IVDR

IVDR Technical Documentation in 2026: The Complete Guide and Checklist

By Dr Shabbir Nagpurwala · August 13, 2026
← All insights

If you manufacture an in vitro diagnostic device and want to sell it in the European Union, you must compile a technical documentation file that proves your device is safe and performs as claimed. The structure of that file is set by Annexes II and III of the In Vitro Diagnostic Regulation (EU) 2017/746, usually called the IVDR.

This guide explains the entire file, section by section, in plain language. By the end you will know what goes in each section, what notified bodies look for, which deadlines apply in 2026, and where manufacturers most often go wrong. A compact checklist you can work from sits at the end of the article.

One thing to say upfront: there is no official EU template for IVDR technical documentation. Annex II and Annex III define the required content, and the file is organized around them. Vendors sometimes advertise a "mandatory official IVDR template"; no such thing exists. What matters is that every content requirement in the annexes is covered, clearly indexed, and supported by evidence.

The 2026 deadlines you cannot afford to miss

Before we open the file itself, you need to know where we are in the IVDR transition, because in 2026 the deadlines determine what you must have done, and by when.

The IVDR became applicable on 26 May 2022, replacing the old IVD Directive (98/79/EC, the IVDD). Because notified body capacity could not absorb the entire market at once, the EU adopted Regulation (EU) 2024/1860, which gave existing IVDD-compliant devices staggered extra time, on strict conditions. The milestones are:

Device class IVDR application submitted to a notified body by Written agreement signed with the notified body by May remain on the market until
Class D (highest risk) 26 May 2025 (passed) 26 September 2025 (passed) 31 December 2027
Class C 26 May 2026 (passed) 26 September 2026 31 December 2028
Class B and Class A sterile 26 May 2027 26 September 2027 31 December 2029

Three consequences follow.

First, if you make a Class C legacy device, the next milestone is weeks away. You must have a signed written agreement with your notified body by 26 September 2026. Submitting an application on its own does not preserve your status past that date. If the agreement is not concluded in time, your device loses its transitional status and can no longer be lawfully placed on the EU market.

Second, the transition only protects devices that meet the conditions: a valid declaration of conformity under the old IVDD drawn up before 26 May 2022, no significant changes to the design or intended purpose since, no unacceptable safety risk, and an IVDR-compliant quality management system in place (the QMS requirement applied from 26 May 2025 for all classes). Legacy status defers full certification, and at the same time it adds interim duties, including IVDR-level post-market surveillance and vigilance.

Third, as of August 2026 there is no further extension on the table. Which brings us to a widespread and dangerous misunderstanding.

Does the December 2025 EU reform proposal pause any of this? No.

In December 2025 the European Commission published a proposal (COM(2025) 1023) to simplify parts of the MDR and IVDR. It attracted enormous attention, and understandably so: it proposes abolishing the five year maximum validity of certificates in favor of risk based periodic reviews, broadening what counts as clinical data, easing requirements for the person responsible for regulatory compliance, revising software classification rules, expanding electronic instructions for use, and creating orphan device and breakthrough innovation pathways.

None of that is law yet. The proposal must pass through the European Parliament and the Council, adoption is not expected before 2027, and the text may change substantially in negotiation. Most importantly for you, the proposal does not amend the IVDR transitional deadlines. The 26 September 2026 agreement deadline for Class C stands. Manufacturers who slowed their IVDR projects in early 2026 expecting relief are now compressing eighteen months of work into a few. Plan against the deadlines as they stand, and treat anything the reform eventually delivers as additional room.

A second deadline hiding in plain sight: EUDAMED

Separately from certification, 2026 is the year EUDAMED, the EU's central medical device database, finally became mandatory. Commission Decision (EU) 2025/2371 declared four modules functional, and from 28 May 2026 their use is compulsory: Actor registration, UDI and device registration, Notified Bodies and Certificates, and Market Surveillance.

The practical consequences:

Many manufacturers who are on track for certification have no project plan for EUDAMED registration. It requires an actor registration (your Single Registration Number), UDI assignment, and accurate device data entry. Treat it as a workstream with an owner and a date, because a device that is fully certified but unregistered after the deadline is still non-compliant.

What exactly is "technical documentation" under the IVDR?

Technical documentation is the complete evidence file for one device (or one family of closely related devices). It has two parts:

Two properties of the file surprise first-time manufacturers.

It is a living file. You do not compile it once for the submission and archive it. Every design change, every new stability claim, every post-market finding, every PSUR feeds back into it. Notified bodies check whether the file has been maintained, and an obviously frozen file is a finding in itself.

It is required for every class, including Class A. Manufacturers of low risk devices sometimes assume that self-declaration means no file. It does not. A Class A non-sterile device is self-certified, meaning no notified body reviews the file before market, but the complete Annex II and III documentation must exist and be available to competent authorities on request for ten years after the last device is placed on the market. The class determines who checks the file and at what point; the file itself is required in every case.

Why classification decides everything else

Your device's risk class determines the depth of evidence, the conformity assessment route, and who reviews what. The IVDR classifies IVDs into four classes using the rules in Annex VIII:

Classification under the IVDR moved the market dramatically. Under the old directive roughly four fifths of IVDs reached the market with no notified body involvement. Under the IVDR the proportions are close to inverted: most devices now need a notified body. If you are unsure of your class, resolve that question before writing a single page of the file, because the class drives the evidence plan. Borderline cases (for example, assays whose intended purpose sits between Class B and C depending on the claimed clinical use) call for documented reasoning against the Annex VIII rules, because your notified body will re-derive the classification and challenge optimistic readings.

Inside Annex II: the pre-market file, section by section

Annex II lists six content areas. Below is what each one actually asks for, in the order a reviewer will read them, with the mistakes we see most often.

1. Device description and specification

This section answers a deceptively simple question: what exactly is this device? It must contain:

The most common weakness here is an intended purpose statement written by marketing rather than regulatory. Every performance claim you make later must trace back to this statement, and every phrase in it creates an evidence obligation. "Aids in the diagnosis of X" and "diagnoses X" are different claims with different evidence burdens. Write the intended purpose first, make it exact, and treat it as the contract the rest of the file must honor. The same statement also drives classification, which is why a single adjective can move a device between classes.

2. Information supplied by the manufacturer

A complete set of everything the user will see: labels on the device and its packaging in each configuration, and the instructions for use (IFU) in the languages accepted by the member states where you will sell. For self-tests, the IFU carries additional content requirements because a lay user must be able to run the test and interpret the result safely.

Reviewers cross-check this section against the rest of the file. If the IFU claims a limit of detection your analytical data does not support, or omits a limitation your risk file identifies, that discrepancy becomes a deficiency letter. Version control matters: the file must contain the current issue of every label and IFU, and the change history.

3. Design and manufacturing information

This section shows how the device comes into existence:

Manufacturers who outsource heavily often stumble here. The IVDR holds the legal manufacturer responsible for the whole chain, so the file must demonstrate control over critical suppliers: quality agreements, incoming controls, audit arrangements. A file that assigns a critical process to a contract manufacturer without showing your oversight of it will draw a deficiency on exactly that point.

4. General safety and performance requirements (GSPRs)

Annex I of the IVDR lists the general safety and performance requirements every device must meet. This section of your file is the master index that demonstrates conformity with each of them. In practice it takes the form of the GSPR checklist: a table listing each requirement, whether it applies to your device, the method used to demonstrate conformity, the standards or common specifications applied, and a precise cross-reference to the evidence document.

Three rules make this section work:

5. Benefit-risk analysis and risk management

Here you present the risk management file, in practice built to EN ISO 14971: the risk management plan, hazard identification and risk analysis, risk evaluation, the control measures implemented and the verification that they work, the evaluation of overall residual risk, and the benefit-risk conclusion for the device as a whole.

Two connections make or break this section. The residual risks and limitations you identify must appear in the information supplied to users (section 2), and the risks you say are acceptable must be consistent with the performance evidence in section 6. Reviewers actively hunt for contradictions between the risk file, the IFU, and the performance evaluation, because contradictions reveal a paper exercise rather than a functioning risk process.

6. Product verification and validation

This is the largest and most scrutinized section of the file: the results and critical analyses of all the studies that prove the device does what it claims. For an IVD, the heart of it is the performance evaluation, which under the IVDR rests on three pillars:

These three pillars are planned in a performance evaluation plan (PEP), executed, and synthesized in a performance evaluation report (PER) that states the conclusions and the clinical evidence supporting the intended purpose. We cover the PEP and PER in depth in a companion article, including what MDCG 2025-5 changed about performance study applications. For the technical documentation file, the key point is that the PEP, the underlying study reports and literature reviews, and the PER all belong in section 6, and they must tell one consistent story.

Beyond performance evaluation, section 6 also contains, as applicable:

Annex III: the post-market surveillance file

Annex III is shorter than Annex II and manufacturers routinely underestimate it. It requires the technical documentation on post-market surveillance, meaning:

For a first submission of a new device there is naturally little post-market data, and reviewers know that. What they expect is a credible plan with named responsibilities, defined data sources, and thresholds that would actually trigger action. For legacy devices in transition the expectation is higher: IVDR-grade surveillance has applied to them throughout the transition, so a legacy Class C device arriving at its notified body in 2026 with no PSUR history has a problem before the review starts.

What happens to your file after submission?

Understanding the review helps you build a file that survives it.

For Class B and C devices, the notified body audits your quality management system and assesses technical documentation on a sampling basis: at least one representative device per device category for Class B, and at least one per generic device group for Class C. Sampling means every file in the group must be submission-ready, because you do not choose which one is pulled. For Class D, every device's technical documentation is assessed, with EU reference laboratory performance verification and, once on the market, batch verification.

Timelines have been a persistent complaint industry-wide, and 2026 brought a structural change: Implementing Regulation (EU) 2026/977 introduced uniform requirements for notified bodies, including standardized quotation practices with itemized cost breakdowns and a maximum of 90 days for the technical documentation assessment stage. The clock stops when the notified body raises questions and waits for your answers, so in practice the total duration is driven by the number of deficiency rounds, and that number depends mainly on how complete the file is on day one. A file that generates one focused round of questions finishes months ahead of a file that generates three.

From reviews we have supported and notified body publications, the recurring deficiencies cluster in a familiar list:

  1. Intended purpose statements that are vague, or that drifted between the label, the IFU, and the performance evaluation.
  2. GSPR checklists with unjustified "not applicable" entries or references to superseded standard versions.
  3. Analytical performance gaps: interference testing that does not cover the claimed specimen types, missing near-cutoff precision data for qualitative assays, limits claimed in the IFU but never studied.
  4. Clinical evidence that leans on literature without demonstrating equivalence of the cited devices or applicability to the claimed population.
  5. Stability claims not yet supported by real-time data and without a clear commitment plan.
  6. Risk files that do not reflect the current design or that contradict the IFU.
  7. PMS plans that are generic templates with no device-specific thresholds.
  8. Software documentation without evidence of validation in the claimed use environments, and thin cybersecurity risk assessment.

Every item on that list is preventable with an internal review against the annexes before submission. An internal reviewer who applies Annex II and III strictly will find most of what the notified body would find, at a fraction of the cost in time.

Where this genuinely gets hard

An honest guide should tell you where the difficulty concentrates, because these are the points where budgets and timelines slip.

Borderline classification. The Annex VIII rules resolve most devices cleanly, and then there are the edge cases: assays where the claimed clinical use determines whether Rule 3 pulls them into Class C, multiplex panels whose targets fall in different classes, software whose output feeds clinical decisions. Getting this wrong late is the most expensive mistake available, because the evidence plan, the conformity route, and the notified body contract all depend on it.

The literature versus study decision for clinical performance. MDCG 2025-5 clarified the ground rules, but the judgment call remains: is your device close enough to the published state of the art, and is the published population close enough to your claimed population, to carry the argument without a new study? An over-optimistic call here surfaces as a deficiency a year into review, which is the worst possible moment to design a clinical performance study.

Legacy devices with directive-era evidence. Many IVDD-era files were built to a lower evidentiary standard. Analytical data may predate current CLSI protocols, clinical evidence may be thin, and the original design documentation may be partial. The gap analysis between what exists and what the IVDR requires is the real scope of a legacy transition project, and it is routinely underestimated by a factor of two.

Notified body capacity and engagement. The number of notified bodies designated under the IVDR remains far below the directive era, and the ones that exist are loaded. Practical consequences: expect onboarding questionnaires and quotation lead times measured in months, respond to deficiency letters completely the first time, and never leave the written agreement to the deadline month. The 2026/977 rules on quotations and timelines help, but they do not add reviewer capacity.

Frequently asked questions

Is there an official IVDR technical documentation template? No. The IVDR defines required content in Annexes II and III, and the near-universal practice is to structure the file in the annex order so reviewers can navigate it without a map. The checklist below follows that structure and works as a table of contents for a submission.

Does a Class A device really need the full file? Yes. The conformity route is self-declaration (unless sterile), so no notified body reviews it pre-market, but the complete technical documentation must exist, be kept current, and be available to competent authorities for ten years after the last device is placed on the market.

How long does it take to compile the file? In our experience, for a device where the performance data already exists, assembling and gap-filling a submission-ready file typically takes three to six months. Where new analytical or clinical performance work is needed, the studies dominate the timeline and twelve months or more is realistic. Class D adds EURL and common specification dependencies on top.

Can I submit while some studies are still running? Sometimes. Provisional shelf-life claims supported by accelerated data with real-time studies ongoing are an accepted practice when properly committed. Core analytical and clinical performance evidence for the claims you make must be complete. Your notified body's guidance documents state their position on this; check them before you plan around an assumption.

What language should the file be in? Whatever your notified body accepts, which for most is English. Labels and IFUs must additionally exist in the languages required by each member state where you sell.

We already CE marked this device under the IVDD. Does that file carry over? Parts of it, after a gap analysis. The IVDR file has content the directive never demanded: the three-pillar performance evaluation, PMPF, PSURs for Class C and D, UDI, and a heavier risk management and GSPR apparatus. Treat the IVDD file as source material for the new one; it cannot simply be restructured and resubmitted as is.

Do we need EUDAMED registration even though our notified body review is still ongoing? Yes, on the timelines described earlier: legacy devices still on the market must be registered by 28 November 2026, and any new device needs registration before placement. Certification and registration are separate obligations.

The IVDR technical documentation checklist

Download this checklist as a PDF to work through with your team, one page per Annex II and III section, including the 2026 deadline items.

Download the checklist (PDF)

Use this as a completeness check against your file. Every line traces to Annex II or Annex III.

Device description and specification - Product name, general description, intended purpose statement covering analyte, function, condition, specimen type, population, and user - Basic UDI-DI assigned - Assay principle and components (antibodies, antigens, primers, calibrators, controls) - Variants, configurations, and accessories listed completely - Specimen collection and transport materials or specifications - Previous generations and similar devices referenced

Information supplied by the manufacturer - Labels for the device and every packaging configuration - IFU in required languages, current versions, with change history - Self-test or near-patient additional content where applicable

Design and manufacturing - Design process description - Manufacturing process description with in-process and release controls - All sites, critical suppliers, and subcontractors identified with roles and controls

GSPRs - Checklist covering every Annex I requirement - Applicability justified for every N/A - Standards cited with dates and application scope - Pinpoint cross-references to evidence

Risk management - Risk management plan, analysis, evaluation, controls, and verification (ISO 14971) - Overall residual risk evaluation and benefit-risk conclusion - Consistency verified against IFU and performance data

Verification and validation - Scientific validity report - Analytical performance studies covering all claimed characteristics and specimen types - Clinical performance evidence (studies, literature, or routine-use data) with documented justification of the route chosen - Performance evaluation plan and performance evaluation report, mutually consistent - Shelf-life, in-use, and transport stability evidence with commitments for ongoing real-time work - Software verification and validation, cybersecurity risk assessment - Metrological traceability of calibrators and controls - Sterility, measuring function, and compatibility evidence where applicable - Class D: common specifications conformity, EURL testing, and batch verification arrangements

Post-market (Annex III) - PMS plan with device-specific data sources, methods, and action thresholds - PMPF plan, or a defensible justification for its absence - PMS report (Class A/B) or PSUR (Class C/D, at least annual) current

Administrative and 2026 obligations - Declaration of conformity current - Transition conditions documented for legacy devices (pre-2022 IVDD declaration, no significant change, QMS) - Notified body application and written agreement status tracked against the 2026/2027 milestones - EUDAMED actor and device registration complete or scheduled ahead of 28 November 2026

Getting it done

A file like this rewards method: classify first, write the intended purpose as a contract, plan the evidence against the annexes, build the GSPR index as you go rather than at the end, and run an adversarial internal review before your notified body does it for you.

EvySaif Research and Medical Affairs Solutions supports IVD manufacturers across this whole scope: IVDR gap analysis for legacy files, technical documentation authoring and remediation, performance evaluation plans and reports, PMS and PSUR systems, and submission support through notified body review. Our team combines regulatory writing depth with hands-on clinical and evidence-generation experience across the EU, MENA, and India.

If you are working against the September 2026 agreement deadline, the November 2026 EUDAMED deadline, or a first IVDR submission, write to us at info@evysaif.com or reach us through the contact page for a scoping discussion. A short gap analysis at the start costs a fraction of what a deficiency cycle costs later in review time and delay.


This article reflects the regulatory position as of 12 August 2026, including Regulation (EU) 2024/1860 transition timelines, Commission Decision (EU) 2025/2371 on EUDAMED, MDCG 2025-5 and MDCG 2025-10 guidance, Implementing Regulation (EU) 2026/977, and the status of the December 2025 MDR/IVDR reform proposal. Regulatory requirements evolve; verify current requirements for your specific device before acting.

Need this level of rigor on your next deliverable?

Book a Consultation