Medical Device Classes: MDR Risk Classification Explained

The route to market for a medical device in the EU rests on a single decision made early on: the risk class. It sets whether a notified body comes in, how deep the technical documentation has to go, how heavy the clinical evaluation becomes and which post-market obligations follow afterwards. Yet many teams treat this decision as paperwork at the end, not as architecture at the start.

This raises a practical question:
How do you classify a medical device correctly under MDR without getting tangled in Annex VIII or hitting nasty surprises at the next audit?

This article walks through the medical device classes under EU Regulation 2017/745: the four classes of medical devices with examples, the logic behind Annex VIII, the special case of software classification under Rule 11, what each class means for your project setup and the mistakes that most often trigger findings at audit.

Table of Content

one

Why Risk Classification Sets the Whole MDR Path

Risk classes as the EU regulation mechanism
Three

How MDR Annex VIII Classification Works

Four Categories, 22 Rules, One Logic

Software is the Special Case: Rule 11

Why MDD Software Lifts Under MDR

FAQs on Medical Device Classes

Answers to Recurring Questions

Why Risk Classification Sets the Whole MDR Path

The medical device risk classes are the mechanism EU Regulation 2017/745 (MDR) uses to scale how much regulatory depth a product needs. Class I lets the manufacturer self-declare conformity. From Class IIa upwards a notified body enters the picture, audits the QMS and signs off the product.

Budget, timeline and team setup hang off the classification result. A misclassification costs months, because the technical documentation, the clinical evaluation and the post-market system are not built for the class that applies. Worst case: the product turns up at audit with a dossier one tier too thin.

On top of that, there is the MDD-to-MDR effect. Many legacy products and especially software ran in Class I under the old Directive 93/42/EEC. Under MDR the same products often slide into IIa or higher, because new rules apply and old thresholds have shifted. Teams that miss this shift lose conformity quietly.

-> In short: The class decides the workload of the whole project. Wrong class means wrong path.

"Overview of the four medical device classes under MDR: Class I low risk, Class IIa medium risk, Class IIb elevated risk and Class III highest risk with conformity requirements and typical examples"

The Four Medical Device Classes Under MDR

MDR defines four medical device classes: I, IIa, IIb and III. The class rises with the potential harm to patients, users or third parties, with invasiveness and with how long the device is in use. Each of the classes of medical devices has its own conformity assessment route.

Class I: Low Risk

Class I covers medical devices with the lowest risk potential. The manufacturer can declare conformity itself, without involving a notified body. Typical examples are rollators, reusable surgical instruments, basic dressings and stethoscopes.

Three sub-classes break that simple path. Class Is applies to sterile devices, Class Im to devices with a measuring function and Class Ir to reusable surgical instruments. In all three sub-cases, a notified body steps in for the specific aspect, meaning for sterility, for the measuring function or for the reprocessing procedure.

Class IIa: Low to Medium Risk

Class IIa covers medical devices with moderate risk and shorter use duration. From this class onwards a notified body is mandatory for the conformity assessment. The quality management system per ISO 13485 is audited at the same time.

Examples are hearing aids, ultrasound systems, insulin pens and a large portion of digital health apps that target reimbursement pathways. Many Medical Device Software applications with a therapeutic or diagnostic function also land in IIa or above, driven by Rule 11.

Class IIb: Medium to High Risk

Class IIb sits at elevated risk. This bracket holds medical devices with longer use duration, active therapeutic function or significant energy delivery. The notified body audits deeper, clinical evidence carries more weight.

Typical examples are ventilators, infusion pumps, dialysis equipment and contact lenses for long-term use. Software whose output can cause serious deterioration in health also belongs here.

Class III: High Risk

Class III is the highest risk tier. It covers life-supporting devices, devices in direct contact with the heart or central nervous system and active implants. Examples include pacemakers, hip and breast implants and stents.

For Class III the notified body goes beyond the QMS and reviews each batch or works through very narrow sampling. A clinical investigation is the norm. A consultation procedure with an expert panel can be added on top. The bottom line: Class III is the heaviest regulatory setup and ripples through the whole product development effort.

-> In short: Class I for low risk with self-declaration, IIa and IIb with a notified body, III with clinical investigation as the standard.

What To Do:

  • Pin down the intended purpose early and the class follows from it.
  • List every plausible use case and check each one against Annex VIII.
  • Document the classification logic in full, because the notified body will want to see it.

How MDR Annex VIII Classification Works

Annex VIII of the MDR sets out 22 classification rules, organised into four main categories. Classification of medical devices follows the intended purpose of the product and not the technology that builds it. Plus, every applicable rule fires at the same time, never just one in isolation.

The Four Rule Categories

Annex VIII groups the rules into non-invasive devices (Rules 1 to 4), invasive devices (Rules 5 to 8), active devices (Rules 9 to 13) and special rules (Rules 14 to 22). This grouping gives the entry point for the classification.

One important point: a product can sit in several categories at once. A software-controlled insulin pump system is invasive (the needle), active (the pump) and contains software (Rule 11) all at the same time. Each of these axes triggers a classification rule that has to be checked on its own.

The 22 Rules at a Glance

The individual rules tier the class by use duration (transient, short-term, long-term), by depth of penetration and by energy delivery or substance action. Take Rule 9 as an example: active therapeutic devices are typically IIa, but when energy is delivered or withdrawn in a potentially hazardous way, the result becomes IIb.

Special rules (Rules 14 to 22) lift entire product groups across the board. These cover contraceptive products, products containing nanomaterials, products in direct contact with the heart or central nervous system and implants. Skip these special rules and the classification of medical devices comes out wrong.

The Worst-case Rule

When several rules apply to the same product, the highest resulting class wins. This worst-case logic is anchored explicitly in Annex VIII Section 3.5. In practice this means: walk through each applicable rule, note the resulting class for each, then take the highest.

Plus, accessories do not automatically inherit the class of the main device. The Accessories are classified in their own right. Teams that lump accessories into the main device's class build gaps into the technical dossier.

-> In short: Check every applicable rule one by one, the highest resulting class wins, so classify accessories separately.

"MDR Annex VIII classification flowchart for medical device classes covering non-invasive, invasive, active and special rules with Rule 11 highlighted for medical device software"

Software is the Special Case: Rule 11

Software gets its own rule under MDR. Rule 11 in Annex VIII applies to any software that qualifies as a medical device in its own right, in other words Medical Device Software (MDSW). This rule is the most consequential change versus MDD and the reason so many software vendors have to rethink their place in the medical device classes under MDR.

How Rule 11 Lifts Medical Device Software

Rule 11 in essence says: software that provides information for decisions with diagnostic or therapeutic purposes is at least Class IIa. It becomes IIb when those decisions can cause serious deterioration in health or surgical intervention. It becomes Class III when those decisions can cause death or irreversible deterioration in health.

Software that only monitors physiological processes also lands in IIa at minimum. It moves to IIb when the vital parameters carry critical consequences. Class I remains only for software with no diagnostic or therapeutic decision support, typically pure administration, documentation or logistics. So the corridor for Class I has become very narrow.

MDCG 2019-11: Qualify Before You Classify

Before classification comes qualification: is this software a medical device at all? The European Commission's MDCG 2019-11 guidance lays out the decision logic. Without a clean qualification call, the whole classification of medical devices for software hangs in the air.

MDCG 2019-11 checks three stages: is the software a medical device under MDR, does it fall under Annex VIII Rule 11 and what consequences follow. This order is not optional and auditors will expect to see the qualification decision before they accept the classification.

What This Means for Legacy MDD Software

Software that ran in Class I under the old MDD almost always lands in IIa or higher under MDR. That makes a notified body mandatory, requires a formally certified QMS per ISO 13485 and pulls the technical documentation and clinical evaluation to a deeper level. For many legacy products this is a serious effort that MDR transition plans regularly underestimate.

-> In short: Rule 11 and MDCG 2019-11 lift most medical software at least one class higher under MDR.

"Diagram showing how MDR Rule 11 reclassifies medical device software from MDD Class I into Class IIa, IIb or III depending on intended use and decision impact"

What Your Medical Device Class Means for the Rest of the Project

Medical device risk classes are not a label tacked on at the end of development, but drive direct consequences for project structure, team composition, budget and timeline. Three dimensions matter the most: notified body involvement, depth of technical documentation and clinical evaluation, plus the running post-market obligations.

Notified Body and Conformity Assessment

Class I without sub-class flags allows self-declaration. From Class Is, Im, Ir and IIa onwards a notified body is in the loop. That stretches the timeline by months, because audit slots are scarce and the QMS has to be in place before the first audit.

For IIb the notified body sampling technical files, for III it reviews each product design. This pushes substantial lead time into the plan and should be budgeted at the moment of risk classification, not afterwards.

Technical Documentation and Clinical Evaluation

Annex II of the MDR governs the technical documentation and the scope and depth scale with the class. Classes IIa and IIb call for substantive risk management files, verification and validation plans, plus complete software lifecycle documentation per IEC 62304.

Clinical evaluation follows MDR Article 61 and Annex XIV. For IIb and III, clinical investigations are usually required, whereas for IIa a literature-based evaluation can carry the case if equivalent evidence is strong enough. This call is made early and shapes research partnerships and study budgets.

Post-market Surveillance and PSUR

After market launch, Post-market Surveillance (PMS) kicks in. For Class I a PMS report is enough. From Class IIa onwards a Periodic Safety Update Report (PSUR) is mandatory, at least every two years. For IIb and III the PSUR is required annually and submitted to the notified body.

On top of that, Post-market Clinical Follow-up (PMCF) and EUDAMED obligations apply. Here too, the workload scales with the class and teams that fix the class too late and under-plan the PMS setup, end up retrofitting under live operations.

-> In short: Class steers notified body, documentation depth, clinical evaluation and PSUR cadence. Every one of those axes costs lead time.

What To Do:

  • Fix the class before the architecture freeze, or the dossier will trail reality.
  • Book notified body audit slots early. The market is tight.
  • Build the PMS and PSUR setup in parallel with development, not after launch.

Common Mistakes Classifying Medical Device Classes

From real projects, the same five mistakes around medical device risk classes come back again and again. They show up where classification was treated as a bureaucratic step at the end and not as a design decision at the start.

1. Carrying the MDD Class Over

The most common trap: an existing product is carried forward under MDR in the same class it held under MDD. Software vendors get caught here in particular. What was MDD Class I almost always becomes IIa or higher under Rule 11.

2. Underestimating Rule 11

Teams frame their software as pure administration or documentation, when it actually provides information for clinical decisions. The fallout is a Class I self-declaration that collapses under the first serious review, where MDCG 2019-11 is the test the notified body will apply.

3. Ignoring the Worst-case Rule

Several classification rules apply and the team picks the lowest or the most convenient one. Annex VIII Section 3.5 demands the highest resulting class. The classification logic has to demonstrate that every applicable rule was checked.

4. Lumping Accessories With the Main Device

Under MDR, accessories are classified in their own right. Running accessories in the class of the main device builds gaps into the technical dossier. Likewise, pure software modules attached to a hardware product often need their own Rule 11 assessment.

5. Missing the Special Rules: Nanomaterials, CNS Contact

Rules 14 to 22 lift entire product groups across the board. Nanomaterials, substances absorbed by the body, or direct contact with the heart or central nervous system pull a product into Class III. Teams that do not work through these special rules systematically risk a late uplift with re-engineering costs.

-> In short: MDD class carried over, Rule 11 underestimated, worst-case ignored, accessories lumped in, special rules missed. Five paths to the same audit finding.

FAQs on Medical Device Classes

Q1: Who decides the class of a medical device?

A1: Classification is made by the manufacturer, based on MDR Annex VIII. The notified body reviews the classification decision as part of the conformity assessment. In disputes, the competent national authority decides, in Germany the BfArM. A clean, documented classification logic is therefore part of the technical documentation.

Q2: Can a medical device fall into several classes?

A2: Yes. When several classification rules apply, the highest resulting class wins (Annex VIII Section 3.5). In practice: check each rule on its own, note the resulting class for each, then take the highest. Accessories within the same product family are classified in their own right, separate from the main classes of medical devices.

Q3: When is Medical Device Software still Class I?

A3: Only when the software provides no information for diagnostic or therapeutic decisions and does not monitor physiological processes. Typically, Class I remains for pure administration, documentation or logistics software and everything else falls under Rule 11 and is at least IIa.

Q4: How often do medical device risk classes need review?

A4: At every relevant change to the intended purpose, the functionality or the use case. A changed indication can also shift the class. During the live phase, classification is reviewed inside the post-market surveillance cycle and at every significant software update.

Closing Thoughts

Classifying the medical device classes is the call that shapes every later step under MDR. Teams that make it early, cleanly and with documented logic build the rest of the project on solid ground. Teams that defer it pay later in re-engineering, lost audit slots and retrofitted documentation.

If the classification of your product is unclear, or if a legacy Class I product needs re-assessment under MDR, a structured MDR consulting engagement is the fastest route to clarity and a realistic path to conformity.



What Else we can do for you?

Contact us to Schedule a Short Call

Classification unclear or MDR transition open? Let us talk.

    ```