What the Proposed MDR/IVDR Simplification Means for Medical Device and IVD Manufacturers

by | 18. 05. 2026 | Software Development

Reading Time: 5 minutes

On December 16, 2025, the European Commission proposed MDR/IVDR simplification, a legislative package to simplify the Medical Devices Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR).

Driven by the need to resolve administrative bottlenecks and support innovation, this reform is projected to save the industry approximately €3.3 billion annually while maintaining the highest standards of patient safety.

For manufacturers of medical devices, analytical instruments, and IVDs, the current regulatory landscape has often felt like an uphill battle, with strict rules slowing innovation and delaying market access. That’s why many companies are looking forward to a more innovation-friendly regulatory environment.

We analyzed the Commission’s proposal to understand how these changes could impact your product roadmaps, and how we can help you navigate them.

Smarter, more proportionate software classification

One of the most relevant proposed changes for software-driven devices concerns classification rules.

Under the current framework, the software driving your instruments or accessories is often pushed into higher-risk classes by default, regardless of its actual clinical impact. This has frequently meant longer conformity assessments and higher costs.

The new proposal introduces revised classification rules. The rules are being adapted so that certain software products may fall into lower, more appropriate risk classes. This is a major advantage for device manufacturers, as lower risk classification can translate to less burdensome conformity assessment procedures, reduced notified body involvement, and faster time-to-market.

What is Cyber Resilience Act (CRA)

Source: Unsplash

Clearer rules for outsourced software development

If you rely on an expert partner like BioSistemika to design and develop custom software for your devices, the new proposal brings greater transparency to this relationship.

The legislation clarifies that manufacturers whose devices (or device software) are designed and manufactured by another legal entity may need to submit the identity and digital contact details of that partner to the Eudamed database. Furthermore, as the legal manufacturer, you remain responsible for ensuring that the relevant technical documentation is properly maintained and made available to competent authorities.

This makes choosing a software development partner who deeply understands MDR/IVDR compliance more important than ever.

Streamlined rules for AI-enabled devices

If you are integrating Artificial Intelligence into your diagnostic devices, you are likely worried about overlapping compliance requirements between MDR/IVDR and the new EU AI Act.

To reduce these overlaps, the proposal updates how MDR and IVDR are referenced within the AI Act framework. By moving MDR and IVDR from Section A to Section B in Annex I of the AI Act, the proposal aims to simplify the regulatory pathway and reduce unnecessary duplication in conformity assessment procedures.

This could allow manufacturers to focus more on the clinical value of their algorithms rather than navigating overlapping regulatory processes.

“Regulatory sandboxes” for safe testing

One of the most exciting additions for innovators is the introduction of regulatory sandboxes at both the Member State and EU levels.

A regulatory sandbox is a controlled environment that allows you to develop, test, and validate innovative technologies — especially AI applications — under regulatory supervision and in real or simulated real-world conditions.

This could make it easier to evaluate and refine innovative software tools for IVDs and medical devices earlier in development, before moving into full conformity assessment procedures.

Clearer alignment on cybersecurity

As medical devices and laboratory instruments become increasingly connected, cybersecurity is paramount. The proposal addresses a crucial gap by aligning the MDR/IVDR with the Cyber Resilience Act. Among other changes, the proposal introduces clearer expectations around reporting actively exploited vulnerabilities and severe cybersecurity incidents through Eudamed and in coordination with cybersecurity authorities such as ENISA (EU Agency for Cybersecurity) and national CSIRTs (computer security incident response teams).

For manufacturers of connected devices, this reinforces the importance of secure software architecture, cybersecurity monitoring, and well-documented post-market processes.

What is Cyber Resilience Act (CRA)

Source: Pexels

Lifelines and cost reductions for “orphan devices”

If you manufacture highly specialized diagnostic instruments or devices for rare conditions, the new proposal introduces more flexible pathways to help keep these critical technologies on the market.

A device qualifies as an “orphan device” if it is intended to diagnose, prevent, or treat a condition affecting no more than 12,000 individuals in the EU per year and addresses an unmet medical need.

Under the proposed rules, orphan devices could benefit from a prioritised “rolling review” approach by notified bodies, helping speed up market access. To make these niche markets more economically viable, the proposal also foresees at least a 50% reduction in notified body conformity assessment fees.

Finally, the proposal introduces transitional provisions allowing certain legacy orphan devices previously marketed under the old Directives to remain on the market beyond the transitional periods without undergoing a full new MDR/IVDR conformity assessment, provided they continue to meet specific safety conditions.

Flexibility for in-house devices and clinical research

While the proposed overhaul does not outline a new, specific pathway for upgrading “Research Use Only” (RUO) products to commercial IVDs, it does introduce important flexibility for diagnostic innovation in laboratory settings. If your instruments are used by laboratories that develop their own custom tests, the rules for these “in-house devices” are becoming much more practical.

Notably, central laboratories that manufacture and use tests exclusively for clinical trials will now be explicitly included under the “in-house device” exemption. This means that as long as these laboratory-developed tests are not manufactured on an industrial scale and are not commercialized, they remain exempt from the full IVDR conformity assessment framework.

Furthermore, for health institutions using in-house IVDs, the current condition that “no equivalent device is available on the market” would be removed entirely.

This gives laboratories more flexibility to innovate, conduct clinical research, and use custom diagnostic tools without facing unnecessary regulatory barriers.

Broader administrative relief and SME support

Beyond software-specific updates, the proposal also introduces broader structural changes designed to reduce administrative burden and lower compliance costs across your product portfolio.

One important change is the removal of the current 5-year maximum validity period for certificates. Instead of fixed recertification cycles, the proposal introduces periodic reviews proportionate to the risk of the device while the certificate remains valid.

The administrative burden around post-market surveillance is also being reduced, including lower frequencies for updating Periodic Safety Update Reports (PSURs).

The proposal also introduces financial relief for smaller companies. Notified bodies would be required to apply fee reductions of at least 50% for micro enterprises and 25% for small enterprises.

SMEs would additionally benefit from more flexible rules regarding the Person Responsible for Regulatory Compliance (PRRC). For companies relying on an external PRRC, the proposal introduces greater flexibility around availability requirements.

When will these changes take effect?

It is important to note that this legislative overhaul is not yet in effect.

The European Commission officially presented the proposal on December 16, 2025, and it is currently moving through the EU legislative process. The proposal was also presented to the European Parliament’s Public Health (SANT) Committee in April 2026, where it received broad political support.

The proposal must still be formally adopted by both the European Parliament and the Council before the new measures become applicable. Adoption is currently expected in 2027.

Until then, medical device and IVD manufacturers must continue complying with the existing MDR and IVDR frameworks, including the currently extended transitional periods running through 2027, 2028, or 2029, depending on device risk class.

BioSistemika: Your compliance-oriented software development partner

Even with these simplification measures, translating regulatory requirements into compliant software architecture, secure code, and structured technical documentation still requires deep expertise.

In addition, the new proposal further reinforces manufacturer responsibility for documentation and development processes – including work performed by external software partners.

At BioSistemika, we combine software development expertise with deep understanding of regulated environments. We develop custom software in close cooperation with manufacturers, ensuring it fits the specific instrument or workflow while supporting MDR/IVDR compliance requirements from the start.

Contact us today to discuss how we can support your next MedTech software project and help streamline your regulatory journey.

Related articles

Subscribe to our newsletter

Receive news about new blog articles, webinars, and BioSistemika’s events.