MDD to MDR: 10 Critical Changes Medical Device Manufacturers Must Know | MDRcert

MDD to MDR: 10 Critical Changes Medical Device Manufacturers Must Know

July 15, 2026
Technical Documentation for EU MDR: Complete Guide to Annexes II and III | MDRcert

Technical Documentation for EU MDR: Complete Guide to Annexes II and III

July 15, 2026

General Safety and Performance Requirements (GSPR): Complete Guide to MDR Annex I

What Are the General Safety and Performance Requirements? The General Safety and Performance Requirements (GSPRs) are the foundational requirements that ever...

What Are the General Safety and Performance Requirements?

The General Safety and Performance Requirements (GSPRs) are the foundational requirements that every medical device must meet before it can be placed on the European market. They are set out in Annex I of the Medical Device Regulation (EU) 2017/745 and replace the Essential Requirements that existed under the previous Medical Device Directive (MDD 93/42/EEC).

The GSPRs cover all aspects of device safety, performance, design, manufacturing, packaging, labeling, and clinical evaluation. Demonstrating conformity to each applicable GSPR is a mandatory component of the technical documentation required under Annexes II and III of the MDR.

For a full overview of the MDR framework, read the EU MDR Compliance Complete Guide.

Structure of Annex I

Annex I is divided into three Chapters:

Chapter I: General Requirements (Sections 1-9)

These sections establish the core safety and performance obligations for all devices. They address risk management, benefit-risk determination, clinical evaluation, and general design principles.

Section 1,General Safety and Performance

Devices must perform in accordance with their intended purpose and be suitable for the normal conditions of use.

Section 2, Reduction of Risks as Far as Possible

Manufacturers must reduce risks as far as possible without adversely affecting the benefit-risk ratio.

Section 3, Risk Management (ISO 14971)

Section 3 requires manufacturers to establish, document, implement, and maintain a risk management system throughout the entire lifecycle of each device. The risk management process must:

  • Identify known and foreseeable hazards associated with the device
  • Estimate and evaluate the resulting risks under normal use and reasonably foreseeable misuse
  • Eliminate or control these risks through inherent safety by design, protective measures, and information for safety
  • Evaluate the impact of any information from the production phase and post-market surveillance system
  • If necessary, implement suitable changes to risk control measures

The process must be iterative. Each update to the risk management file must be documented, and the overall residual risk must be acceptable when weighed against the clinical benefits provided by the device.

MDCG guidance confirms alignment with ISO 14971:2019 as the standard approach to meeting these requirements. For detailed guidance, see /services/iso-14971-risk-management-consulting/.

Section 4, Risk Control Measures

The hierarchy of risk control measures is:

  • Inherent safety by design and manufacture (eliminate the hazard)
  • Protective measures (guards, alarms, failsafes)
  • Information for safety (warnings, precautions, training)

Section 5, Reduction of Risks Related to Use Error

Devices must be designed to reduce risks from ergonomic features, user error, and environmental conditions, taking into account the technical knowledge, experience, education, and training of the intended user.

Section 6, Safety and Performance Throughout the Lifetime

Device characteristics and performance must not be adversely affected during the lifetime of the device.

Section 7, Transport and Storage

Devices must be designed to withstand physical, chemical, and environmental stresses during normal use, transport, and storage. This includes protection against mechanical damage, temperature, humidity, and pressure changes.

Section 8, Benefit-Risk Determination

The manufacturer must demonstrate that the overall residual risk of the device is acceptable when weighed against the intended clinical benefits. This is a continuous obligation that extends throughout the device lifetime. The benefit-risk determination must be updated with post-market surveillance data.

Section 9, Devices Without an Intended Medical Purpose

Specific requirements regarding safety and clinical data for devices listed in Annex XVI.

Chapter II: Requirements for Design and Manufacture (Sections 10-22)

These sections address specific device characteristics and technologies.

Section 10, Chemical, Physical, and Biological Properties

Devices must be designed to ensure compatibility with biological tissues, cells, body fluids, and specimens.

Section 11, Infection and Microbial Contamination

Devices must be designed to reduce infection risks as far as possible.

Section 12, Devices Incorporating a Substance Considered to be a Medicinal Product

Devices that incorporate as an integral part a substance which, if used separately, would be considered a medicinal product with ancillary action, must ensure the substance is safe and effective within the device.

Section 13, Devices Incorporating Materials of Biological Origin

Devices manufactured from human or animal tissues, cells, or derivatives must minimize the risk of transmitting infectious agents.

Section 14,Construction and Environmental Properties

Devices must be designed to withstand physical, chemical, and environmental stresses during normal use.

Section 15, Devices with a Diagnostic or Measuring Function

Devices with a diagnostic or measuring function must be designed to provide sufficient accuracy, precision, and stability for their intended purpose, taking account of the intended users.

Section 16, Protection Against Radiation

Devices that emit radiation for diagnostic or therapeutic purposes must be designed to achieve the clinical benefit while minimizing radiation exposure to patients and users.

Section 17,Electronic Programmable Systems and Software (SaMD)

Software must be developed according to the state of the art, taking into account the principles of development lifecycle, risk management, verification, and validation. The MDR requires that software be developed in accordance with EN 62304 or equivalent.

Section 18, Active Devices and Devices Connected to Them

Devices intended to be connected to other devices must be designed to maintain safety and performance during connection and not impair the connected device.

Section 19, Particular Requirements for Active Implantable Devices

Active implantable devices and their accessories must comply with the relevant GSPRs plus specific requirements regarding energy sources, alarms, and electromagnetic compatibility.

Section 20, Protection Against Mechanical and Thermal Risks

Devices must be designed to protect patients and users against mechanical risks (e.g., moving parts, instability) and thermal risks (e.g., surface temperature).

Section 21, Devices Supplying Energy or Substances

Devices intended to administer medicinal products must be compatible with the medicinal products concerned and designed to minimize the risk of overdose or administration error.

Section 22, Protection Against Risks Posed by Devices Intended for Lay Persons

Devices for use by lay persons must be designed to be easy and safe to use, minimizing the risk of errors in handling or interpreting results.

Chapter III: Requirements for Information Supplied With the Device (Section 23)

Section 23.2, Label Requirements

The label must include:

  • Device name and details
  • Manufacturer name and address
  • Authorized representative in the EU
  • UDI carrier (if applicable)
  • Lot or serial number, expiry date
  • Sterilization method (if applicable)
  • Storage and handling conditions
  • Special operating instructions
  • Warnings and precautions
  • Intended patient population

Section 24.4, Instructions for Use (IFU)

The IFU must be comprehensive and include:

  • Device description and intended purpose
  • Clinical benefits and performance characteristics
  • Residual risks and undesirable side effects
  • Instructions for use, installation, and maintenance
  • Information on how to interpret results
  • Training requirements for the user
  • Information for patients about implantable devices (implant card)
  • Reference to the need to report serious incidents

How to Demonstrate GSPR Conformity

The GSPR checklist is one of the most important documents in the technical file. Every applicable requirement must be addressed with a specific reference to the method of conformity.

The standard approach is:

  • Create a GSPR checklist table listing each section of Annex I
  • For each section, determine if it is applicable or not applicable to your device
  • For applicable sections, specify the method used to demonstrate conformity
  • Reference supporting documentation such as test reports, risk management files, clinical evaluation reports, and harmonized standards
  • For non-applicable sections, provide a clear justification for why the requirement does not apply

Notified Bodies review the GSPR checklist during technical documentation review. Common deficiencies include:

  • Claiming non-applicability without adequate justification
  • Referencing harmonized standards that are outdated or do not cover the specific requirement
  • Insufficient detail on how conformity was achieved
  • Missing references to supporting documentation in the technical file
  • Failure to update the GSPR checklist after device changes

Role of Harmonized Standards

The MDR recognizes compliance with harmonized European standards as providing a presumption of conformity with the corresponding GSPRs. The most important standards include:

  • EN ISO 14971:2019 + A11:2021, Risk management (GSPR Section 3)
  • EN ISO 13485:2016 + A11:2021, Quality management systems
  • EN ISO 10993 series, Biological evaluation (GSPR Section 10)
  • EN 62366, Usability engineering (GSPR Section 5)
  • EN 62304, Software lifecycle (GSPR Section 17)
  • EN 60601 series, Electrical safety of medical electrical equipment (GSPR Section 19)
  • EN ISO 14937, Sterilization (GSPR Section 11)

The Official Journal of the European Union publishes the list of harmonized standards. Manufacturers should verify the current list before submitting a technical file, as standards are updated periodically.

Common GSPR Compliance Gaps

Incomplete applicability assessment: Manufacturers sometimes skip GSPR sections that are applicable, assuming they do not apply to their device type. Each section must be formally assessed.

Generic justifications: Stating compliance without specific references to test reports, standards, or documentation is not sufficient. Notified Bodies expect traceability between the GSPR checklist and the supporting evidence.

Failure to update: The GSPR checklist must be updated when the device changes or when new standards are published. An outdated checklist can result in non-conformities during surveillance audits.

Missing state-of-the-art consideration: The MDR requires that devices conform to the state of the art. Manufacturers must demonstrate awareness of current clinical practice, alternative treatments, and evolving safety expectations.

Related Content

References

Frequently Asked Questions (FAQ)

What do the General Safety and Performance Requirements cover?

The GSPRs in Annex I cover all aspects of device safety, performance, design, manufacturing, packaging, labeling, and clinical evaluation. Annex I is divided into three Chapters: Chapter I covers general requirements, Chapter II covers design and manufacture requirements, and Chapter III covers information supplied with the device.

How must a manufacturer demonstrate compliance with the GSPRs?

Manufacturers must create a GSPR checklist table listing each section of Annex I, determine applicability, specify the method of conformity for each applicable section, reference supporting documentation such as test reports and risk management files, and justify any non-applicable sections. Notified Bodies review the checklist during technical documentation review.

What should be included in a GSPR checklist?

A GSPR checklist should list every section of Annex I with columns for applicability status, method of conformity, reference to supporting documentation, and justification for non-applicable sections. The checklist must be updated when the device changes or when new harmonised standards are published.

What role do harmonised standards play in GSPR compliance?

Compliance with harmonised European standards provides a presumption of conformity with corresponding GSPRs. Key standards include EN ISO 14971 for risk management, EN ISO 13485 for quality management, the EN ISO 10993 series for biological evaluation, EN 62304 for software, and the EN 60601 series for electrical safety.

How do GSPRs differ from the Essential Requirements under the MDD?

The GSPRs under MDR Annex I replace the Essential Requirements under MDD Annex I. While the structure is similar, the GSPRs are more detailed and prescriptive, with expanded requirements for clinical evaluation, risk management throughout the device lifecycle, software validation, nanomaterial safety, and information supplied to patients such as the implant card.

Stay Compliant. Stay Ahead.

Join the MDRCert Newsletter

Get the latest MDR/IVDR updates, compliance checklists & expert tips delivered weekly. No spam, ever