What is IVDR?

IVDR is the EU In Vitro Diagnostic Regulation, Regulation (EU) 2017/746. It governs how in-vitro diagnostic medical devices — the tests, instruments, reagents, software and specimen receptacles used to examine samples taken from the human body — may be placed on the European market. It is important to be precise about what it is: IVDR is a regulation, not a voluntary certificate. You do not choose to adopt it the way you might pursue an ISO standard. If you sell IVDs in the EU, complying with it is the law, and the CE marking you carry is the visible sign that you have met its requirements.

IVDR replaced the older In Vitro Diagnostic Directive (IVDD, Directive 98/79/EC), with its date of application in May 2022. The change was not a light refresh. Under the old directive, the large majority of IVDs could be self-declared by the manufacturer with no independent review. IVDR overturns that. It introduces a risk-based classification system that pulls most devices into a conformity-assessment process involving an independent Notified Body, and it raises the bar substantially on clinical and performance evidence.

Two themes run through the entire regulation: demonstrated performance — proving your device does what you claim, with real evidence — and disciplined technical documentation that lets a Notified Body and a regulator trace every claim back to the data behind it. If you can show a clear line from your intended purpose, through your performance evidence and risk management, to the records that prove conformity, you are most of the way to a defensible IVDR file.

Who needs IVDR?

IVDR applies to anyone who places in-vitro diagnostic devices on the EU market or keeps them there. In practice, the organizations that must comply include:

  • IVD manufacturers — makers of instruments, analyzers, reagents, assays and calibrators.
  • Companion diagnostic developers, whose tests guide the use of a specific therapy and now face heightened scrutiny.
  • Software and algorithm developers whose product qualifies as an in-vitro diagnostic device.
  • Manufacturers of self-tests and near-patient tests intended for use outside a laboratory.
  • Importers and EU authorized representatives who take on defined regulatory responsibilities.
  • Laboratories developing in-house tests, which fall under specific conditions of the regulation.

Compliance is not optional. Unlike a certification you pursue to win a tender, IVDR is a legal gate on market access: without a compliant technical file, the right conformity assessment and — for most devices — Notified Body involvement, you cannot lawfully sell in the EU. Many manufacturers who comfortably self-declared under the old IVDD now find the same product sits in a higher class and needs far more evidence and independent review than before.

What IVDR requires

At a high level, IVDR asks you to classify your device correctly, prove it performs and is safe, document all of it, and run a quality system that keeps it that way. The main themes are:

  • Classification. Every device is assigned to one of four risk classes — A, B, C or D — using the regulation's rules. The class determines how much independent scrutiny applies, with Class D (highest risk) attracting the most.
  • Conformity assessment. The route to CE marking depends on class. For most classes above the lowest, an independent Notified Body must be involved, rather than the self-declaration that dominated under the IVDD.
  • Performance evaluation. You must demonstrate scientific validity, analytical performance and clinical performance, supported by a performance evaluation plan and report that is kept current.
  • Technical documentation. A structured technical file covering device description, intended purpose, design, manufacturing, risk management, performance evidence and labeling — traceable and audit-ready.
  • A quality management system aligned with ISO 13485. The regulation expects a working QMS, and ISO 13485 is the practical foundation manufacturers build it on.
  • Risk management applied across the device life cycle, feeding design, production and post-market decisions.
  • Post-market surveillance and performance follow-up, including vigilance reporting and, for higher-risk devices, periodic safety reporting.
  • A Person Responsible for Regulatory Compliance, unique device identification (UDI) and registration obligations tied to the EU database, EUDAMED.

The regulation tells you what you must prove and control, not the exact forms to use. That is where most manufacturers over-build — and where our approach keeps things lean.

Why it matters

The most immediate reason is market access. IVDR is the legal gate to the EU. Without a compliant technical file and the correct conformity-assessment route, you cannot lawfully place your device on the market or keep it there — and for products already on sale under the old IVDD, the transition means real work to stay compliant rather than a formality. Missing a milestone can mean a product coming off the market, not just a delayed launch.

The stakes are higher than under the directive it replaced. Because IVDR pulls most devices into independent Notified Body review and demands genuine clinical and performance evidence, a weak file is exposed in a way it never was before. That is a risk to your revenue and your reputation. Done well, though, the effort pays back. A device with solid performance evidence and clean documentation moves through conformity assessment with fewer questions, defends its claims to clinicians and buyers, and rests on a quality system that lowers the chance of the field actions and safety events that are far more costly than the compliance work itself. Because IVDR is built on an ISO 13485-aligned QMS, the same foundation also supports your wider regulatory readiness.

How QSE gets you ready

We have spent 30+ years building management systems and have guided 900+ organizations to certification with a 100% first-time pass rate at the certification audit. IVDR is a regulation rather than a certificate, so our role is to get your ISO 13485-aligned quality system, technical documentation and performance evidence genuinely ready for conformity assessment — with the same discipline that track record is built on. A weak IVD file does not just draw questions; it can keep a product off the market.

Our 10-Step Approach takes you from gap assessment through documentation, implementation, internal audit and management review to a system that stands up to Notified Body scrutiny, with us alongside you at each stage. We write your quality system as single-level documentation, typically under 200 pages — not the sprawling manuals that people stop reading and auditors stop trusting. The result is a system your scientists, quality team and regulatory staff actually use, built around how you really work.

Because IVDR sits on an ISO 13485 foundation, companies with a working 13485 system have a real head start; we build on it and add the regulation-specific elements — classification rationale, performance evaluation, technical documentation structure and post-market processes — rather than starting over. Everything we build is yours to keep, so your team can own and maintain it long after the file is submitted. Note that the Notified Body conformity assessment and CE marking are formal regulatory steps carried out by the Notified Body and the manufacturer; our job is to make sure you walk into that process ready.

Common pitfalls we help you avoid

  • Assuming IVDR is like the IVDD. Treating a device you once self-declared as low effort, when it now sits in a higher class needing Notified Body review and far more evidence.
  • Getting classification wrong. Misapplying the A-to-D rules, which sets the whole conformity route on the wrong footing.
  • Thin performance evidence. Weak or missing scientific validity, analytical or clinical performance data that cannot support the claims you make.
  • Disorganized technical documentation. A file that cannot trace each claim back to its evidence, which stalls the Notified Body review.
  • Treating the QMS as separate. Building compliance activities that sit outside a working ISO 13485-aligned system rather than being driven by it.
  • Bolt-on risk management. Treating risk as a one-time document instead of something that drives design, production and post-market decisions.
  • Neglecting post-market obligations. Forgetting that surveillance, performance follow-up and vigilance are continuing duties, not launch-day checkboxes.
  • Over-documentation. Bloated, multi-level manuals nobody follows — we keep it single-level and usable.