On this page
Published: February 25, 2024 · Last reviewed: May 1, 2026
Key Takeaways
- CE marking medical devices is a manufacturer declaration of conformity to EU MDR or IVDR, not a government approval or a quality endorsement.
- Device classification (I, IIa, IIb, III under the MDR; A through D under the IVDR) determines whether a Notified Body must review the technical file before the mark can be affixed.
- Technical documentation under Annex II and III must include risk management, verification and validation evidence, and, for software, documented IT security measures under Annex I Section 17.2.
- MDCG 2019-16 sets the cybersecurity expectations Notified Bodies use to evaluate that Annex I Section 17.2 evidence, and it now sits alongside the incoming EU Cyber Resilience Act's requirements for products with digital elements.
- CE marking and FDA 510(k) clearance both demand evidence of safety and performance, but they run on different legal instruments, different reviewer models, and different post-market obligations.
CE marking medical devices means the manufacturer has completed a conformity assessment demonstrating the device meets the EU Medical Device Regulation 2017/745 (or IVDR 2017/746 for in vitro diagnostics) and has signed a Declaration of Conformity. It is not an approval issued by a regulator, a quality award, or a one-time test result. Depending on device classification, it requires a quality management system, technical documentation under Annex II and III, and, for anything above Class I, review by a Notified Body before the device can legally be placed on the EU market.
Reviewed September 17, 2026
A device without a valid CE mark cannot legally be sold or distributed anywhere in the European Economic Area, which makes CE marking medical devices a gating requirement rather than a marketing checkbox. Manufacturers frequently misunderstand what the mark actually certifies: it is the manufacturer's own declaration, backed by evidence and, in most cases, third-party review, that the device meets EU legal requirements at the moment of assessment. It does not mean a regulator tested the device, and it does not mean the device is risk-free. For connected and software-driven devices, the evidence a Notified Body now expects includes cybersecurity risk management under MDR Annex I Section 17.2, which is where CE marking and premarket security testing intersect directly.
Why This Matters
CE marking is the legal precondition for market access across the EEA, and its absence stops a device at the border regardless of how well it performs clinically. The MDR 2017/745 and the IVDR 2017/746 replaced the older directives with tighter classification rules, mandatory clinical evidence, and, through Annex I Section 17.2 and MDCG 2019-16, explicit cybersecurity expectations for software and connected devices. A parallel obligation is arriving through the EU Cyber Resilience Act, which adds product-wide cybersecurity requirements that overlap with, but do not replace, MDR obligations for devices with digital elements. The FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions final guidance, issued February 3, 2026, sets a comparable expectation in the United States: security evidence has to be built into the design history file, not bolted on before submission. Manufacturers selling in both markets increasingly build one threat model and one set of security testing evidence, then map it to each jurisdiction's specific documentation format, because the underlying engineering work, secure development, risk management, and vulnerability testing, is largely the same regardless of which mark or clearance letter it eventually supports.
What Does the CE Mark Legally Mean?
The CE mark is a legal declaration by the manufacturer, not a certificate issued by a government agency, and no EU body "approves" a device the way the FDA clears or approves one. Affixing the mark means the manufacturer has completed the applicable conformity assessment route, holds the technical documentation to prove it, and has signed a Declaration of Conformity taking legal responsibility for the claim. For Class I devices with no measuring function and no sterile requirement, the manufacturer can self-certify. For every other class, a Notified Body must review the file first and issue a certificate before the manufacturer can affix the mark. The mark is also not permanent: it depends on the manufacturer maintaining the quality system and technical file for as long as the device stays on the market.
[KEY REQUIREMENT] The CE mark is a legal declaration of conformity to MDR or IVDR requirements, evidenced by a technical file and, above Class I, a Notified Body certificate. It is not a safety guarantee and not equivalent to a regulatory approval.
How Are Devices Classified Under MDR and IVDR?
Classification determines the conformity assessment route, and it is based on intended use, invasiveness, and duration of contact with the body rather than on the manufacturer's own risk judgment. The MDR sets four classes: Class I (lowest risk, largely self-certified), Class IIa, Class IIb, and Class III (highest risk, implants and life-sustaining devices, always requiring full Notified Body involvement). The IVDR uses a separate letter scale, Class A through D, running from low individual and public health risk (A) to high public health risk and high individual risk (D), reflecting the different risk logic of diagnostic tests versus therapeutic devices. Software that drives or influences clinical decisions is classified according to MDR Rule 11 (or the equivalent IVDR rule), which frequently pushes standalone diagnostic and clinical decision software into Class IIa or higher, triggering Notified Body review that manufacturers sometimes do not anticipate.
What Conformity Assessment Route Applies, and When Is a Notified Body Required?
The applicable route depends on device class, and a Notified Body is required for every class above Class I (non-measuring, non-sterile). Manufacturers choose among several MDR Annex routes: full quality assurance (Annex IX), type-examination combined with production quality assurance (Annex X and XI), or, for Class I devices without special conditions, self-certification with no external review at all. A Notified Body's role is to audit the manufacturer's quality management system, review the technical documentation, and, for higher-risk classes, examine the device's own design dossier before issuing an EU certificate. That certificate, not the CE mark itself, is the artifact a competent authority or customer can request as proof the assessment happened.
| Device Class | Typical Examples | Notified Body Required | Assessment Depth |
|---|---|---|---|
| MDR Class I | Bandages, non-sterile exam tools | No (self-certification) | Manufacturer declaration only |
| MDR Class IIa | Diagnostic ultrasound, infusion sets | Yes | QMS audit plus technical file sampling |
| MDR Class IIb | Ventilators, infusion pumps | Yes | Full technical file review |
| MDR Class III | Implants, life-sustaining devices | Yes | Full technical file plus design dossier examination |
| IVDR Class A | General lab equipment | No (self-certification) | Manufacturer declaration only |
| IVDR Class D | HIV, blood-borne pathogen tests | Yes, plus EU reference laboratory | Full technical file plus batch verification |
What Goes Into the Technical Documentation?
Annex II and Annex III of the MDR define the technical documentation a manufacturer must hold and, for non-Class I devices, submit for Notified Body review. Annex II covers device description, design and manufacturing information, general safety and performance requirements, benefit-risk analysis, verification and validation data, and, for software, a description of the software's architecture and security measures. Annex III covers post-market surveillance documentation, including the post-market surveillance plan and periodic safety update reports for higher-risk classes. For software-containing devices, this file has to demonstrate compliance with MDR Annex I Section 17, which requires manufacturers to develop and manufacture software according to the state of the art, considering the principles of the development lifecycle, risk management, verification, and validation, and to set minimum requirements for IT security including protection against unauthorized access.
[KEY REQUIREMENT] MDR Annex I Section 17.2 requires manufacturers to design software with IT security measures appropriate to intended use, including protection against unauthorized access, and to define minimum hardware and network characteristics needed to run it safely.
Which Standards Do Notified Bodies Actually Check?
Notified Bodies evaluate the technical file against a set of harmonized and recognized standards rather than inventing their own criteria case by case. ISO 13485 governs the quality management system the manufacturer runs the whole design and production process under, and a current ISO 13485 certificate is close to a precondition for any Notified Body engagement. ISO 14971 governs risk management and is the backbone document that every safety and security claim in the technical file has to trace back to. IEC 62304 governs the software development lifecycle for medical device software, covering software safety classification, architecture, verification, and problem resolution. IEC 81001-5-1 extends that lifecycle model specifically to health software security, covering secure design, security risk management, and security verification activities that MDCG 2019-16 references directly when describing acceptable cybersecurity evidence.
What Does MDCG 2019-16 Require for Cybersecurity?
MDCG 2019-16 is the Medical Device Coordination Group's guidance on cybersecurity for medical devices, and it is what Notified Bodies use to interpret Annex I Section 17.2 in practice. It expects manufacturers to run a documented security risk management process alongside the standard ISO 14971 safety risk process, covering secure design, a defined secure development lifecycle, vulnerability and patch management, and evidence of security testing, including penetration testing where the device's connectivity and risk profile warrant it. The guidance does not name a specific test methodology, but reviewers increasingly expect testing evidence that traces to a documented threat model rather than a generic vulnerability scan. Manufacturers preparing a CE technical file alongside an FDA submission commonly build this evidence once and format it for both audiences, since the underlying security engineering the two frameworks expect is closely aligned.
How Does the EU Cyber Resilience Act Interact With MDR?
See also: CVSS Scoring for Medical Devices: A Complete Walkthrough, Healthcare Cybersecurity Companies: A Buyer's Selection Guide, and Medical Device Software Development: A Compliance Guide.
The EU Cyber Resilience Act introduces horizontal cybersecurity requirements for products with digital elements sold in the EU, and medical devices already regulated under the MDR or IVDR are largely carved out from duplicating requirements the MDR already covers, but the interaction is not a full exemption. Where the MDR's own cybersecurity requirements (Annex I Section 17.2, as interpreted by MDCG 2019-16) are judged equivalent to a Cyber Resilience Act obligation, that MDR pathway satisfies it; where a gap exists, for example around vulnerability disclosure and incident reporting timelines for connected components, the Cyber Resilience Act's own obligations apply on top of MDR compliance. Manufacturers of connected devices should treat the two frameworks as complementary evidence sets rather than assume MDR compliance alone closes every Cyber Resilience Act obligation.
What Are the Declaration of Conformity, UDI, and EUDAMED Requirements?
The Declaration of Conformity is the manufacturer's signed legal statement that the device meets all applicable MDR or IVDR requirements, and it must be kept current and available to competent authorities for as long as the device is on the market. Every device also needs a Unique Device Identifier (UDI), assigned by the manufacturer and registered in the EUDAMED database, which links the device to its technical documentation, certificates, and post-market data in a single EU-wide record. Manufacturers based outside the EU must also appoint an Authorized Representative established within the EU, who acts as the manufacturer's legal contact for competent authorities and holds a copy of the technical documentation and Declaration of Conformity on file.
What Post-Market Obligations Come After the CE Mark Is Affixed?
CE marking is not a one-time event; it carries ongoing post-market surveillance (PMS) obligations for the life of the device on the market. Manufacturers must run a documented PMS plan, collecting field data, complaints, and incident reports, and feed that data back into the risk management file. Higher-risk devices additionally require Periodic Safety Update Reports (PSURs), submitted to the Notified Body or competent authority on a defined schedule, and any serious incident triggers vigilance reporting obligations with strict timelines. For connected and software devices, this is also where post-market vulnerability monitoring and patch deployment evidence belongs, feeding the same risk file that supported the original CE mark.
How Does CE Marking Compare to FDA 510(k) Clearance?
CE marking and FDA 510(k) clearance both require documented evidence of safety and performance, but they differ in who reviews the evidence, what legal instrument grants market access, and what happens after the device ships.
| What Each Requires | CE Marking (MDR) | FDA 510(k) |
|---|---|---|
| Reviewing body | Notified Body (above Class I) or self-certification | The FDA reviews the submission directly |
| Legal basis | Manufacturer's Declaration of Conformity | FDA clearance letter |
| Classification basis | Risk class I to III (MDR) or A to D (IVDR) | Device class I to III plus predicate comparison |
| Core comparison standard | Conformity with harmonized standards and GSPRs | Substantial equivalence to a predicate device |
| Cybersecurity evidence | Annex I Section 17.2, MDCG 2019-16, IEC 81001-5-1 | Section 524B, February 3, 2026 premarket guidance, ANSI/AAMI SW96 |
| Post-market obligation | PMS plan, PSUR, vigilance reporting | Postmarket surveillance, Section 524B vulnerability monitoring |
| Market covered | European Economic Area | United States |
How Blue Goat Cyber Approaches This
Blue Goat Cyber supports manufacturers building the cybersecurity evidence that CE marking and FDA submissions both depend on, without displacing the regulatory or quality work a Notified Body or the FDA actually reviews. In dual-market submissions we see the same threat model and SBOM reused across both jurisdictions, with a short crosswalk annex mapping SW96 controls to MDR Annex I Section 17.2, which tends to shorten the Notified Body question cycle. Our medical device penetration testing work is scoped against the device's own threat model so the resulting evidence supports Annex I Section 17.2 and MDCG 2019-16 review, not a generic vulnerability scan. Manufacturers preparing an EU technical file alongside a Cyber Resilience Act assessment can also review our EU Cyber Resilience Act support for how the two evidence sets map together.
Frequently Asked Questions
Does CE marking mean a medical device is FDA approved?
No. CE marking and FDA clearance are entirely separate legal processes tied to different markets. A CE-marked device has no standing in the United States until it goes through its own FDA pathway, and an FDA-cleared device needs a separate MDR or IVDR conformity assessment before it can be sold in the EEA.
Who is legally responsible for CE marking a medical device?
The manufacturer is legally responsible for CE marking, even when a Notified Body reviews the technical file. The manufacturer signs the Declaration of Conformity and carries ongoing liability for the accuracy of that declaration for as long as the device remains on the market.
Can a manufacturer self-certify a CE mark without a Notified Body?
Only for MDR Class I devices with no measuring function and no sterile packaging requirement, or IVDR Class A devices. Every higher class requires a Notified Body to review the technical documentation and issue a certificate before the mark can be affixed.
What is the difference between the CE mark and a Notified Body certificate?
The CE mark is the visible symbol affixed to the device; the Notified Body certificate is the underlying evidence that a third party reviewed the technical file and found it compliant. The certificate has an identification number that must appear alongside the CE mark for any device that required Notified Body review.
How long does it take to get CE marking for a medical device?
Timelines vary widely with device class and Notified Body workload, and vary enough by device and Notified Body that manufacturers should scope timing directly with their chosen body rather than assume a fixed figure. Higher-risk classes and devices with significant software or cybersecurity documentation gaps generally take longer because of the additional review cycles.
Do software-only medical devices need CE marking?
Yes, standalone software that meets the MDR's definition of a medical device (intended for a medical purpose such as diagnosis, monitoring, or treatment) needs its own CE marking under the same classification and conformity assessment rules as hardware devices, frequently landing in Class IIa or higher under MDR Rule 11.
CTA
If your device needs cybersecurity evidence that will hold up under Notified Body review or an FDA submission, or both, talk to Blue Goat Cyber about scoping threat modeling and penetration testing against your specific technical file requirements. We build the evidence once and map it to the jurisdictions you are actually shipping into.
About the author
Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
