialists support complaint intake, adverse event assessment, reportability evaluations under both EU MDR and FDA requirements, preparation of incident reports, Field Safety Corrective Actions (FSCAs), Field Safety Notices (FSNs), and Periodic Safety Update Reports (PSURs).

SJML also integrates vigilance with ISO 14971 risk management, CAPA, post-market surveillance, EUDAMED readiness, and technical documentation maintenance, ensuring that safety signals are translated into documented product improvements throughout the device lifecycle.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between vigilance and post-market surveillance?

Post-market surveillance (PMS) is the ongoing system used to collect, review, and analyze information about a medical device after commercialization.
Vigilance is one component of PMS that focuses specifically on detecting, evaluating, and reporting serious incidents and Field Safety Corrective Actions (FSCAs) to regulatory authorities within legally required timelines.
PMS is continuous and proactive, while vigilance is event-driven and regulatory reporting focused.

What are the EU MDR serious incident reporting timelines?

Under EU MDR Article 87, reporting timelines begin from the manufacturer’s awareness date.
Serious public health threat: Immediately and no later than 2 calendar days
Death or unanticipated serious deterioration in health: Within 10 calendar days
Other serious incidents: Within 15 calendar days
Meeting these timelines is a legal obligation for manufacturers.

How does vigilance relate to CAPA?

Although closely connected, vigilance and CAPA serve different purposes.
Vigilance is the external regulatory reporting process that informs Competent Authorities about serious incidents and Field Safety Corrective Actions.
CAPA (Corrective and Preventive Action) is the internal quality system process used to investigate root causes, implement corrective actions, verify effectiveness, and prevent recurrence.
A reportable incident often initiates both processes simultaneously.

Is vigilance reported through EUDAMED yet?

Not completely.
While the first four EUDAMED modules became mandatory on 28 May 2026, the Vigilance and Post-Market Surveillance modules remain under development.
Until those modules become operational and mandatory, manufacturers continue reporting serious incidents and Field Safety Corrective Actions directly to national Competent Authorities, typically using the Manufacturer Incident Report (MIR) form.


Related terms

  • Post-Market Surveillance (PMS)
  • Field Safety Corrective Action (FSCA)
  • CAPA (Corrective and Preventive Action)
  • Complaints Handling
  • Risk Management (ISO 14971)

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant