Technical Documentation Under the MDR: Annex II, Annex III and the Copy We Hold
Updated: Aug 30
Technical documentation is the one MDR deliverable that no one else can produce for you, and the one most often assembled in the wrong shape. Annex II sets out what the device file contains, Annex III sets out the post-market file, and Article 10(4) requires both to be drawn up and kept up to date. Article 11(3)(b) then requires your authorised representative to keep a copy available for competent authorities. Those are three obligations, not one.
What Annex II technical documentation must contain, section by section
Annex II has six numbered sections and the chapeau is itself a requirement: the file must be presented in a clear, organised, readily searchable and unambiguous manner. Section 1 is the device description and specification, running from point (a) to point (l) — trade name, intended purpose and intended users, the Basic UDI-DI, the intended patient population, principles of operation, the rationale for qualification as a device, the risk class with a justification for the classification rule applied under Annex VIII, novel features, accessories, variants, key functional elements, and a description of the raw materials in direct or indirect contact with the body. Section 1.2 requires an overview of previous generations of your own device and of similar devices on the Union or international markets.
Section 2 is a complete set of labels and instructions for use, in the languages accepted in the Member States where the device is to be sold. Section 3 covers design and manufacturing information, including validated manufacturing processes and, at point (c), the identification of all sites — including suppliers and sub-contractors — where design and manufacturing activities are performed. Section 5 requires the benefit-risk analysis referred to in Sections 1 and 8 of Annex I, and the risk management results referred to in Section 3 of Annex I.
Section 4 is the general safety and performance requirements demonstration, and it has four limbs that are routinely collapsed into two. Point (a) requires the applicable requirements and an explanation of why the others do not apply. Point (b) requires the method used for each. Point (c) requires the harmonised standards, common specifications or other solutions applied. Point (d) requires the precise identity of the controlled documents offering evidence of conformity, with a cross-reference to their location in the file. A checklist that names a standard without naming the controlled document and its location fails point (d) on its face.
Annex III, and the post-market file that lives inside Annex II
Annex III Section 1.1 is the post-market surveillance plan required by Article 84. It must address serious incident information including that from periodic safety update reports and field safety corrective actions, records of non-serious incidents and undesirable side-effects, trend reporting information, specialist and technical literature, databases and registers, feedback and complaints from users, distributors and importers, and publicly available information about similar devices. It must also cover suitable indicators and threshold values for continuous reassessment of the benefit-risk analysis, the methods and protocols for establishing a statistically significant increase under Article 88 including the observation period, and a post-market clinical follow-up plan under Part B of Annex XIV or a justification for its absence.
Section 1.2 is one line — the periodic safety update report under Article 86 and the post-market surveillance report under Article 85. Frequency follows class. Manufacturers of class IIb and class III devices update the PSUR at least annually. Manufacturers of class IIa devices update it when necessary and at least every two years. Class I manufacturers instead prepare a post-market surveillance report under Article 85, with no fixed periodicity, made available to the competent authority on request.
Here is the point that catches class I files. Article 84 states that for devices other than custom-made devices, the post-market surveillance plan shall be part of the technical documentation specified in Annex II. There is no class exemption. A class I self-declared file with an Annex II structure and no post-market surveillance plan is incomplete against Article 10(4), not merely thin.
What the authorised representative holds under Article 11(3)(b)
Article 11(3)(a) requires the representative to verify that the EU declaration of conformity and technical documentation have been drawn up and, where applicable, that an appropriate conformity assessment procedure has been carried out. MDCG 2022-16 is explicit that this means checking the existence of those documents. It is not a second conformity assessment and no representative should present it as one.
Article 11(3)(b) is the holding obligation: keep available a copy of the technical documentation, the EU declaration of conformity and, if applicable, a copy of the relevant certificate including amendments and supplements, at the disposal of competent authorities for the period referred to in Article 10(8). Section 6 of MDCG 2022-16 says what available means in practice. The manufacturer must provide the documentation in its most recent versions, in hard or electronic copy, and permanent access implies constant availability through electronic or physical storage, shared or otherwise. Shared electronic storage is acceptable. A superseded revision is not.
Article 11(3)(d) then requires the representative to provide the competent authority, on request, with all information and documentation necessary to demonstrate conformity, in an official Union language determined by the Member State concerned. Article 10(14) imposes the same language rule on the manufacturer. Neither the Regulation nor MDCG 2022-16 sets a fixed number of days for the response — the requesting authority sets the timeframe, which is exactly why a representative holding a stale copy has no room to recover.
Article 11(4): the obligations a mandate cannot move
Article 11(4) states that the mandate shall not delegate the manufacturer's obligations laid down in Article 10(1), (2), (3), (4), (6), (7), (9), (10), (11) and (12). Ten paragraphs, including paragraph (12) on corrective action, withdrawal and recall. Device conformity, risk management, clinical evaluation, classification, the technical documentation itself, the declaration of conformity, the CE marking, the quality management system, post-market surveillance and corrective action all stay with the manufacturer.
Article 11(5) is the counterweight. Where the manufacturer is not established in a Member State and has not complied with Article 10, the authorised representative is legally liable for defective devices on the same basis as, and jointly and severally with, the manufacturer. Read together, 11(4) and 11(5) explain why a serious representative asks to see the file before signing a mandate rather than after.
Article 11(3)(h) closes it: the representative must terminate the mandate if the manufacturer acts contrary to its obligations, and under Article 11(6) must immediately inform the competent authority and, where applicable, the notified body of the termination and its reasons. Termination is not a commercial decision dressed up in regulatory language; it is an obligation with a notification attached.
Where technical documentation is rejected in practice
Notified body sampling is where structure problems surface. Under Article 52(4), class IIb devices are subject to an assessment of the technical documentation for at least one representative device per generic device group — except class IIb implantables, other than the listed items such as sutures, staples, dental fillings, screws, plates, wires, pins, clips and connectors, where the assessment applies to every device. Under Article 52(6), class IIa devices are sampled at least one representative device for each category of devices. Those two units of sampling are not the same, and Annex IX Section 2.3 requires the notified body to document its rationale for the samples it takes.
The second recurring problem is a stale clinical evaluation. Annex II 6.1(c) requires the clinical evaluation report and its updates, alongside the clinical evaluation plan referred to in Article 61(12) and Part A of Annex XIV. Article 83(3) requires the technical documentation to be updated following post-market surveillance data. A file whose report predates two years of vigilance data is not a documentation formatting issue; it is a breach of Article 10(4).
The third is a standards assumption worth checking today. Under Commission Implementing Decision (EU) 2021/1182 and its amendments, EN ISO 13485:2016 with AC:2018 and A11:2021 is harmonised under the MDR, and EN ISO 14971:2019 with A11:2021 was added by Implementing Decision (EU) 2022/757 of 11 May 2022. Several standards manufacturers habitually cite are not on that list — including IEC 62304 for software life-cycle processes, IEC 62366-1 for usability engineering, and EN ISO 10993-1. They may still be applied, but under Annex II 4(c) they are other solutions applied, and they carry no presumption of conformity. If your general safety and performance requirements checklist treats them as though they do, the assessment will say so.
Retention: ten years, fifteen for implantable devices
Article 10(8) requires the manufacturer to keep the technical documentation, the EU declaration of conformity and any relevant certificate available for competent authorities for at least ten years after the last device covered by that declaration has been placed on the market, and at least fifteen years for implantable devices. Article 11(3)(b) binds the representative to the same period, and Article 13(9) binds the importer to the same period for the declaration and certificates.
The trigger is worth stating precisely, because it is often misread. The period runs from the placing on the market of the last device covered by the EU declaration of conformity — not from the certificate expiry, not from the date of manufacture, and not from the last shipment any individual operator happened to handle.
That has a practical consequence for changes of representative. A new representative starts its ten- or fifteen-year clock from the same event, which means it needs the historical file, not only the current revision. Transferring a mandate without transferring the full documentation set simply moves the gap. We are not a law firm and do not provide legal advice.

Sources
Regulation (EU) 2017/745, Articles 10(4), 10(8), 10(14), 11(3), 11(4), 11(5), 52(4), 52(6), 52(7), 83, 84, 85, 86; Annex II Sections 1 to 6; Annex III Section 1; Annex IX Sections 2.2 and 2.3
MDCG 2022-16 — Guidance on Authorised Representatives under Regulation (EU) 2017/745 and Regulation (EU) 2017/746, October 2022, Section 6
MDCG 2022-21 — Guidance on Periodic Safety Update Report (PSUR) according to Regulation (EU) 2017/745, December 2022
MDCG 2025-10 — Guidance on post-market surveillance of medical devices and in vitro diagnostic medical devices, December 2025
Commission Implementing Decision (EU) 2021/1182 of 16 July 2021, OJ L 256, 19 July 2021, as amended by Implementing Decision (EU) 2022/6 of 4 January 2022 and Implementing Decision (EU) 2022/757 of 11 May 2022
Who wrote this
Medex is a medical device manufacturer established in Ankara and a registered authorised representative in EUDAMED under SRN TR-AR-000057550. We are not a law firm and do not provide legal advice. Send us your device list and the current index of your technical documentation, and we will respond in writing.
As EU authorised representative Medex keeps the copy Article 11(3)(a) requires available for competent authorities, and files the Basic UDI-DI and device data in EUDAMED from the same file.




Comments