A practical guide to building an IVDR GSPR matrix that connects each applicable requirement to its conformity method, standards, evidence and technical documentation location.
1. What Are IVDR GSPRs?
Article 5(2) of Regulation (EU) 2017/746 requires every in vitro diagnostic (IVD) medical device to meet the general safety and performance requirements in Annex I that apply to it, taking its intended purpose into account 1. Article 5(3) adds that the demonstration of conformity must include a performance evaluation under Article 56 1.
Annex I has three chapters 1:
| Chapter | Title | Sections |
|---|---|---|
| Chapter I | General requirements | 1 to 8 |
| Chapter II | Requirements regarding performance, design and manufacture | 9 to 19 |
| Chapter III | Requirements regarding information supplied with the device | 20 |
There are 20 numbered sections. Most have lettered or numbered subclauses, so a working matrix has many more than 20 rows. Section 20 alone covers the label (20.2), sterile packaging (20.3), the instructions for use (20.4.1) and extra content for self-testing and near-patient testing devices (20.4.2) 1.
The IVDR list differs from Annex I of Regulation (EU) 2017/745, the Medical Device Regulation (MDR), which has 23 requirements. IVDR Chapter I has eight sections and MDR Chapter I has nine. IVDR Section 9 on performance characteristics has no MDR counterpart. An MDR matrix cannot be turned into an IVD matrix by renumbering.
2. Is a GSPR Checklist Mandatory?
The regulation does not name a document called a "GSPR checklist". What it requires is the content.
Article 10(4) obliges the manufacturer to draw up and keep up to date technical documentation that allows conformity with the regulation to be assessed, containing the elements in Annexes II and III 1. Annex II opens by requiring the technical documentation to be presented in a clear, organized, readily searchable and unambiguous manner 1.
Annex II Section 4 covers the general safety and performance requirements. It requires the documentation to demonstrate conformity with the applicable Annex I requirements, including the justification, validation and verification of the solutions adopted, and lists four elements 1:
- the requirements that apply to the device, and an explanation of why the others do not apply;
- the method or methods used to demonstrate conformity with each applicable requirement;
- the harmonized standards, common specifications or other solutions applied;
- the precise identity of the controlled documents that offer evidence of conformity, with a cross-reference to where that evidence sits in the full technical documentation.
A checklist with an applicability column and a yes/no compliance column supplies element 1 and leaves out 2, 3 and 4. The matrix is the table that presents all four together.
The rest of the technical documentation, including the Annex II sections on device description, manufacturing information and product verification and validation, and the Annex III post-market surveillance file, is covered in the EvySaif IVDR technical documentation guide.
3. The GSPR Matrix as an Evidence Map
A GSPR matrix should let a reviewer move from an IVDR requirement to the controlled document that demonstrates conformity, and back from that document to the requirement it supports. Each row answers seven questions in order.

- Which Annex I requirement or subclause is this?
- Does it apply to this device?
- Why, or why not?
- How is conformity demonstrated?
- Which harmonized standard, common specification or other solution is used?
- Which controlled document holds the evidence?
- Where in the technical documentation is that document?
A GSPR matrix is not a substitute for the technical documentation. It is the traceability layer that connects the requirements to the reports, specifications, studies and labeling that make up the file. A complete matrix with missing reports behind it demonstrates nothing.
EvySaif assesses Annex I applicability for each IVD as the first step of its IVDR technical documentation service, so that the matrix structure is fixed before evidence generation begins.
4. The 20 IVDR GSPR Sections and the Evidence Typically Used to Demonstrate Conformity
The table maps each Annex I section to the documents usually relied on. The evidence column names document types, not a fixed set every device must hold. Which documents a device needs depends on its class, technology and intended purpose.
| GSPR | Subject (Annex I) | Conformity method | Evidence typically used |
|---|---|---|---|
| 1 | Performance as intended; safety and performance under normal conditions of use; acceptable benefit-risk | Performance evaluation; risk management | Performance evaluation report; risk management report; intended purpose statement |
| 2 | Risks reduced as far as possible without harming the benefit-risk ratio | Risk management | Risk management plan and report; residual risk acceptability record |
| 3 | Risk management system established, documented, implemented and maintained through the lifecycle | Risk management | Risk management plan; hazard analysis; risk management report; post-market inputs |
| 4 | Risk control measures in the order eliminate, protect, inform | Design controls; verification of risk controls | Risk control table with verification references; design verification reports; warnings in the instructions for use |
| 5 | Risks from use error reduced; intended user considered | Usability engineering | Usability engineering file; formative and summative evaluation reports; user profile |
| 6 | Characteristics and performance kept during the lifetime under normal use, maintenance and calibration | Stability and reliability testing | Shelf-life, in-use and transport stability reports; reliability and calibration data |
| 7 | Protection during transport and storage | Packaging validation; transport simulation | Packaging validation report; transport study; storage condition study |
| 8 | Known and foreseeable risks and undesirable effects minimized and acceptable against the benefit | Benefit-risk determination | Benefit-risk analysis in the risk management report and the performance evaluation report |
| 9 | 9.1 analytical and clinical performance; 9.2 stability; 9.3 metrological traceability; 9.4 performance in self-testing and near-patient testing | Performance evaluation | Scientific validity report; analytical performance report; clinical performance report; stability reports; traceability documentation for calibrators and controls; lay-user or near-patient study |
| 10 | Chemical, physical and biological properties; compatibility with specimens and analytes; contaminants and residues | Material characterization; verification | Material specifications; biological safety assessment where relevant; residue and leachables data; interference studies |
| 11 | Infection and microbial contamination; sterile supply | Sterilization validation; contamination control | Sterilization validation; bioburden and packaging integrity data; handling instructions |
| 12 | Materials of animal, human or microbial origin | Sourcing and processing controls | Sourcing records; inactivation and processing validation; supplier certificates |
| 13 | Construction and interaction with the environment; compatibility with other devices; electromagnetic and physical hazards; specimen receptacles | Design verification; compatibility testing | Compatibility and interoperability reports; electromagnetic compatibility report; mechanical design verification |
| 14 | Diagnostic or measuring function: accuracy, precision, stability, units, readable display | Measurement performance verification | Accuracy and precision data; measuring range and units specification; display verification |
| 15 | Protection against radiation | Radiation safety verification | Radiation emission test report; shielding documentation; or a documented reason for non-applicability |
| 16 | Electronic programmable systems and software: reliability and single fault condition; lifecycle, security, verification and validation; mobile platforms; IT environment requirements | Software lifecycle process | Software development plan; requirements and architecture; verification and validation reports; cybersecurity risk assessment; anomaly list; minimum hardware and IT specification |
| 17 | Devices connected to or equipped with an energy source | Electrical safety testing | Electrical safety test report; battery and power supply verification; alarm verification where applicable |
| 18 | Protection against mechanical and thermal risks | Design verification | Mechanical hazard assessment; surface temperature testing; guarding of moving parts |
| 19 | Self-testing and near-patient testing: performance suited to the user, reduced use error, understandable results | Usability and lay-user performance evaluation | Lay-user study; near-patient environment performance data; result interpretation verification; usability file |
| 20 | Label and instructions for use: 20.1 general; 20.2 label; 20.3 sterile packaging; 20.4.1 instructions for use; 20.4.2 extra content for self-testing and near-patient testing | Labeling review against each subclause | Label specifications; instructions for use with a clause-by-clause checklist; symbol check; translations; sterile packaging label |
Sections 9.3 and 9.4 exist only in the IVDR. Section 9.3 requires the values assigned to calibrators and control materials to be traceable to reference measurement procedures or reference materials of a higher metrological order, and, where available, to certified reference materials or reference measurement procedures 1. Section 9.4 requires performance to be checked with lay persons for self-testing devices and in the actual use environments for near-patient testing devices, such as the patient home, emergency units and ambulances 1.
5. How to Build the Evidence Matrix
A matrix that meets the four elements of Annex II Section 4 has these columns.
| Column | Content | Annex II Section 4 element |
|---|---|---|
| GSPR number and subclause | For example 9.1(a), 16.2, 20.4.1(u) | 1 |
| Requirement | Short paraphrase of the Annex I clause | 1 |
| Applies | Yes, No, or Partially | 1 |
| Justification | The device property that makes the requirement apply or not apply | 1 |
| Conformity method | Verification, validation, performance evaluation, risk management, labeling review | 2 |
| Standard, common specification or other solution | Standard with edition and year; common specification with annex; MDCG guidance; internal procedure | 3 |
| Evidence document | Document number, title, revision | 4 |
| Location | Section, table or page inside the document; folder in the technical documentation | 4 |
| Status and comments | Complete, open, notified body query reference | Internal control |
The revision column records which version of each report the claim rests on, because results can change between revisions. The edition column does the same for standards: a matrix citing ISO 14971 without the year does not show whether the risk management file follows the 2019 edition.
A device supplied in several configurations (kit sizes, analyzer models, reagent lots) needs either one matrix per configuration or a column showing which configurations each row covers.
Download the IVDR GSPR Evidence Matrix template (PDF)
6. Applicability and Non-Applicability
Annex II Section 4(a) requires an explanation of why non-applicable requirements do not apply 1. The explanation names a property of the device:
- Section 11 (infection and microbial contamination) does not apply because the device is software with no reagent or physical part that touches specimens.
- Section 12 (materials of biological origin) does not apply because no component comes from animal, human or microbial tissue; the reagent components are synthetic and their sourcing is recorded in the material specification.
- Section 15 (radiation) does not apply because the analyzer emits no ionizing or non-ionizing radiation beyond the visible light source described in the electrical safety report.
- Section 19 (self-testing and near-patient testing) does not apply because the intended purpose statement limits use to trained professionals in a clinical laboratory, and the label carries the professional-use restriction.
"Partially applicable" is used when some subclauses apply and others do not; the row is then split so that each subclause has its own decision. A single "not applicable" against Section 16 for an analyzer with embedded firmware is wrong, because 16.1 and 16.2 apply to any device that incorporates an electronic programmable system 1.
A self-testing exclusion has to read the same way in the intended purpose statement, on the label and in the instructions for use. Section 20.2 requires the label of a near-patient testing device to say so, and for rapid assays not intended for self-testing or near-patient testing, the label must state that exclusion 1.
7. Harmonized Standards
Article 8(1) states that a device in conformity with the relevant harmonized standards, or the relevant parts of them, whose references have been published in the Official Journal of the European Union, is presumed to conform with the requirements covered by those standards or parts 1. The presumption also applies to system and process requirements such as quality management, risk management, post-market surveillance, performance studies and post-market performance follow-up 1.
The IVDR list is Commission Implementing Decision (EU) 2021/1195 of 19 July 2021, amended eight times to date, most recently by Decisions (EU) 2026/197 and 2026/1313 3. The May 2022 amendment added EN ISO 14971:2019/A11:2021, whose Annex Z tables map the standard's clauses to the Annex I requirements, which is the mapping a matrix cites when it relies on ISO 14971 3. The January 2022 amendment added, among others, the standards on symbols (EN ISO 15223-1) and on metrological traceability of values assigned to calibrators (EN ISO 17511) 3.
A standard that is widely used but not listed, or a newer edition not yet listed, gives no presumption; the matrix records it as an "other solution" with the manufacturer's own demonstration. A listed standard covers only the requirements the Official Journal entry says it covers, and some entries carry restrictions, so a standard cited against a whole section when it covers one subclause leaves the other subclauses without evidence. And citing a standard does not show it was applied: the row still needs the controlled document, such as the risk management file for ISO 14971 or the usability engineering file for IEC 62366-1 7,9.
Standards commonly recorded in IVDR GSPR matrices include ISO 13485 (quality management), ISO 14971 (risk management), IEC 62304 (software lifecycle), IEC 62366-1 (usability engineering), ISO 15223-1 (symbols), ISO 20417 (information supplied by the manufacturer), the ISO 18113 series (IVD labeling and instructions for use), ISO 17511 (metrological traceability) and ISO 20916 (clinical performance studies using human specimens) 7,8,9,10,11,12,13. The edition applied and its status in the current Official Journal list are recorded in the matrix, with a gap assessment where the edition applied differs from the listed one.
8. Common Specifications and Class D IVDs
Article 9(1) allows the Commission to adopt common specifications (CS) where no harmonized standard exists, where the relevant harmonized standards are not sufficient, or where public health concerns need to be addressed 1. Article 9(2) gives a device that conforms with a common specification a presumption of conformity for the requirements it covers. Article 9(3) makes compliance mandatory: manufacturers shall comply with the common specifications unless they can duly justify solutions that ensure at least an equivalent level of safety and performance 1.
Regulation (EU) 2022/1107 applies to certain class D devices, not to class D as a whole. Commission Implementing Regulation (EU) 2022/1107 of 4 July 2022 lays down common specifications for the device groups listed in its Annexes II to XIII, in respect of the performance characteristics in Annex I Section 9.1 points (a) and (b), Section 9.3 and Section 9.4 point (a) 2. The groups include blood group antigen detection (ABO, Rh, Kell, Duffy and Kidd), HIV markers, HTLV markers, and hepatitis B, C and D markers 2. The specifications applied from 25 July 2024. A class D device outside those groups is not subject to it.
For a device in scope, the matrix rows for 9.1(a), 9.1(b), 9.3 and 9.4(a) cite the relevant annex as the conformity method and reference the performance data that show each specified acceptance criterion was met, including the required specimen panels and the sensitivity and specificity thresholds. Where the manufacturer departs from a specification, the Article 9(3) justification of equivalence becomes the evidence document for that row.
EvySaif maps common specification acceptance criteria to the performance study design during IVD performance evaluation planning, so that class D evidence is generated against the CS panels from the start.
9. Risk Management Traceability
Article 10(2) requires a risk management system as described in Section 3 of Annex I 1. Sections 2, 3, 4, 5 and 8 of Annex I together set the content: risk reduction as far as possible, a lifecycle risk management system, control measures in a fixed order of priority, reduction of use error, and an acceptable benefit-risk determination 1.
The reviewer reads the matrix and the risk management file together, in both directions:
- from the row for Section 4 to the risk control table, which lists each hazard, the control measure, the verification record and the residual risk;
- from each risk control that relies on information for safety (a warning, a limitation, a specimen requirement) to the label or instructions-for-use clause under Section 20 that carries it;
- from the residual risk conclusion to the benefit-risk determination in the performance evaluation report, which supplies the clinical benefit side of Section 8.
A residual risk listed in the file that has no matching warning in the instructions for use breaks the chain at Section 20.
10. Performance Evidence and Section 9
Section 9.1 requires the device to achieve the analytical and, where applicable, clinical performance stated by the manufacturer, and lists the parameters to address 1. The analytical parameters in 9.1(a) are analytical sensitivity, analytical specificity, trueness, precision (repeatability and reproducibility), accuracy, limits of detection and quantitation, measuring range, linearity, cut-off, specimen collection and handling factors, and endogenous and exogenous interference and cross-reactions. The clinical parameters in 9.1(b) are diagnostic sensitivity, diagnostic specificity, positive and negative predictive value, likelihood ratio and expected values in normal and affected populations 1.
Each listed parameter that applies to the device gets its own matrix row, citing the section of the analytical or clinical performance report that addresses it, with the acceptance criterion and the result. Section 9.2 (shelf life, in-use stability and transport stability) cites the stability protocol and reports. Section 9.3 cites the traceability documentation for each calibrator and control material, naming the reference measurement procedure or reference material. Section 9.4 cites the lay-user or near-patient study.
The performance evaluation plan, scientific validity, analytical performance and clinical performance, and MDCG 2022-2 on clinical evidence for IVDs 5, are covered in the EvySaif IVDR performance evaluation and PEP guide.
11. Software and Section 16
Section 16.1 requires devices that incorporate electronic programmable systems, including software, and software that is a device in itself, to be designed for repeatability, reliability and performance in line with the intended use, with means to eliminate or reduce risks in a single fault condition 1. Section 16.2 requires software to be developed and manufactured according to the state of the art, taking into account the development lifecycle, risk management including information security, and verification and validation. Section 16.3 covers software for mobile platforms. Section 16.4 requires the manufacturer to state the minimum hardware, IT network and IT security requirements needed to run the software as intended 1.
Rows for 16.1 to 16.4 cite, at minimum:
- the software development plan and software safety classification;
- the software requirements specification and architecture;
- the verification and validation reports, including single fault condition testing for 16.1;
- the cybersecurity risk assessment and the security controls implemented, with reference to MDCG 2019-16 6;
- the software release record, anomaly list and accepted residual anomalies;
- the instructions-for-use clause stating minimum hardware, network and security requirements for 16.4.
For a software-only IVD, Sections 9, 16 and 20 carry most of the matrix, and the non-applicability reasons for Sections 10 to 15, 17 and 18 rest on the absence of a physical component.
12. Self-Testing and Near-Patient Testing
Article 2(5) defines a device for self-testing as one intended by the manufacturer for use by lay persons. Article 2(6) defines a device for near-patient testing as one intended for testing outside a laboratory, near the patient, by a health professional 1. Beyond the general requirements, these devices are covered by:
- Section 9.4, which requires performance to be checked with lay persons (self-testing) or in the actual use environments (near-patient testing) 1;
- Section 19, which requires the device to perform appropriately given the skills and means of the intended user, to reduce the risk of use error as far as possible, and to make results easy to understand 1;
- Section 20.4.2, which sets extra instructions-for-use content, including results explained in language a lay person can understand and an instruction to consult a healthcare professional 1;
- Article 10(10), which requires the information supplied with these devices to be easily understandable and provided in the official language or languages set by each Member State 1.
The matrix for such a device cites a lay-user performance study against 9.4, a usability file with summative evaluation by representative lay users against Sections 5 and 19, and an instructions-for-use readability verification against 20.4.2, together with the translation records for each market.
13. Labeling and Section 20
Section 20 produces the largest number of matrix rows because 20.2 and 20.4.1 are lettered lists of mandatory content 1. Section 20.1 sets the general rules: the information must be indelible, legible and comprehensible to the intended user; labels are human-readable and may be supplemented by machine-readable formats; and instructions for use accompany the device unless, in duly justified cases, the device can be used safely without them 1. Section 20.2 lists the label particulars, including the device name, the manufacturer, the unique device identifier (UDI), lot or serial number, storage and handling conditions, the IVD indication, the single-use indication where relevant, the near-patient testing indication where relevant, and the explicit exclusion for rapid assays not intended for self-testing or near-patient testing 1. Section 20.4.1 lists the instructions-for-use content, from intended purpose and specimen type through performance characteristics, interferences and limitations to the metrological traceability of calibrator and control values with their maximum batch-to-batch variation (20.4.1(u)), and the date of issue or latest revision 1.
Each lettered item of 20.2 and 20.4.1 gets its own row, citing the label artwork specification or the instructions-for-use section and page that carries it. Symbols are checked against ISO 15223-1 and information content against ISO 20417 and the ISO 18113 series 10,11,12.
Every performance claim in the instructions for use has to match the performance evaluation report cited under Section 9, and every warning or limitation has to trace to a risk control under Section 4. A performance figure in the instructions for use that does not appear in the performance evaluation report is a claim without evidence, which Article 7 prohibits 1.
14. Three Worked Matrix Examples
Illustrative examples only. The rows below show the level of detail that meets Annex II Section 4 for a hypothetical class C laboratory immunoassay with an analyzer and software. Document numbers, revisions and section references are invented.
Row: GSPR 9.1(a), analytical performance, precision
| Field | Entry |
|---|---|
| Applies | Yes |
| Justification | Quantitative immunoassay; precision is a listed 9.1(a) parameter |
| Conformity method | Performance evaluation (analytical performance study) |
| Standard or CS | Internal protocol based on CLSI EP05 (not a harmonized standard; recorded as other solution) |
| Evidence | APR-0117 Analytical Performance Report, Rev 03, Section 6.2, Tables 6 to 8 (repeatability, within-laboratory precision, reproducibility across three lots and three sites); acceptance criteria in PEP-0117 Rev 02, Section 5.3 |
| Location | Technical documentation Section 6.1.2, folder 06-Performance-Evaluation |
| Status | Complete; results within acceptance criteria |
Row: GSPR 16.2, software lifecycle, risk management, information security, verification and validation
| Field | Entry |
|---|---|
| Applies | Yes |
| Justification | Analyzer contains embedded control software and result calculation software (safety class B) |
| Conformity method | Software lifecycle process; cybersecurity risk management |
| Standard or CS | IEC 62304:2006/AMD1:2015 applied; status in the Official Journal list checked on [date]; MDCG 2019-16 Rev 1 applied for cybersecurity |
| Evidence | SDP-0042 Software Development Plan Rev 04; SRS-0042 Rev 06; SVR-0042 Software Verification Report Rev 03, Sections 4 to 7; CSRA-0042 Cybersecurity Risk Assessment Rev 02; ANL-0042 Anomaly List Rev 09 |
| Location | Technical documentation Section 6.4, folder 06-Software |
| Status | Complete; two residual anomalies documented and accepted in RMR-0042 Rev 05, Section 8 |
Row: GSPR 20.4.1(u), instructions for use, metrological traceability of calibrator and control values and maximum batch-to-batch variation
| Field | Entry |
|---|---|
| Applies | Yes |
| Justification | Device is supplied with a calibrator set and two control levels |
| Conformity method | Labeling review; traceability documentation |
| Standard or CS | EN ISO 17511 (traceability), edition and Official Journal status checked on [date]; ISO 18113-2 (reagents for professional use) for the instructions-for-use content |
| Evidence | IFU-0117 Rev 07, Section 11 (traceability statement naming the reference material and procedure) and Section 12 (assigned values with maximum lot-to-lot variation); TRC-0117 Traceability Report Rev 02 |
| Location | Technical documentation Section 2.3 (labeling) and Section 6.1.4 (traceability) |
| Status | Complete |
15. Common GSPR Matrix Failures and Lifecycle Maintenance
Each of the following leaves at least one of the four Annex II Section 4 elements unmet or contradicts another part of the file.
- A yes/no compliance column with no method, standard or document reference.
- "Not applicable" with no device-specific reason, or against a section with subclauses that do apply, such as Section 16 for an analyzer with firmware or Section 14 for any device with a measuring function.
- Evidence references to "the technical file" or "the risk management file" instead of a document number, revision and section.
- Standards cited without an edition, or with an edition that differs from the Official Journal entry and no gap assessment.
- A harmonized standard cited as the evidence itself, with no record showing it was applied to the device.
- No common specification cited for a device in a group covered by Regulation (EU) 2022/1107, or one cited without the row-level data against each criterion.
- Section 9.1 or Section 20.4.1 handled as one row, so that individual parameters or lettered items have no direct evidence reference.
- Residual risks in the risk management file with no matching warning in the instructions for use, or warnings with no source risk.
- Performance figures in the instructions for use that differ from the performance evaluation report.
- An MDR template reused with IVDR numbers pasted in, leaving MDR-only requirements in the IVD matrix and Section 9 missing.
- A matrix dated before the latest design, standard or performance evaluation change, with no revision history.
Article 10(8) requires changes in product design or characteristics, and changes in the harmonized standards or common specifications used to declare conformity, to be taken into account in a timely manner 1. The matrix is a controlled document with a revision history. A new revision is triggered by a design change, software release or change of intended purpose; a new edition of an applied standard or a change to the Official Journal list; a new or amended common specification; a performance evaluation update, including post-market performance follow-up (PMPF) data under Annex XIII Part B 1; a labeling change, including translations; and a post-market surveillance conclusion, periodic safety update report finding or field safety corrective action that changes a risk control.
Article 29 requires manufacturers of class C and D devices to draw up a summary of safety and performance that includes a reference to any harmonized standards and common specifications applied 1. The standards column of the matrix is the source for that statement, so the two documents are revised together. EvySaif writes the summary of safety and performance from the same controlled standards list and updates the matrix after post-market findings as part of its post-market performance follow-up support.
16. IVDR GSPR Documentation Support from an IVDR Consultant
EvySaif prepares and remediates GSPR evidence matrices for IVD manufacturers in India, Europe and the MENA region. The work covers:
- GSPR applicability assessment with a written reason for every not-applicable and partially applicable entry;
- standards and common specifications mapping, including Official Journal status and gap assessments;
- evidence gap analysis against each applicable row, with the list of reports still to be produced;
- traceability review across the matrix, the risk management file, the performance evaluation report and the labeling, and response support during notified body review.
These services sit within the EvySaif medical device and IVD consulting practice, alongside IVDR technical documentation writing, IVD performance evaluation and CE marking strategy. Manufacturers preparing or remediating an IVDR technical file can request a GSPR gap assessment.
17. Frequently Asked Questions
Annex I of Regulation (EU) 2017/746 has 20 numbered sections in three chapters: 1 to 8 (general requirements), 9 to 19 (performance, design and manufacture) and 20 (information supplied with the device). Most sections have subclauses, so a working matrix has many more than 20 rows 1.
The regulation does not name a checklist. Annex II Section 4 requires the technical documentation to identify the applicable requirements, explain why the others do not apply, state the conformity method, identify the standards, common specifications or other solutions applied, and give the exact identity and location of the evidence documents. A matrix is the usual way to present those four elements 1.
A GSPR checklist demonstrates conformity with Annex I. A technical documentation checklist confirms that every element required by Annexes II and III is present. The GSPR matrix is one part of the technical documentation, under Annex II Section 4.
No. MDR Annex I has 23 requirements and IVDR Annex I has 20, the chapters differ, and IVDR Section 9 on performance characteristics has no MDR equivalent. An IVD matrix is built from the IVDR text.
Article 8(1) gives a presumption of conformity only for standards listed in the Official Journal under the IVDR (Implementing Decision (EU) 2021/1195, as amended), and only for the requirements those standards cover. The matrix still has to reference the document that shows the standard was applied to the device 1,3.
Article 9(3) requires manufacturers to comply with adopted common specifications unless an equivalent solution is duly justified. Regulation (EU) 2022/1107 lays down common specifications for the class D device groups listed in its annexes, in respect of Annex I Sections 9.1(a) and (b), 9.3 and 9.4(a) 1,2.
A reason that names the device property that removes the requirement: no sterile component for Section 11, no biological material for Section 12, no radiation source for Section 15, professional-use-only intended purpose for Section 19.
After every design change, software release, change of intended purpose, change to an applied standard or the Official Journal list, new or amended common specification, performance evaluation update, labeling change, or post-market finding that changes a risk control. Article 10(8) requires such changes to be taken into account in a timely manner 1.
Applicability assessment with written reasons, standards and common specifications mapping, evidence gap analysis, construction of the matrix inside the manufacturer's document control system, traceability review against the risk management file, performance evaluation report and labeling, and response support during notified body review.
References
- Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices. OJ L 117, 5.5.2017, p. 176. Consolidated text of 10 January 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02017R0746-20250110
- Commission Implementing Regulation (EU) 2022/1107 of 4 July 2022 laying down common specifications for certain class D in vitro diagnostic medical devices in accordance with Regulation (EU) 2017/746. OJ L 178, 5.7.2022, p. 3. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R1107
- Commission Implementing Decision (EU) 2021/1195 of 19 July 2021 on the harmonised standards for in vitro diagnostic medical devices drafted in support of Regulation (EU) 2017/746. OJ L 258, 20.7.2021, p. 50. As amended by Implementing Decisions (EU) 2022/15, 2022/729, 2023/1411, 2024/817, 2024/2625, 2025/679, 2026/197 and 2026/1313. Consolidated text: https://eur-lex.europa.eu/eli/dec_impl/2021/1195/oj/eng. Current list of amending decisions: https://health.ec.europa.eu/medical-devices-topics-interest/harmonised-standards_en
- Commission Implementing Decision (EU) 2022/729 of 11 May 2022 amending Implementing Decision (EU) 2021/1195 as regards harmonised standards for quality management systems and risk management. OJ L 135, 12.5.2022, p. 31. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0729
- Medical Device Coordination Group. MDCG 2022-2: Guidance on general principles of clinical evidence for in vitro diagnostic medical devices (IVDs). January 2022.
- Medical Device Coordination Group. MDCG 2019-16 Rev.1: Guidance on cybersecurity for medical devices. July 2020.
- EN ISO 14971:2019/A11:2021. Medical devices. Application of risk management to medical devices.
- IEC 62304:2006/AMD1:2015. Medical device software. Software life cycle processes.
- IEC 62366-1:2015/AMD1:2020. Medical devices. Application of usability engineering to medical devices.
- ISO 15223-1:2021. Medical devices. Symbols to be used with information to be supplied by the manufacturer. Part 1: General requirements.
- ISO 20417:2021. Medical devices. Information to be supplied by the manufacturer.
- ISO 18113 series. In vitro diagnostic medical devices. Information supplied by the manufacturer (labelling). Parts 1 to 5.
- ISO 17511:2020. In vitro diagnostic medical devices. Requirements for establishing metrological traceability of values assigned to calibrators, trueness control materials and human samples. ISO 20916:2019. In vitro diagnostic medical devices. Clinical performance studies using specimens from human subjects. Good study practice.
EvySaif Research Solutions is a clinician-led medical writing, regulatory affairs, HEOR and drug clinical development consultancy serving pharmaceutical, biotechnology and medical device companies across India, the Middle East and Europe.
Last reviewed: September 2026. This article is provided for general information and does not constitute regulatory or legal advice. Requirements are applied to a specific device through its conformity assessment.