PSUR for medical devices: EU MDR requirements explained
%20for%20medical%20devices%20what%20FDA%20expects%20in%202026%20(1).png?width=800&height=400&name=Software%20bill%20of%20materials%20(SBOM)%20for%20medical%20devices%20what%20FDA%20expects%20in%202026%20(1).png)
A periodic safety update report, or PSUR, is a recurring summary of post-market surveillance data and safety conclusions that the EU requires for higher-risk medical devices and in vitro diagnostics. Manufacturers prepare one under Article 86 of the EU Medical Device Regulation (MDR) or the parallel Article 81 of the EU In Vitro Diagnostic Regulation (IVDR), update it on a set schedule tied to the device's risk classification, and submit it to a notified body for as long as the device stays on the market.
Where that submission actually goes right now is more complicated than the regulation implies. EUDAMED, the EU's central database for medical devices, reached a milestone on May 28, 2026, when four of its six modules officially became mandatory, a rollout the European Commission had pushed back for years. One module missed that deadline: Vigilance and Post-Market Surveillance, the specific system Article 86 names as the required channel for PSUR submissions. Until that module goes live, sometime in 2027 at the earliest, manufacturers keep submitting PSURs the way they always have: through whatever process their notified body already has in place, not through EUDAMED.
BONUS RESOURCE: Click here to download your free PDF copy of our Periodic Safety Update Report template.
What is a PSUR?
A PSUR is a recurring summary of the post-market surveillance data a manufacturer has collected on a device, along with the conclusions drawn from it. Under Article 86 of MDR (and the parallel Article 81 of IVDR), the report must cover the conclusions of the device's benefit-risk determination, the findings of any post-market clinical follow-up activity, a description of preventive or corrective actions taken along with the rationale behind them, and the device's sales volume with an estimate of the population using it and, where practical, how often it gets used.
The PSUR becomes part of a device's technical documentation once submitted, and it stays there for the life of the device. It is not a one-time filing. Each update needs to reflect what actually happened with the device since the last version, not a restatement of the same risk language with updated dates.
Who needs a PSUR, and how often?
MDR requires a PSUR for Class IIa, IIb, and III devices. IVDR applies the same logic to Class C and D in vitro diagnostics. Update frequency depends on classification. Lower-risk devices file a Post-Market Surveillance Report (PMSR) instead, and the two reports are often confused. A PMSR covers similar ground: results and conclusions from surveillance activity, plus any corrective or preventive actions. But it stays on file. MDR recommends updating it at least every three years and making it available to a competent authority on request, while a PSUR goes to a notified body on a fixed cycle regardless of whether anything eventful happened that year.
|
Type |
Classification under MDR or IVDR |
PMSR or PSUR |
Submission Protocol |
Update Frequency |
|
MEDICAL DEVICE |
Class I |
PMSR |
Upon request |
As necessary |
|
Class IIa |
PSUR |
During Conformity Assessment for Notified Body review |
Every 2 years, |
|
|
Class IIb (non-implantable) |
PSUR |
During Conformity Assessment for Notified Body review |
Every year, |
|
|
Class IIb |
PSUR |
Via EUDAMED for Notified Body review |
Every year, |
|
|
Class III (all) |
PSUR |
Via EUDAMED for Notified Body review |
Every year, |
|
|
IVD |
Class A, B |
PMSR |
Upon request |
As necessary |
|
Class C |
PSUR |
During Conformity Assessment for Notified Body review |
Every year, |
|
|
Class D |
PSUR |
During Conformity Assessment for Notified Body review |
Every year, |
Where do you submit a PSUR right now?
Article 86(2) sends Class III and implantable device PSURs to the notified body through an electronic system, and the regulation clearly means EUDAMED. That system is the Vigilance and Post-Market Surveillance module. It's one of the two EUDAMED modules still under development after the May 2026 milestone, and until the European Commission declares it functional and starts the six-month countdown to mandatory use, manufacturers keep submitting PSURs through whatever channel their notified body already has in place, whether that is a dedicated portal or a direct upload during a surveillance audit.
Class IIa devices and non-implantable Class IIb devices follow a lighter path under Article 86(3). Their PSURs stay inside the technical documentation and are made available to the notified body and, on request, to competent authorities. There is no proactive submission requirement for this group. A notified body simply expects to find a current PSUR when it reviews the file.
What MDCG 2022-21 clarifies for manufacturers
The Medical Device Coordination Group's guidance document MDCG 2022-21, published in December 2022, answers two questions that trip up manufacturers building their first PSUR process.
The first is what counts as "a device" for PSUR purposes. A manufacturer does not need a separate PSUR for every SKU. MDCG 2022-21 defines the device as a model tied to one Basic UDI-DI, so variants and sizes sharing that identifier can be covered in a single report.
The second is when the clock starts. Data collection begins from the date of the device's first EU MDR Statement of Conformity, or from the date it was first placed on the market if no conformity assessment was required. Legacy devices carried over under the MDR transition extension in Regulation (EU) 2023/607 follow a separate rule: the first PSUR must cover the period starting May 26, 2021, and be issued within one year for Class IIb and III devices, or two years for Class IIa devices, of the first MDR conformity assessment statement.
What belongs in a PSUR?
At minimum, your PSUR should include the following:
-
Your postmarket surveillance data
-
The conclusions of your benefit-risk analysis
-
A description of any CAPAs and the rationale behind them
-
The findings of your Post Market Clinical Follow-up
-
The device’s sales volume and an estimate of the user population
-
The frequency of the device’s usage (if practical)
-
An analysis and summary of all the information listed above
This last point is important, because the PSUR is not about checking boxes. The Periodic Safety Update Report is intended to be an analysis of the postmarket data your company has actively collected. It’s a meaningful, regularly updated report that should help both regulators and internal stakeholders understand the safety and efficacy of your device during its time on the market.
Where manufacturers go wrong with the PSUR
The PSUR is meant to be an analysis, not a template exercise. A report that lists complaint counts and CAPA numbers without drawing a conclusion about the benefit-risk profile fails the intent of Article 86, even if every required field is technically present. Reviewers read a PSUR looking for judgment, not just data.
The second recurring failure is treating post-market clinical follow-up as a separate workstream that gets bolted onto the PSUR at the last minute. PMCF findings are supposed to feed directly into the benefit-risk conclusion, and a PSUR built without that connection tends to read as two documents stapled together rather than one coherent analysis.
The third is data fragmentation. Complaints sit in one spreadsheet, CAPA records in another, sales figures in a CRM export, and PMCF data in a consultant's report. Assembling a PSUR from four disconnected sources under a deadline is where most of the actual pain in this process comes from.
The manufacturers who handle PSURs well are the ones whose complaint handling, CAPA management, and PMCF data already live in one connected system. When a complaint gets logged, it should already be linked to the CAPA it triggers and traceable to the device's risk file, so that pulling a PSUR together is a matter of running a report rather than reconstructing a timeline from memory.
BONUS RESOURCE: Click here to download your free PDF copy of our Periodic Safety Update Report template.
See what a connected quality system does for your next PSUR
MDR and IVDR make it clear that postmarket surveillance and vigilance reporting should not be passive or reactive processes. It’s up to medical device manufacturers to consistently capture and analyze data on the performance of devices and ensure the results of that analysis are available to regulatory bodies.
With Greenlight Guru, complaints, CAPAs, training records, and design changes stay linked from the moment they open, so pulling together the benefit-risk analysis at the center of a PSUR means running a report instead of chasing four departments for their version of events.
If you want to see what it looks like to treat postmarket surveillance proactively, rather than reactively, then get your free demo of Greenlight Guru today!
Greenlight Guru is the leading cloud-based platform purpose-built for MedTech companies. The end-to-end solution streamlines product development, quality management, and clinical data management by integrating cross-functional teams, processes, and data throughout the entire product lifecycle. Greenlight Guru’s...
Related Posts
Greenlight Guru Announces True Quality Summit Series: EU MDR & IVDR
Greenlight Guru Introduces Export API for a Connected Quality Management System
Greenlight Guru Introduces Newly Expanded Global Partner Program
Get your free Template
Periodic Safety Update Report Template
.png?width=250&height=321&name=Periodic%20Safety%20Update%20Report%20Template%20-%20slide%20in%20cover%20(1).png)



