Designing a PMCF survey that holds up under MDR scrutiny

August 20, 2026 ░░░░░░

Designing a PMCF survey that holds up under MDR scrutiny

Imagine a quality or clinical lead walking a notified body reviewer through a PMCF survey, they feel great about the conversation, but then they get a finding anyway. Not because the survey was inaccurate, or because the team skipped a step on purpose... But because the instrument itself, the actual questions, the sample size logic, the way responses were validated, was never designed for that kind of scrutiny in the first place.

We've already covered the boundary question of when a PMCF survey is even the right tool, and when it becomes something closer to a clinical investigation. That's a scope question. This is a different one. Assume the survey belongs inside your PMCF plan. Assume it clears the boundary test. The question this article answers is narrower and more mechanical: how do you actually build the instrument so the data it produces holds up once a reviewer starts asking why?

Why a survey can be legitimate and still fail review

A PMCF survey can be the right activity for a device and still generate evidence that a notified body rejects. That distinction trips people up because it feels like it should not be possible. If the activity is appropriate, shouldn't the data be fine?

It's not that simple, and here's why: MDCG 2020-6 grades PMCF evidence on a hierarchy, and a survey's position on that hierarchy depends entirely on how it was constructed, not on the fact that a survey was chosen. A retrospective, unsupervised survey with vague questions and no sample size justification sits near the bottom of that scale. A prospective, validated instrument with a defensible sample and documented data integrity controls ranks much higher, sometimes high enough to support PMCF evidence for a class III device. Same activity type but completely different evidentiary weight.

Some teams treat survey design as a formality, something to move through quickly so they can get to the part that feels like real clinical work. But that gets the order backward. The design decisions made before a single response comes in are what determine whether the resulting data means anything at all.

Question construction: map every item to the approved indication

The single most common design failure is a question that drifts outside the device's approved intended purpose. A question that asks about symptom relief in general, without anchoring it to the specific indication and patient population in the instructions for use, invites the kind of off-label signal that turns a clean PMCF survey into a scope problem.

The fix isn't complicated, but it takes discipline. Before a question goes into the instrument, someone should be able to point to the specific line in the approved labeling that the question is measuring against. If a question can't be traced back to a defined performance or safety attribute within the approved indication, it doesn't belong in the survey. Cut it or rewrite it.

Wording matters almost as much as scope. Compound questions, the kind that ask two things at once, produce data that cannot be cleanly analyzed later. "Did the device reduce your symptoms and was it easy to use" is two questions disguised as one. Split them. Leading language does the same kind of damage, but less obviously. A question that assumes a positive outcome before the respondent answers biases the response before the data ever reaches your dataset.

Validated instruments earn their reputation here. When a validated, published questionnaire exists for the outcome you are measuring, use it instead of writing your own from scratch. A reviewer who sees a validated instrument doesn't have to take your word for its reliability. A homegrown questionnaire, however well-intentioned, is one more thing you have to defend from first principles.

BONUS RESOURCE: Click here to download our 15-in-1 Clinical Investigations Content Bundle.

Sample size: a number you can defend, instead of explaining it away

Sample size is where a lot of  hand-waving happens. Teams pick a number that feels achievable given their patient population, then build a justification backward from that number. Reviewers can usually tell when this happened, because the justification looks more like an explanation than a calculation.

A defensible sample size starts with the question you're trying to answer, not the number of patients you expect to reach. What effect size matters clinically. What variability exists in your outcome measure. What confidence level and power the evidence needs to carry, given the device's risk classification. Those inputs produce a number. If your achievable population cannot reach that number, that is useful information too. It tells you the survey alone can't carry the evidentiary weight you need, and you may need to combine it with another PMCF activity or extend the collection window.

Lower-class devices get some latitude here, and it's important to know where that latitude applies rather than assuming it covers everything. A smaller, well-justified sample for a class I or class IIa device can be entirely appropriate. The justification still has to exist on paper. "We surveyed everyone we could reach" is not a sample size rationale, even when it happens to be a reasonable number.

For higher-risk devices, the standard tightens considerably. A prospective, adequately powered survey with a documented statistical rationale is what moves a survey up the MDCG 2020-6 evidence hierarchy. Skipping that rationale does not just weaken the survey. It caps how much evidentiary credit the survey can ever receive, regardless of how many responses come in.

Response validity: the part most teams design last and regret first

Data integrity controls are often the last thing added to a PMCF survey design, tacked on after the questions and the recruitment plan are already locked. That ordering causes problems, because validity controls work best when they shape the instrument from the start rather than get bolted onto it afterward.

Start with who is answering. If your intended respondent is a patient using a device at home, a survey design that can't verify the respondent's identity or exclude duplicate submissions creates an opening a reviewer will find. Simple controls, unique access links, single-submission logic, basic identity checks tied to your subject list, close that gap without turning the survey into a full clinical investigation workflow.

Missing data needs a plan before collection starts, not after. Decide in advance how you will handle partial responses, whether a threshold of completion is required for a response to count, and how you will document exclusions. A survey that drops incomplete responses without a documented rule looks, to a reviewer, indistinguishable from a survey that dropped inconvenient answers.

Anonymization deserves a real decision rather than a default setting. For most patient and lay-user surveys, full anonymization is the safer path, and it removes an entire category of data protection questions before they come up. The tradeoff is that anonymized responses are harder to link to longitudinal follow-up if your PMCF plan calls for tracking the same patients over time. Decide which one your evidence strategy actually needs before the survey goes live, not after the first response comes in.

BONUS RESOURCE: Click here to download our 15-in-1 Clinical Investigations Content Bundle.

Connecting the survey to the rest of your PMCF plan

None of this happens in isolation. A PMCF survey is one activity inside a broader PMCF plan, and a survey that is well designed on its own terms can still fail if it is disconnected from what the rest of the plan is supposed to demonstrate. The plan sets the evidence objectives. The survey is one instrument you are using to meet them. If you haven't yet worked through how a PMCF survey fits alongside your other PMCF activities, our guide to developing a PMCF plan covers that structure in detail.

It is also worth considering when a survey is the right tool at all before you invest in designing one. Our guide to when PMCF surveys work and when they don't walks through that decision. This article assumes you have already made that call and are past the boundary question of where a survey ends and a clinical investigation begins. What follows here is the mechanical work of building an instrument that produces evidence a notified body will actually accept.

Where the tooling comes in

The instrument matters more than the platform, but the platform still matters. Question logic, branching, single-submission controls, and audit trails are hard to enforce consistently in a general-purpose survey tool or a spreadsheet stitched together with a form builder. A validated electronic data capture system built for medical device studies handles those controls natively, which means your clinical team spends its time on the questions and the sample size logic instead of rebuilding data integrity safeguards from scratch every time a new PMCF survey goes out.

Greenlight Guru's EDC was built for exactly this kind of work, structured PMCF surveys alongside full clinical investigations, with the traceability and validation documentation a notified body expects to see. If you are designing your next PMCF survey and want a system that carries the audit trail with it, take a look at how Greenlight Guru Clinical supports PMCF data collection.

Keep reading

If you are building out your PMCF evidence strategy, these related guides go deeper on the specific components:

Etienne Nichols is the Head of Industry Insights & Education at Greenlight Guru. As a Mechanical Engineer and Medical Device Guru, he specializes in simplifying complex ideas, teaching system integration, and connecting industry leaders. While hosting the Global Medical Device Podcast, Etienne has led over 200...

BONUS RESOURCE: 15-in-1 Clinical Investigations Content Bundle
Download now
15-in-1 clinical investigations content bundle (new)
Search Results for:
    Load More Results