scieee AI-readable full text Open interactive document viewer

ThrombUS+ D2.2: Regulatory framework, security, safety and ethics strategy and guidelines.

Prinz, Thorsten; Narten, Zoe; Wenner, Hans; Didaskalou, Stylianos; Schlötelburg, Cord

Abstract

A report detailing the compliance requirements for the development of ThrombUS+ outcome according to the corresponding EU legal frameworks, including security, safety, privacy, and ethical considerations.This report is the output of Task 2.2. The aim of Task 2.2 is to identify and early address the compliance requirement for the development of medical devices according to the corresponding EU legal framework, namely Medical Device Regulation (MDR) (EU 2017/745), along with the identification and inclusion of further relevant standards and guidelines according to the nature of the ThrombUS+.

Full text

D2.2. Regulatory framework, security, safety and ethics strategy and guidelines T. Prinz [VDE], Z. Narten [VDE], H. Wenner [VDE], S. Didaskalou [ATHENA], C. Schlötelburg [VDE] Due Date: 31 August 2024 Delivery Date: 17 July 2024 Revision Date: 12 November 2025 Horizon Innovation Action | Agreement No. 101137227 HORIZON-HLTH-2023-TOOL-05-05 Co-funded by the European Union D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 ii ThrombUS+ Consortium ATHENA Research and Innovation Center in Information, Communication and Knowledge Technologies, Greece Eleni Kaldoudi [email protected] KTU Kaunas University of Technology Lithuania Vaidotas Marozas [email protected] VERMON Vermon SA France Mathieu Legros [email protected] FRAUNHOFER Institute for Photonic Microsystems, Fraunhofer Germany Nicolas Lange [email protected] TELEMED Telemed Ultrasound Medical Systems Lithuania Dmitry Novikov [email protected] EchoNous EchoNous Inc USA Pavlos Moustakidis [email protected] MEDIS medis Medizinische Messtechnik GmbH Germany Susann Balling [email protected] ComfTech ComfTech SLR Italy Lara Alessia Moltani [email protected] TAU Faculty of Medicine and Health Technology Tampere University, Finland Antti Vehkaoja [email protected] LMSU Lithuanian University of Health Science Lithuania Andrius Macas [email protected] GNP Papageorgiou General Hospital Greece Maria Bigaki [email protected] CSS-IRCCS Home Relief of Suffering Hospital Italy Elvira Grandone e.grand[email protected] HSV Simon Veil Hospital France Maxime Gautier [email protected] VDE Association for Electrical, Electronic & Information Technologies, Germany Thorsten Prinz thorsten[email protected] MEDEA MEDEA SRL Italy Pietro Dionisio [email protected] PHAZE Clinical Research and Pharma Consulting SA Greece Spiros Anagnostopoulos [email protected] PBY PredictBy Research and Consulting SL Spain Frans Folkvord [email protected] SciGen SciGen Technologies SA Greece Katerina Pavlidi [email protected] Disclaimer This document contains description of the ThrombUS+ project work, findings, and products. The authors of this document have taken any available measure for its content to be accurate, consistent and lawful. However, neither the project consortium as a whole nor the individual partners that implicitly or explicitly participated in the creation and publication of this document hold any sort of responsibility that might occur as a result of using its content. Views and opinions expressed are those of the author(s) only and do not necessarily reflect those of the European Union or HADEA. Neither the European Union nor the granting authority HADEA can be held responsible for them. In case you believe that this document harms in any way intellectual property held by you as a person or as a representative of an entity, please do notify us immediately. ThrombUS+ is an Innovation Action Project co-funded by the European Union, under HORIZON-HLTH-2023-TOOL05-05 “Harnessing the potential of real-time data analysis and secure Point-of-Care computing for the benefit of person-centred health and care delivery”. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 iii Document Control Page Project Grant Agreement: 101137227 Acronym: ThrombUS+ Title: Wearable Continuous Point-of-Care Monitoring, Risk Estimation and Prevention for Deep Vein Thrombosis Type: Innovation Action Start: 1 January 2024 End: 30 June 2027 Programme: Horizon Europe Call Identifier: HORIZON-HLTH-2023-TOOL-05-05 Call Topic Harnessing the potential of real-time data analysis and secure Point-of-Care computing for the benefit of person-centred health and care delivery Website: http://thrombus.eu/ Deliverable # 11 No: D2.2 Deliverable Title: Regulatory framework, security, safety and ethics strategy and guidelines Deliverable Type: R Classification: PU Task: T2.2. Regulatory framework, security, safety and ethics Task Leader: VDE [T. Prinz] Work Package: Work package WP2 – Requirements and product co-design Work Package Leader: PBY [L. J. Segal] Responsible Partner: VDE Authors: T. Prinz [VDE], Z. Narten [VDE], H. Wenner [VDE], S. Didaskalou [ATHENA], C. Schlötelburg [VDE] Input from: --- Peer Reviewers: P. Dionisio [MEDEA], E. Kaldoudi [ATHENA] Due Date: 31 August 2024 Delivery Date: 17 July 2024 Revision Date: 12 November 2025 Document Status Version: 2.0 Status: Draft Consortium reviewed WP leader endorsed Coordinator endorsed D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 iv Revision History Version Date Modification Contributors 0.1 09 Jul 2024 First draft T. Prinz [VDE], Z. Narten [VDE], H. Wenner [VDE], C. Schlötelburg [VDE] 0.2 15 Jul 2024 Revised draft T. Prinz [VDE] based on comment by reviewers 1.0 16 Jul 2024 Revised for conformity S. Didaskalou [ATHENA] E. Kaldoudi [ATHENA] 2.0 12 Nov 2025 Revision based on interim review report #1 1. Reference error on page 11 was corrected. 2. The intended purpose was added in section 4.2 - different colours highlight different elements. 3. A new Annex 3 was added to summarize the interplay of technical documentation, standards and guidelines. 4. In Section 4.4.7. the new Annex 3 was referenced. 5. A summary of applying the ThrombUS+ use case to EU regulatory requirements for medical devices was introduced in a new Section 4.5. T. Prinz [VDE] E. Kaldoudi [ATHENA] D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 v Contents About ThrombUS+ ...................................................................................................................................................... 1 Deliverable D2.2 Description ...................................................................................................................................... 1 Cite this Document as ................................................................................................................................................. 1 Terms and Definitions ................................................................................................................................................ 2 Executive Summary .................................................................................................................................................... 4 1. Introduction ....................................................................................................................................................... 7 2. ThrombUS+ device use case ............................................................................................................................... 8 3. European regulatory framework for medical devices ......................................................................................... 8 3.1. European medical device legislation ................................................................................................................. 8 3.2. Actors ................................................................................................................................................................ 9 3.3. Standards and Guidelines .................................................................................................................................. 9 4. Steps towards placing a medical device on the European market .....................................................................11 4.1. Regulatory strategy ......................................................................................................................................... 11 4.2. Qualification as medical device ....................................................................................................................... 11 4.2.1. Accessory ................................................................................................................................................ 13 4.2.2. Procedure packs and systems ................................................................................................................ 13 4.3. Risk classification of the medical device .......................................................................................................... 14 4.4. Manufacturer obligations ............................................................................................................................... 14 4.4.1. General safety and performance requirements (GSPRs) ....................................................................... 14 4.4.1.1. Electrical safety .............................................................................................................................. 17 4.4.1.2. Electromagnetic compatibility (EMC) ............................................................................................ 17 4.4.1.3. Material compliance ...................................................................................................................... 18 4.4.1.4. Requirements regarding cybersecurity of medical devices ........................................................... 19 4.4.1.5. Requirements regarding AI-based medical devices ....................................................................... 20 4.4.1.6. Integrating medical devices with non-medical devices ................................................................. 21 4.4.2. Quality management .............................................................................................................................. 21 4.4.2.1. Product realization ......................................................................................................................... 22 4.4.2.2. Design and development of medical devices ................................................................................ 23 4.4.2.3. Design and development of medical device software (MDSW) .................................................... 24 4.4.3. Risk management ................................................................................................................................... 25 4.4.4. Usability engineering and testing ........................................................................................................... 27 4.4.5. Clinical evaluation ................................................................................................................................... 27 4.4.5.1. Clinical investigation ...................................................................................................................... 29 4.4.6. Instructions for use and labelling ........................................................................................................... 31 4.4.7. Technical documentation ....................................................................................................................... 33 4.4.8. Registration of product and manufacturer ............................................................................................ 33 4.4.9. Financial protection in the event of liability ........................................................................................... 35 4.4.10. Post-market surveillance and post-market clinical follow-up ................................................................ 35 4.4.11. Conformity assessment .......................................................................................................................... 36 4.5. Summary of applying the ThrombUS+ use case to EU regulatory requirements for medical devices ............. 39 4.6. Key regulatory roles......................................................................................................................................... 40 4.6.1. Person responsible for regulatory compliance (PRRC) ........................................................................... 40 D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 vi 4.6.2. Management representative for the QMS ............................................................................................. 40 4.6.3. Other regulatory roles ............................................................................................................................ 41 5. Role of the Notified Body (NB) ..........................................................................................................................41 5.1. Responsibilities during the conformity assessment procedure ....................................................................... 41 5.2. Surveillance of the manufacturer during the market phase ............................................................................ 41 5.3. Notification obligations of the manufacturer regarding the Notified Body .................................................... 42 6. Further applicable European legislations...........................................................................................................43 6.1. General Data Protection Regulation (GDPR) ................................................................................................... 43 6.2. Data Act (DA) and Data Governance Act (DGA) .............................................................................................. 44 6.3. Cybersecurity Directive (NIS 2) ........................................................................................................................ 44 6.4. Radio Equipment Directive (RED) .................................................................................................................... 44 6.5. Battery Regulation (BR) ................................................................................................................................... 45 6.6. Artificial Intelligence Act (AIA) ......................................................................................................................... 46 7. Upcoming European legislation .........................................................................................................................48 7.1. European Health Data Space (EHDS) Act ........................................................................................................ 48 7.2. Directive on liability for defective products ..................................................................................................... 48 7.3. Regulation on packaging and packaging waste .............................................................................................. 49 8. Ethical Consideration ........................................................................................................................................49 8.1. Ethics in clinical investigations with medical devices ...................................................................................... 49 8.2. Ethics in artificial intelligence .......................................................................................................................... 49 9. Literature ..........................................................................................................................................................50 10. Other sources ................................................................................................................................................60 Annex 1. Special MDR requirements for respective risk classes .................................................................................61 Annex 2. Compliance with MDR requirement regarding the quality management system by application of the EN ISO 13485 ..................................................................................................................................................................66 Annex 3. Interplay of technical documentation, standards, and guidelines ...............................................................67 Dx.x| Short Title v2.0 | 12 Nov 2025 1 About ThrombUS+ Deep vein thrombosis (DVT) is the formation of a blood clot within the deep veins, most commonly those of the lower limbs, causing obstruction of blood flow. In 50% of people with DVT, the clot eventually breaks off and travels to the lung to cause pulmonary embolism. Clinical assessment of DVT is notoriously unreliable because up to 2/3 of DVT episodes are clinically silent and patients are symptom free even when pulmonary embolism has developed. Early diagnosis of DVT is crucial and despite the progress made in ultrasound imaging and plethysmography techniques, there is a need for new methods to enable continuous monitoring DVT diagnosis at the point of care. ThrombUS+ brings together an interdisciplinary team of industrial, technology, regulatory, social science, and clinical trial experts to develop a novel wearable diagnostic device for point-of-care, operator free, continuous monitoring in patients with high DVT risk. The device will combine autonomous, AI driven DVT detection based on a novel wearable ultrasound hardware, impedance plethysmography and light reflection rheography for immediate detection of blood clot formation in the lower limb. Activity and other physiological measurements will be used to provide a continuous assessment of DVT risk and support DVT prevention via serious gaming. The aggregated data will drive an intelligence decision support unit that will provide accurate monitoring and alerts. Extended reality will be used to guide experts to design exercises and patients to use the device optimally. ThrombUS+ is intended for use by postoperative patients in the ward, during long surgical operations, cancer patients or otherwise bedridden patients at home or in care units, and women during pregnancy and postpartum. ThrombUS+ will use big data sets for AI training collected in the project via 3 large scale clinical studies and will validate the outcome in the clinical setting via 1 early feasibility study and 1 multi-center clinical trial. Deliverable D2.2 Description A report detailing the compliance requirements for the development of ThrombUS+ outcome according to the corresponding EU legal frameworks, including security, safety, privacy, and ethical considerations. This report is the output of Task 2.2. The aim of Task 2.2 is to identify and early address the compliance requirement for the development of medical devices according to the corresponding EU legal framework, namely Medical Device Regulation (MDR) (EU 2017/745), along with the identification and inclusion of further relevant standards and guidelines according to the nature of the ThrombUS+. Cite this Document as Prinz T, Narten Z, Wenner H, Didaskalou S, and Schlötelburg C, Regulatory framework, security, safety and ethics strategy and guidelines, Deliverable 2.2, ThrombUS+ Horizon Europe Innovation Action, EC Grant Agreement No. 101137227, 16 July 2024. Revised 12 November 2025. https://doi.org/10.5281/zenodo.17642311 D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 2 Terms and Definitions Term Definition AI Artificial Intelligence AIA Artificial Intelligence Act; EU 2024/1689 AI HLEG High-Level Expert Group on Artificial Intelligence IB Investigator's Brochure CA Competent Authority CE Conformité Européenne (European Conformity) CEN European Committee for Standardization (https://www.cencenelec.eu/europeanstandardization/european-standards/) CENELEC European Committee for Electrotechnical Standardization (https://www.cencenelec.eu/european-standardization/european-standards/) CDP Clinical Development Plan (as part of CEP) CEP Clinical Evaluation Plan CER Clinical Evaluation Report CIP Clinical Investigation Plan CIR Clinical Investigation Report DGBMT German Society for Biomedical Engineering (https://www.vde.com/de/dgbmt) DI Device Identifier DVT Deep Vein Thrombosis EC European Commission ECHA European Chemical Agency (https://echa.europa.eu/) EMC Electromagnetic Compatibility EUDAMED European Database on Medical Devices FDA U. S. Food and Drug Administration (https://www.fda.gov/medical-devices) FSCA Field Safety Corrective Actions GDPR General Data Protection Regulation GPAI General Purpose AI GSPR General Safety and Performance Requirements (MDR) IEC International Electrotechnical Commission (https://www.iec.ch/governmentregulators/medical-devices) IEEE Institute of Electrical and Electronics Engineers (https://www.ieee.org/) IFU Instructions for Use IG-NB German Notified Bodies Alliance (https://www.ig-nb.de/) IMDRF International Medical Device Regulators Forum (https://www.imdrf.org/) D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 3 Term Definition ISO International Organisation for Standardisation (https://www.iso.org/home.html) IVDR In Vitro Diagnostic Medical Devices Regulation; EU 2017/746 MDCG Medical Device Coordination Group (of EC) (https://health.ec.europa.eu/medicaldevices-dialogue-between-interested-parties/medical-device-coordination-groupworking-groups_en) MDR Medical Devices Regulation; EU 2017/745 MDSW Medical Device Software MHRA Medicines and Healthcare products Regulatory Agency (https://www.gov.uk/government/organisations/medicines-and-healthcare-productsregulatory-agency) NB Notified Body NBOG Notified Body Operations Group (https://www.nbog.eu/) OJEU Official Journal of the European Union (https://eur-lex.europa.eu/oj/directaccess.html?locale=en) PI Product Identifier PMCF Post-Market Clinical Follow-up PMS Post-Market Surveillance PRRC Person responsible for regulatory compliance PSUR Periodic Safety Update Report QMS Quality Management System RM Risk Management SMEs Small and Medium-sized Enterprises SRN Single Registration Number SSCP Summary of Safety and Clinical Performance TD Technical Documentation Team-NB European Association for Medical devices of Notified Bodies (https://www.team-nb.org/) ThrombUS+ EU project “Wearable Continuous Point-of-Care Monitoring, Risk Estimation and Prevention for Deep Vein Thrombosis” (https://thrombus.eu/) ThrombUS+ device Medical device that is developed in the respective EU project UDI Unique Device Identifier UN United Nations (https://www.un.org/en/) VDE Association for Electrical, Electronic & Information Technologies (https://www.vde.com/en) D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 10 essentially identical, whereas harmonized European standards must also contain a “European Foreword” and Annexes Z (usually designated as “ZA”, “ZB”… “ZZ”), which link the provisions of a standard to the relevant requirements of EU legislation. European standards are adopted unchanged into national standards by all CEN and CENELEC members, i.e., the national standards institutes. − Products designed and manufactured in accordance with the applicable harmonized European standards, the references of which are published in the Official Journal of the European Union (OJEU), shall benefit from a presumption of conformity with the relevant legal requirements (Art. 8 (1) MDR). However, the use of standards remains voluntary. Thus, it is solely up to the manufacturer to choose whether to use a standard or not. − A summary consolidates the references of harmonized standards published by the Commission in the OJEU and is regularly updated [6]. − It is common sense that the most recent versions of standards reflect the “state of the art”. However, unless their references are cited in the OJEU, "state of the art" standards do not confer a presumption of conformity. Figure 2. Important medical device standards embedded in the quality management of the manufacturer. There exist various types of standards, as summarized in Figure 2: − Basic standards determine general specifications for products, e.g., EN 60601-1. − Supplementary standards describe additional general requirements and tests, e.g., EN 60601-1-1. − Product standards, also known as vertical standards, refer to the basic and supplementary standards, e.g., EN 60601-2-4. They supplement or replace general standards with specific requirements and only apply to certain products in accordance with a European legal act. − Procedural or process standards describe the requirements for the development, introduction and maintenance of processes and have a cross-product (horizontal) significance, e.g., EN ISO 13485. Regarding the European Artificial Intelligence Act the development of respective standards by IEC, ISO and the Institute of Electrical and Electronics Engineers (IEEE) is ongoing [7], [8]. The guidelines are non-legally binding documents intended to provide practical interpretation, clarification, and recommendations on various aspects of the legal requirements. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 11 According to Art. 105, the MDCG shall contribute to the development of device standards, common specifications, and scientific guidelines, including product specific guidelines. The MDCG has issued guidelines to aid in the implementation of the MDR. They present a common understanding of the MDR requirements and pursue a harmonized implementation of the legislation. As the list of guidance documents is constantly being revised and expanded by the MDCG, medical device manufacturers are advised to monitor the guidelines on a regular basis [9]. On an international level the guidance documents published by the International Medical Device Regulators Forum (IMDRF) are to be mentioned. The IMDRF is a collaborative initiative comprising regulatory authorities and organizations from around the world. Its primary goal is to facilitate the harmonization of regulatory practices and processes related to medical devices. Other essential guidelines are published by the Notified Body Operations Group (NBOG) or the European Association for Medical devices of Notified Bodies (Team-NB). ThrombUS+ is a medical device, which means that Regulation (EU) 2017/745 (Medical Device Regulation, MDR) applies to its placing on the market in Europe. In order to be compliant with MDR requirements, it is recommended to consider various standards and guidelines, which are explained below in relation to the use case ThrombUS+. A complete collection of applicable standards and guidelines is available in the Zotero group library “ThrombUS+” (https://www.zotero.org/groups/5360524/thrombus) and as a list included in the technical documentation. 4. Steps towards placing a medical device on the European market This chapter discusses the key steps towards placing a medical device on the European market. Many of the requirements are applicable to any medical device. Special requirements for the ThrombUS+ use case are explained accordingly. 4.1. Regulatory strategy As part of the quality management system (QMS) requirements a “strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for management of modifications to the devices covered by the system” is required (Art. 10 (9a) MDR). The content of the regulatory strategy is outlined in more detail in No. 2.2. (c) of Annex IX MDR, namely “processes for identification of relevant legal requirements, qualification, classification, handling of equivalence, choice of and compliance with conformity assessment procedures”. Typical addressees of the regulatory strategy are NB, CA, Person Responsible for Regulatory Compliance (PRRC) and, if applicable, authorized representative and importer. 4.2. Qualification as medical device The qualification of a product as a medical device has a significant impact on the regulatory pathway, safety standards and market accessibility. To assess whether a product is a medical device within the meaning of the MDR or whether the product falls within the scope of the MDR, the intended purpose of the product must be defined. The intended purpose specifies the use for which a device is intended according to the manufacturer (Art. 2 (12), MDR). The intended purpose goes beyond a mere description of the device function and shall include clear specification of (No. 23.4. b) Annex I MDR): D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 12 − indications, − contra-indications, − patient target group or groups, and − intended users, as appropriate. Further key elements for the intended purpose are recommended, such as grade/stage/level of disease, use environment, and medical device functions [10]. Based on these provisions the following intended purpose has been developed for the ThrombUS+ device: ThrombUS+ is an active wearable diagnostic device for point-of-care, continuous (intermittent) monitoring in patients with increased risk for deep vein thrombosis (DVT), that is applied to the patient’s lower limbs. For this purpose, ThrombUS+ autonomously combines compression ultrasound imaging (CUS), electrical impedance plethysmography (EIP), and light reflection rheography (LRR) to assess blood clot formation and blood flow on the lower limbs. Additionally, ThrombUS+ uses inertial measurement units (IMUs) to monitor patient’s lower limb activity. Via an extended reality (XR) environment and serious gaming, patients are trained and motivated, respectively, to perform lower limb exercises for DVT prevention at the point of care. ThrombUS+ is intended for application to adult patients in the clinical environment by healthcare professionals. (ThrombUS+ intended purpose elements highlighted by different colors: indication, target patient groups and users, use environment, and medical device functions) The intended purpose must not be misleading by stating functions that the product does not have at the time it is placed on the market. After the intended purpose is elaborated, it can be compared to the definition of a medical device according to MDR. To be classified as medical device a device must fulfil one or more medical purposes according to Art. 2 (1) MDR: “Medical device means any instrument, apparatus, appliance, software, implant, reagent, material or other article intended by the manufacturer to be used, alone or in combination, for human beings for one or more of the following specific medical purposes: − diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease, − diagnosis, monitoring, treatment, alleviation of, or compensation for, an injury or disability, − investigation, replacement or modification of the anatomy or of a physiological or pathological process or state, − providing information by means of in vitro examination of specimens derived from the human body, including organ, blood and tissue donations, and which does not achieve its principal intended action by pharmacological, immunological or metabolic means, in or on the human body, but which may be assisted in its function by such means. The following products shall also be deemed to be medical devices: − devices for the control or support of conception; − products specifically intended for the cleaning, disinfection or sterilisation of devices as referred to in Article 1(4) and of those referred to in the first paragraph of this point.” Additionally, the intended purpose determines further steps for placing a medical device on the EU market. The intended purpose is decisive for [11]: D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 13 − the risk class to which the medical device belongs (cf. 4.3), − the risk management including setting criteria for risk acceptability (cf. 4.4.3), − criteria for selection of benchmark devices (to be considered in the clinical evaluation and postmarket surveillance) (cf. 4.4.5 and 4.4.10) − the validation of the usability (cf. 4.4.4) − the applicability of general safety and performance requirements (cf. 4.4.1) 4.2.1. Accessory An accessory is defined in Art. 2 (2) MDR as “an article which, whilst not being itself a medical device, is intended by its manufacturer to be used together with one or several particular medical device(s) to specifically enable the medical device(s) to be used in accordance with its/their intended purpose(s) or to specifically and directly assist the medical functionality of the medical device(s) in terms of its/their intended purpose(s)”. In general, accessories are treated as independent medical devices due to the risk classification provisions in No. 3.2. Annex VIII MDR. Thus, for accessories the conformity with the applicable General Safety and Performance Requirements (GSPR) of Annex I MDR must be assessed. This also applies regarding the use with the respective specified medical device(s). Moreover, not only the medical device but also its accessories shall be described in the technical documentation (No. 1.1. (h) Annex II MDR). 4.2.2. Procedure packs and systems Both procedure packs and systems combine devices to achieve a specific medical purpose (Art. 2 (10-11)). The following provisions are applicable for procedure packs and systems according to Art. 22 MDR: − Procedure packs and systems placed on the market by the manufacturer without an independent conformity assessment procedure must provide a declaration in accordance with Art. 22 (1-2) MDR. Moreover, specific labelling and information obligations apply (Art. 22 (5) MDR). − Procedure packs and systems that are sterilized before being placed on the market “apply one of the procedures set out in Annex IX or the procedure set out in Part A of Annex XI” under involvement of a NB (Art. 22 (3) MDR). − If procedure packs and systems contain devices, “which do not bear the CE marking or where the chosen combination of devices is not compatible in view of their original intended purpose […]”, these must comply with the regulatory requirements for medical devices (Art. 22 (4) MDR). ThrombUS+ device is intended for use in humans. The intended use of the ThrombUS+ device is the diagnosis and prevention of deep vein thrombosis (DVT) in adult patients. The device therefore fulfils the specific medical purposes stated in the MDR definition of a medical device. Furthermore, the ThrombUS+ device achieves its main effect not through pharmacological, immunological, or metabolic means, but through the implemented hardware and software technology. Therefore, the ThrombUS+ device fulfils the definition of a medical device according to Art. 2 (1) MDR. It is conceivable that the ThrombUS+ device may be placed on the market with accessories that enable it to be used as intended. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 14 4.3. Risk classification of the medical device The MDR follows a risk-based approach and categorizes medical devices into four different risk classes, namely I, IIa, IIb, and III, whereby class I represents the lowest risk class and III the highest (Art. 51 MDR). The higher the risk class, the higher the legal requirements to be met. For devices belonging to risk classes IIa, IIb and III, an NB must be involved in the conformity assessment process to obtain the CE marking. The same is true for sterile class-I-devices, class-I-devices with a measurement function, or reusable surgical instruments. The risk classification is performed according to the rules of Annex VIII MDR. The rules include several criteria, including above all technical, design, material and biological characteristics, invasiveness, contact duration, site of action and type of application. The intended purpose and all the device’s characteristics must be taken into consideration for determining the devices’ risk class. The manufacturer must take into consideration all rules to establish the proper classification for a device. In case several rules apply to a medical device the rule or sub-rule resulting in the highest classification determines the risk class of a device. The rules of the MDR are supplemented by recommendations from MDCG guidelines [12], [13]. The assignment of a risk class has far-reaching consequences in terms of the regulatory burden (cf. Annex “Annex 1. Special MDR requirements for respective risk classes”). ThrombUS+ is an active medical device (cf., 3.1.5 Active medical device of MDCG 202124). It is intended for diagnosis in clinical situations where the patient is in immediate danger (i.e., DVT) as well as for the prevention of DVT. Therefore, according to rule 10 Annex VIII MDR the risk class IIb is provisionally assigned. 4.4. Manufacturer obligations The manufacturer bears full responsibility for the respective product and places it on the market with all rights and obligations. To this end, the manufacturer must prove that he fulfils the following requirements in accordance with Art. 10 MDR. 4.4.1. General safety and performance requirements (GSPRs) Annex I MDR defines the GSPR to ensure the safety and performance of medical devices and thus the safety of patients, users and third parties. Some GSPRs are of a general nature while other GSPRs only apply for products with certain characteristics such as devices emitting ionizing radiation, devices incorporating materials of biological origin or devices that are delivered sterile (Figure 3). The manufacturer must fulfil all GSPRs applicable to his product (Art. 5 MDR). The applicable GSPRs for a specific device are identified based on the development of related documents, such as requirements and design specifications, and particularly the results of the risk management process. In its “Blue Guide”, the European Commission (EC) proposes a risk assessment or similar by the manufacturer as a preliminary step for selecting the requirements applicable to the product in question [14]. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 15 Figure 3. Selection of product-specific GSPRs and application of standards for presumption of conformity (adapted from [14]). The GSPRs are categorized into three chapters in Annex I MDR: I. General requirements − Requirements regarding the risk management. − Requirements for maintaining characteristics and performance of a device (during normal condition of use, storage, transport). II. Requirements regarding design and manufacture (depending on the device nature) − Chemical, physical, and biological properties. − Infection and microbial contamination. − Devices incorporating a medicinal product or substances absorbed by the human body. − Devices incorporating materials of biological origin. − Construction of devices and interaction with their environment. − Devices with a diagnostic or measuring function. − Protection against radiation. − Electronic programmable systems (devices incorporate electronic programmable systems and software that are devices in themselves). − Active devices and devices connected to them. − Active implantable devices. − Protection against mechanical and thermal risks. − Devices supplying energy or substances. − Devices intended by the manufacturer for use by lay persons. III. Requirements regarding the information supplied with the device − General requirements regarding the information supplied by the manufacturer. in Annex I based on the risk analysis for the product in ques on from Annex I No. x No. y No. z (...) Applicable requirements ful lled Presump on of conformity No presump on of conformity D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 16 − Information on the label. − Information on the sterile packaging. − Information in the instruction for use. The first chapter of Annex I focusses on risks associated with the medical device, and the related risk management. Here the link to the manufacturers obligation to implement and maintain a risk management process can be seen (Art. 10 (2) MDR) (cf. 4.4.3). Regarding risk management, the manufacturer shall, in accordance with Annex I MDR: − establish and document a risk management plan for each device, − identify and evaluate risks associated with, and occurring during, the intended use and during reasonably foreseeable misuse, − eliminate or reduce risks as far as possible through safe design and manufacture, − take adequate protection measures, in relation to risks that cannot be eliminated, − inform the user of any residual risks (e.g., warnings/precautions/contra-indications) and, where appropriate, train users. The second chapter of Annex I lists requirements regarding the design and manufacture of a device. The applicability of those requirements depends on the nature of the device. The third chapter of Annex I lists requirements regarding information supplied with a device by the manufacturer. This includes requirements regarding the instructions for use (IFU). Chapter III details the information to be provided on the device label (No. 23.2. Annex I MDR). The label information is for identifying the device and its nature (e.g., single use or custom made). Therefore, among other the UDI carrier shall be on the device label (cf. 4.4.8). The information required on the label shall be provided on the device itself. In cases where this is not feasible or suitable, some or all of the required information may instead be presented on the packaging of each individual unit and/or on the packaging containing multiple devices. Labels shall be provided in a human-readable format and may be supplemented by machine-readable information, such as radio-frequency identification (‘RFID’) or bar codes. For devices with sterile packaging specific requirements regarding the labelling on the sterile packaging are outlined in No. 23.3. Annex I MDR, such as a declaration that the device is in a sterile condition and the method of sterilization. After identification of the applicable requirements the manufacturer must prove the fulfilment of these individual requirements. For this purpose, standards can be used (cf. 3.3). For example, the basic standard EN 60601-1 sets out electrical safety requirements for medical devices [15]. EN 60601-1 and its collateral standards and special parts apply to basic safety and essential performance of medical electrical (ME) equipment and systems. Depending on the GSPR the evidence for fulfilment is documented in various devicespecific documents, e.g., the risk analysis or the IFU which are included in the technical documentation of the device. GSPRs that are not applicable should be justified by the manufacturer. It is beyond the scope of this document to discuss all GSPR applicable to the ThrombUS+ device. However, the following paragraphs discuss the relevant directives and standards and their application for some exemplary GSPRs. ThrombUS+ device is composed of hardware components and software components, including AI and, thus, the following sections shall achieve consideration: devices with a diagnostic or measuring function, protection against radiation, electronic programmable systems, active devices, and devices connected to them, and protection against the risks posed to the patient or user by devices supplying energy or substances. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 17 4.4.1.1. Electrical safety In accordance with Art. 2 (4) MDR, an active medical device is powered by an electrical or other energy source (apart from energy generated directly by the human body or by gravity). The electrical safety of active medical devices with an applied part 2 is required in No. 18.7 of Annex I MDR. The standard EN 60601-1 “Medical electrical equipment - General requirements for basic safety and essential performance” describes the general safety requirements [16]. Most of the standard contains detailed instructions for the various tests that medical devices must pass, such as electrical safety, mechanical stability, and resistance to environmental conditions. A respective IECEE TRF 60601-1 test report serves as proof of compliance with the standard requirements [17]. Moreover, collateral standards EN 60601-1-1 to -12 contain specifications for basic safety and essential performance characteristics for specific equipment subgroups and particular standards are presenting an even further refinement of requirements. EN 60601-1 follows a “single-fault-safe design” approach. No unacceptable risk shall occur during the expected operating time, although a single fault or an abnormal external condition has occurred (example: power supply failure or excessive voltage at a signal input or signal output part). This approach of single-fault safety is extended by risk management considerations to take account of current technological developments and increasingly complex device designs. To determine specific test conditions, currently not covered by the standard, the manufacturer uses the results of the risk analysis to simulate possible further failures and possible combinations of adverse conditions. General requirements for the design are spread across the individual EN 60601-1 chapters. Finally, medical devices must have suitably located controls in place and be designed to provide adequate access for maintenance purposes. 4.4.1.2. Electromagnetic compatibility (EMC) According to No. 14.2 b), 18.5, and 18.6 of Annex I MDR, manufacturers must ensure that their medical devices are not sensitive to electromagnetic influences and do not interfere with other devices in their environment. The manufacturer must declare that protection requirements have been met. Besides the mentioned requirements of the MDR, further requirements for electromagnetic compatibility arise from directive 2014/53/EU (cf. 6.4). Compliance with electromagnetic protection requirements is normally demonstrated by so-called “immunity testing” of the equipment in accordance with the applicable harmonized standards. In the field of medical devices, the standard EN 60601-1-2 [18] defines the state of the art and describes tests-procedures and limits. Important: before testing, the EMC test plan including pass/fail criteria must be determined by the manufacturer. EN 60601-1-2 addresses: − immunity to interference, − emission of radiation and thus potential interference with other devices, − robustness against electrostatic discharge, and − resistance to static magnetic fields. For devices that are used by the patient at home, the requirements of EN 60601-1-11 apply [19] 3 . In general, the risk assessment as part of the risk management activities should include the EMC risks and the influence of the expected electromagnetic environment. Risk Management is the basis for defining the EMC test plan. 2 Applied part: Part of medical electrical equipment that in normal use necessarily comes into physical contact with the Patient for medical electrical equipment or a medical electrical system to perform its function (no. 3.8, IEC 60601-1). 3 Another collateral standard exists for rescue service devices (EN 60601-1-12). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 18 4.4.1.3. Material compliance Material compliance for medical devices refers to compliance with regulatory requirements regarding the use, effects, compatibility, properties and disposal of materials and substances over the entire life cycle. The aim is to ensure safe use in accordance with the intended purpose. Section “10. Chemical, physical, and biological properties” of Annex I MDR describes the requirements for the materials and substances used and is structured as follows: − 10.1 General requirements − 10.2 Risks due to pollutants and residues − 10.3 Compatibility with materials and substances − 10.4 Risks from substances in medical devices or substances that are released − 10.5 Risks due to the penetration of substances into the medical device − 10.6 Risks due to the penetration of particles into the skin The manufacturer must confirm that the product meets all defined chemical and/or physical specifications. Important documents for proofing conformity are the development documentation (including the requirement specifications), the test reports, the risk management report (with reference to the risk analysis), and the clinical evaluation report. According to section 7.5.6 of ISO 13485 the results of the QMS processes on material used in medical devices are examined as part of the process validation (cf. 4.4.2). The corresponding certificates of conformity are part of the preclinical and clinical data in the technical documentation in accordance with section 6.1 b) Annex II MDR. The type and duration of contact between the medical device and materials and medicinal products (if applicable) has a significant influence on the risk profile. If medicinal products are components of the medical device, the relevant EU legislation must be observed. Carcinogenic, mutagenic or reprotoxic (CMR) substances and substances with endocrine disrupting properties may only be contained up to 0.1% by mass (w/w) (Annex I MDR). Higher mass percentages are only permitted with detailed justification. Regarding these substances, special requirements for packaging labelling and instructions for use must be observed. To date, only a few guidelines on material compliance have been published under the MDR. One exception is the “SCHEER Guidelines on the benefit-risk assessment of the presence of CMR/ED phthalates in certain medical devices” from 2019 [20]. Nanomaterials “means a natural, incidental or manufactured material containing particles in an unbound state or as an aggregate or as an agglomerate and where, for 50 % or more of the particles in the number size distribution, one or more external dimensions is in the size range 1-100 nm” (Art. 2 (18) MDR). In medical devices, nanomaterials receive special attention from the EU legislator. This is expressed on the one hand by the publication of the SCENIHR Guidance on the determination of potential health effects of nanomaterials used in medical devices in 2015 [21] and on the other hand in the special rule 19 on the risk classification of products with nanomaterials (Annex VIII MDR). ISO/TR 10993-22 serves to avoid risks in relation to the size and properties of particles. Further material compliance requirements may arise from other EU legislation as discussed in the following paragraph. Regulation (EC) 1907/2006 (REACH) regulates the registration, evaluation, authorization, and restriction of chemical substances throughout Europe [22]. Regulation (EC) 1272/2008 (CLP) implements provisions of the United Nations (UN) “Globally Harmonized System of Classification and Labelling of Chemicals (GHS)” in the EU [23]. Manufacturers are obliged to provide information on articles that contain a substance on the European Chemical Agency's (ECHA) so-called “candidate list” with a mass fraction > 0.1% (Art. 33 REACH) [24]. This information must also be included in the risk analysis. Safety data sheets are not required for certain medical D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 19 devices (Art. 2 (6c) REACH). Registration of the uses of substances by the medical device manufacturer in accordance with REACH is only required if this has not already been done by the supplier. Directive 2011/65/EU (RoHS 2) on the restriction of the use of certain hazardous substances in electrical and electronic equipment also applies to medical devices in accordance with Annex I [25]. The directive was implemented in the national legislation of the member states, e.g., in Germany as the Electrical and Electronic Equipment Substances Ordinance (German: ElektroStoffV). At present, RoHS 2 does not apply to active implantable medical devices (Art. 2 (4h) RoHS 2). In principle, electrical and electronic equipment may not contain any of the substances listed in Annex II (last amended by Delegated Directive (EU) 2015/863 (RoHS 3)) above the specified concentrations (Art. 4 (1) RoHS 2) [26]. Medical devices as well as monitoring and control instruments from Annex IV RoHS 2 are exempt from this restriction. Manufacturers must prepare a technical documentation with the corresponding proof of conformity and undergo a conformity assessment procedure (Art. 7 b-c RoHS 2). Depending on the type of materials used, the following EU regulations and directives may also apply to the manufacturing, packaging, and disposal of medical devices: − Directive 94/62/EC on packaging and packaging waste [27], − Regulation (EU) 528/2012 concerning the making available on the market and use of biocidal products [28], − Directive 2006/66/EC on batteries and accumulators and waste batteries and accumulators [29] , − Regulation (EU) 2017/821 laying down supply chain due diligence obligations for Union importers of tin, tantalum, tungsten, their ores and gold originating from conflict-affected and high-risk areas [30], − Regulation (EU) 2019/1021 on persistent organic pollutants (POPs) [31], − Regulation (EU) 2017/852 on mercury [32], and − Directive 2012/19/EU on waste electrical and electronic equipment (WEEE) [33]. ThrombUS+ device is composed of various materials that potentially could be harmful for patients and users during body contact. Various lab tests and animal experiments might be necessary to be carried out if no other biological safety data are available. 4.4.1.4. Requirements regarding cybersecurity of medical devices According to No. 17.2. of Annex I MDR the “[...] principles of development life cycle, risk management, including information security, verification and validation” shall be taken into account for the development and manufacturing in accordance with the state of the art. No. 17.4. continues: “Manufacturers shall set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorised access, necessary to run the software as intended”. This requirement imposes challenges regarding cybersecurity, which need to be promptly addressed during development. Two standards are addressing these issues: EN 62304 and IEC 81001-5-1 [34], [35]. EN 62304 "Medical Device Software – Software Lifecycle Processes" is an international standard specifying requirements for the development and maintenance of medical device software but mainly focused on safety and reliability. The standard emphasizes thorough planning, requirements analysis, design, implementation, verification and maintenance, integrating risk management to ensure the software's continuous safety and effectiveness. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 26 Figure 6. Risk management (RM) process overview (adapted from [59]). In contrast to FMEA (Failure Modes and Effects Analysis), risk analysis is not limited to malfunctions or failures. Even a product that is fully functional (i.e., working without any failure), operated under normal conditions within the scope of its intended purpose can lead to risks, simply due to the nature of the device or the function it fulfils. Risk management is therefore based on both desired and undesired effects, which can occur when using medical devices. According to ISO 14971, risk is a combination of harm and a probability of occurrence of this harm (sometimes called “likelihood”). To determine risk, ISO 14971 describes a systematic process for identifying, evaluating, and mitigating risks associated with medical devices. To accomplish this, risk management begins by identifying potential hazards and estimating the severity of the harm they could cause. In the next step, the probability (likelihood) of occurrence is assessed. Together, these two factors determine the overall level of risk. Once risks have been identified, they need to be evaluated which means that they are compared with a scale defining risk acceptance. This acceptance is not predefined; it must be specified by the manufacturer. In case a risk can be minimized, the necessary control measures shall be implemented to minimize the risks to acceptable levels, ensuring the safety and effectiveness of the device. However, measures cannot be chosen arbitrarily; MDR dictates in Annex I, 4. the order: a) eliminate or reduce risks as far as possible by means of safe design and manufacturing; b) where appropriate, take adequate protection measures, including alarms, if necessary, in relation to risks that cannot be eliminated; and c) provide information for safety (warnings/precautions/contra-indications) and, where appropriate, training to users. As mentioned above: contribution to risk may arise from the desired effects which are part of the intended purpose and the intended use of medical devices. The undesirable effects are comparable to "side effects". In addition, unexpected events can occur (e.g., malfunctions, external abnormal conditions, cyber-attacks), which can then result in undesirable effects. Special technological characteristics must also be considered: regarding AI-based medical devices and cybersecurity, specific associated risks must also be addressed. For software components in addition to operational safety, IT security (commonly referred to as "cybersecurity") must also be considered in risk management. A medical device is safe (which is the “freedom from unacceptable risk”) only if the benefits outweigh the risks. The manufacturer defines his risk acceptance criteria, based on this concept. Residual risks of which a D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 27 user must be informed are included as restrictions, contraindications, precautions, or warnings in the instructions for use or labelling. For the final assessment of the safety of his product, the manufacturer must relate the risks to the expected benefits. It is good practice to include these considerations in the clinical evaluation. 4.4.4. Usability engineering and testing Usability is defined as a “characteristic of the user interface that facilitates use and thereby establishes effectiveness, efficiency and user satisfaction in the intended use environment” [62]. The MDR contains several related requirements: Requirements References Identification of possibilities for improving usability Art. 83 (3f) MDR Proof of suitability their intended purpose No. 1. of Annex I MDR Risk management regarding intended use and reasonably foreseeable misuse No. 3c of Annex I MDR Reduction of risks related to ergonomic features No. 5a of Annex I MDR Safe use in combination with other products No. 14.1. of Annex I MDR Reduction of injury risks in relation to ergonomic features No. 14.2a of Annex I MDR Measurement, monitoring, or display scale design. and manuf. acc. to. ergonomic principles No. 14.6. of Annex I MDR Understandable instructions for device operation or parameters (visual system) No. 21.3. of Annex I MDR Protection against the risks associated with lay products No. 22. of Annex I MDR Labelling and instructions for safe use No. 23. of Annex I MDR The standard EN 62366-1 details how to set up a usability engineering process for assessing and mitigating “risks associated with correct use and use errors, i.e., normal use”. IEC 62366 part 2 focuses not only on usability in relation to safety, but also on task accuracy, completeness and efficiency, and user satisfaction [63]. Performed usability tests may or may not fall under the definition of clinical investigation in Art. 2 (45) MDR. Therefore, as part of the technical documentation, manufacturers should justify “why a particular usability test falls outside the definition of a clinical investigation when human subjects are involved” [64]. The formative evaluation of the user interface is “performed iteratively throughout the design and development process” whereas the summative evaluation is “conducted at the end of the […] development with the intent to obtain objective evidence that the user interface can be used safely” [62]. Thus, the summative evaluation can be regarded as a validation of the use-related safety aspects of the user interface [63]. 4.4.5. Clinical evaluation The manufacturer is obliged to carry out a clinical evaluation of the medical device in accordance with the requirements laid down in Art. 61 and Annex XIV MDR. According to Art. 2 (44) MDR, the clinical evaluation is defined as a “systematic and planned process to continuously generate, collect, analyse and assess the clinical data pertaining to a device in order to verify the safety and performance, including clinical benefits, D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 28 of the device when used as intended by the manufacturer”. Moreover, the clinical evaluation examines the benefits compared to the current standard clinical procedure. Thus, the key question to be answered by the manufacturer is whether the clinical evidence supports the intended purpose and the clinical claims of the device. The clinical evaluation is part of the QMS of the manufacturer and interacts there with the risk management (cf. 4.4.5) as well as the post-market surveillance (PMS) and post-market clinical follow-up (PMCF) (cf. 4.4.10) [65]. Clinical data may originate from the following sources (Art. 2 (48) MDR): − clinical investigation(s) of the device concerned, − clinical investigation(s) or other studies reported in scientific literature, of a device for which equivalence to the device in question can be demonstrated, − reports published in peer reviewed scientific literature on other clinical experience of either the device in question or a device for which equivalence to the device in question can be demonstrated, and − clinically relevant information coming from post-market surveillance, particularly the post-market clinical follow-up. Although developed under the former legislative framework for medical devices the guideline MEDDEV 2.7/1 rev. 4 is still representing the state of the art for clinical evaluation [66]. In addition, the MDCG has published guidelines regarding the clinical evaluation under the MDR. The two major documents generated during the clinical evaluation process are the Clinical Evaluation Plan (CEP) and the Clinical Evaluation Report (CER) (Annex XIV MDR). The CEP outlines the strategy for assessing the clinical evaluation. To this end, the CEP defines the objectives, methods and timetable for the collection and analysis of clinical data. Part of the CEP is the clinical development plan (CDP) “indicating progression from exploratory investigations, such as first-in-man studies, feasibility, and pilot studies, to confirmatory investigations, such as pivotal clinical investigations, and a PMCF […] with an indication of milestones and a description of potential acceptance criteria (Section 1 (a) of Annex XIV MDR). The results of the clinical evaluation process are documented in the CER. The CER provides a comprehensive analysis of the clinical data collected and draws up conclusions regarding the device's safety, performance and its clinical benefits compared to existing alternatives. To achieve this, authors of the clinical evaluation must demonstrate appropriate qualifications [66]. For implantable devices and class III devices, a summary of safety and clinical performance (SSCP) with a summary of the clinical evaluation must be prepared, to place the device “in the context of diagnostic or therapeutic options taking into account the clinical evaluation of that device when compared to the diagnostic or therapeutic alternatives and the specific conditions under which that device and its alternatives can be considered” (Recital 49 MDR). The MDCG published an SSCP template and a guideline with details on the expected content and the involvement of the NBs [67], [68]. For medical device software (MDSW) the guideline MDCG 2020-1 mentions three key components for the clinical evaluation (required by MDR) / performance evaluation (required by IVDR) [69]: − Valid clinical association/scientific validity: The relationship between a software output and a clinical condition or physiological state shall be established (e.g., evidence by citing a medical guideline) in the state-of-the-art section. − Technical performance: Refers to the ability of software to generate the intended technical output from the input data accurately and reliably (evidence by software verification and validation) and becomes as pre-clinical data part of the clinical data section. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 29 − Clinical performance: Refers to the ability of a software (technical/functional and diagnostic characteristics) to fulfill its intended purpose to achieve the clinical benefit for patients (e.g., evidence by clinical investigation) and becomes part of the clinical data section. Clinical evaluation of the ThrombUS+ device shall encompass both hardware and software components. The sample size must reflect the actual patient target groups. Unresolved questions must be transferred to corresponding PMCF activities within the PMCF plan. 4.4.5.1. Clinical investigation A clinical investigation 6 for medical devices is to be understood as a systematic investigation involving one or more human subjects and conducted for the purpose of evaluating the safety or performance of a medical device (Art. 2 (45) MDR). There is an obligation to conduct a clinical investigation for: − existence of gaps in the clinical data that cannot be covered by other sources, − a class III medical device, unless it is merely a modification of a medical device already placed on the market and the manufacturer fulfils the associated further requirements (Art. 61 (4) MDR), − introduction of a completely new medical device with new features and functions, − modification of an existing medical device with impairment of clinical safety and performance or − extension of the medical purpose for an existing medical device. The MDR only concerns clinical investigations intended to provide clinical evidence to demonstrate the conformity of devices and sets out general requirements for other types of clinical investigations (Art. 62-82 and Annex XV MDR). Depending on the purpose and the impact on the patient several types of clinical investigations can be distinguished, as shown in Figure 7. The MDR legal text relates to general provisions, informed consent, clinical investigations with subjects requiring special monitoring, application procedure and assessment by the Member States, electronic system, etc. The Commission is authorized to enact implementing acts for “detailed arrangements and procedural aspects” (Art. 81 MDR). Moreover, some aspects of the clinical investigations are regulated in national legislations, e.g., in Germany by the Medical Devices Implementation Act (MPDG). Among these are typically “procedures for review and authorization by ethics committees, responsibility for medical care provided to subjects, investigator qualifications, legally designated representative for subjects, damage compensation systems, designation of CA as well as additional requirements for clinical investigations falling under Article 82 of the MDR” [64]. Retrospective clinical studies (e.g., analysis of available patient data) are often preferred over prospective studies for medical device software because they do not impact patient management or add patient risks. These studies are not subject to MDR but probably to Member States provisions and underly the data protection legislation [64]. Good clinical practice is described in the EN ISO 14155 standard and it addresses design, conduct, recording and reporting of clinical investigations [70]. Compared to previous versions the actual 3rd edition reinforces risk management throughout the clinical investigation process. Different stages of clinical development require also different types of clinical investigations (Annex I EN ISO 14155). For example, at an early stage these are typically first-in-human, proof-of-concept and traditional feasibility clinical investigations. 6 The EN ISO 14155 standard defines a clinical trial in section 3.8 as "a systematic investigation on one or more subjects conducted to evaluate the clinical performance, efficacy or safety of a medical device". According to EN ISO 14155, the terms “clinical trial” or “clinical study” are to be used synonymously with “clinical investigation”. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 30 Figure 7. Types of clinical investigations with medical devices according to MDR (adapted from [64]). The sponsor acts as a key player in clinical investigations. Art. 2 (49) MDR defines this as “any person, company, institution, or organization that assumes responsibility for initiating, managing, and establishing funding for the clinical trial.” If the sponsor is located outside the EU, it requires a natural or legal person as legal representative (Art. 62 (2)). The application for a clinical investigation encompasses the following documents [71]: − Application form (cf. No. 1. Chapter II of Annex XV MDR) with sponsor details, dates and duration, details of the clinical evaluation plan etc., − Investigator's Brochure (IB, cf. No. 2. Chapter II of Annex XV MDR) with clinical and non-clinical information about the investigational product [72], and − Clinical Investigation Plan (CIP, cf. No. 3. Chapter II of Annex XV MDR) including justification, goals, design, applied methodology, monitoring activities and statistical considerations regarding the respective clinical investigation as well as information on the organization and implementation [73]. If the clinical investigations are to be conducted outside the European Union, the transferability of the clinical data to the European population must be considered [74]. Any changes which have a significant impact on the safety, health or rights of the subjects or on the robustness or reliability of the clinical data generated shall be notified to the Member State(s) in which a clinical investigation is being conducted [75]. The implementation of the clinical investigation is governed by Art. 72 and Chapter III of Annex XV MDR. Accordingly, the sponsor has several important responsibilities, for example: − continuous compliance with the CIP, Medical device CE Marked Within intended purpose PMCF Addi onal burdensome and/or invasive procedures No addi onal burdensome and/or invasive procedures ther clinical inves ga on / Na onal provisions Not within intended purpose Inves ga on may be used for conformity procedure (to get CE mark) Not inves gated for conformity procedure Not yet CE Marked Inves ga on may be used for conformity procedure (to get CE mark) Not inves gated for conformity procedure Not to be CE marked (e.g. custom made / in house manufactured devices) Inves ga on may be used for conformity procedure (although product is not to be CE marked) Not inves gated for conformity procedure D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 31 − continuous monitoring of implementation (in accordance with good clinical practice), − careful handling of clinical data (collection, storage, evaluation, protection and security), and − careful handling of vigilance data and handling of emergencies through an established process. In the case of occurring adverse events and serious adverse events safety reporting is required [76], [77]. Serious adverse events result in serious consequences for the life or health of the patient. The sponsor must always record and report serious adverse events (Art. 80 (1-2) MDR). Reporting occurs in the clinical investigation report (CIR) according to the structure given in No. 7. Chapter III Annex XV MDR. The respective summary shall be written in “easily understandable language” applying a defined structure [78]. To ensure transparency and reproducibility of the clinical investigations published in journals, reporting guidelines have been issued that require sufficiently detailed descriptions of the study design, inclusion and exclusion criteria, details of the study methodology and standards used, as well as details on the medical device under investigation. However, a recent examination of the few available published Randomized Clinical Trials (RCTs) for medical machine learning interventions revealed “high variability in adherence to reporting standards and risk of bias and a lack of participants from underrepresented minority groups” [79]. As a consequence, AI-specific reporting guidelines for clinical investigations have been published [80], [81]. In general, clinical reporting guidelines are also a valuable reference for evaluating the quality of the results of literature searches during the clinical evaluation. ThrombUS+ device shall be placed as new medical device on the market and, thus, the clinical investigation will be conducted for conformity assessment (Art. 62 MDR). Other clinical investigations (e.g., Investigator Initiated Trials (IITs), that are subject to the law of the Member States could be carried out as well (Art. 82 MDR). 4.4.6. Instructions for use and labelling Art. 10 (11) MDR obliges manufacturers to provide comprehensive and defined information for the medical device. Such information may appear on the device itself, on labels, on the packaging or in the instructions for use (IFU). Chapter III of Annex I of the MDR contains a list of information that must be included in the IFU or as part of the product labelling. Additional requirements for the information supplied by the manufacturer may result from standards, e.g., EN 60601-1-8 lists required content for the IFU regarding alarm systems in medical electrical equipment and medical electrical systems and IEC 82304-1 contains provisions regarding health software [15], [58]. Moreover, the need to include warnings, precautions etc. in the information supplied by the manufacturer may be derived from risk management (cf. 4.4.3). The IFU shall be written in a way easily understandable by the intended user of the device. Where appropriate, the text shall be supplemented by diagrams or drawings. The IFU shall contain: − device information such as name or trade name of the device, − manufacturer information such as name and address, − use instructions (e.g., indications and contra-indications or target population group), − information regarding product characteristics and depending on that information in accordance with Annex I 23.4., − information on device specification relevant for the appropriate use of the device (e.g., measuring accuracies), − information on accessories or other equipment the devise is intended to be used with, D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 32 − handling instructions (e.g., information for use or sterilization, final assembly, calibration), and − warnings, precautions, contra-indications, measures to be taken and limitations of use regarding the device. In principle, the IFU should be provided with each product. According to Art. 3 of implementing regulation (EU) 2021/2226 the provision of an electronically IFU (eIFU) is possible for the following devices [82]: a) implantable and active implantable medical devices and their accessories, b) fixed installed medical devices and their accessories, c) medical devices and their accessories fitted with a built-in system visually displaying the IFU, d) software covered by MDR, whereby points (a), (b) and (c) only apply if they are intended for use by professional users only and a use by other persons is not reasonably foreseeable. Point (d) applies to both professional users and laypersons. Under certain circumstances the IFU can also be provided to the user electronically, unless the electronic information reduces the level of safety compared to a paper format (Art. 5 of implementing regulation (EU) 2021/2226). However, the eIFU must be accessible on manufacturer’s website. Moreover, the manufacturer must assess the eIFU in his risk management (Art. 4 of implementing regulation (EU) 2021/2226). The electronic provision of the IFU shall be indicated on the label of the device and upon request users should be able to obtain the IFU in paper form free of charge (Art. 6 of implementing regulation (EU) 2021/2226). Labelling refers to written, printed or graphical information that is applied either to the product itself or, in case this is not practicable or appropriate to the packaging of each unit or to the packaging of several products. According to No. 23. Annex I MDR, the labelling must contain: − device information such as name or trade name of the device, − manufacturer information such as name and address, − information for identifying the product, e.g., UDI carrier and lot number or the serial number, − information for identifying product characteristics, e.g., single use, sterile or information on incorporated substances, − important warnings or precautions that require immediate attention, − information on product usage, e.g., special storage and/or handling condition or the shelf life, and − indication that the device is a medical device. Both IFU and labelling must be provided in the official languages of the EU Member States in which a medical device is to be sold. The EU issued an overview for language requirements including language requirements for labelling and instruction for use [83]. The language requirements for the IFU differ based on the intended user group (lay user/ patient or professional user). In Germany, for example, the IFU must be in German for lay users/ patient as target user group, however German and English are possible for professional users as target user group [83]. Internationally recognized symbols may be used by the manufacturer where appropriate to convey information to the user (No. 23.1. (h) Annex I MDR), for which EN ISO 15223 can be used [84], [85]. Additionally, ISO 20417 outlines requirements for the information to be provided by manufacturers of medical devices [86]. It includes the generally applicable requirements for identification and labels on a medical device or accessory, the packaging and accompanying information. Because of its technical complexity ThrombUS+ device will require detailed Instructions For Use and, in addition, training material specially tailored to the user. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 33 4.4.7. Technical documentation The technical documentation (TD) is a compilation of all relevant product documents for the conformity assessment and must be prepared by the medical device manufacturer (Art. 10 (4) MDR). The technical documentation represents the entirety of the documents describing a device, including information on device design, function, safety and production [87]. The technical documentation forms the basis for the conformity assessment and thus for the CE marking of a product. It is not to be confused with a "technical description", which is aimed at a technician who is to install a system, for example. The TD must be kept up to date throughout the entire product life cycle. After placing the device on the market data gathered through the post-market activities serves as input for the continuous update of the TD [87]. The MDR specifies the structure of the technical documentation in Annexes II and III. According to Annex II and III the technical documentation contains the following information: − device description and specifications, − comprehensive Information (labelling, IFU, etc.), − design and manufacturing information, − demonstration of conformity with the general safety and performance requirements, − information regarding the risk management and the benefit-risk analysis, − information on product verification and validation, including the clinical evaluation, and − information regarding the post-market phase, including post-market surveillance (PMS) and postmarket clinical follow-up (PMCF). The TD shall be presented by the manufacturer in a clear, organized, readily searchable and unambiguous manner (Annex II MDR). Although the structure set out in Annexes II and III is not mandatory, the required information should be provided in a coherent and clear structure [88]. For the assessment of the TD by a NB (c.f. 5.1) or a CA the generation of a TD summary is recommended. It can therefore be useful to precede the TD with a summary that provides an overview and puts further evidence documents into context. Some information may be required repeatedly across several evidence documents, e.g., product name or intended purpose. The uniformity of this information must be ensured, also during TD updates. The TEAM NB has published a document that describes further details on the content and submission of the technical documentation [88]. The ThrombUS+ device consists of various hardware components (e.g., wearable, acidity sensors, ultrasound sensor) and incorporates software including AI. All components together make up the finished product for which one TD must be prepared. In the case of ThrombUS+ device, the required information may need to be presented on a component level as well as in the context of the device. For example, the functionality and purpose of each component should be described and how they contribute to the overall purpose and functionality of the device. In the TD it must be clearly indicated which information or documents relate to individual components or the entire device. The interplay of ThrombUS+ technical documentation, standards, and guidelines is shown in Annex 3. 4.4.8. Registration of product and manufacturer The medical device manufacturer must fulfil several registration obligations (Art. 10 (7) MDR; Chapter III MDR) before he is allowed to place the device on the market: D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 34 − registration of the manufacturer, importer (if applicable) and authorized representative (if applicable) in the European Database on Medical Devices (EUDAMED), and − registration of the product in the UDI database (module of EUDAMED). EUDAMED is a centralized database established by the European Union (EU) to enhance the oversight and regulation of medical devices within the EU market. It serves as a comprehensive platform for the registration, tracking, and monitoring of medical devices throughout their lifecycle. EUDAMED facilitates the exchange of crucial information among EU member states, regulatory authorities, manufacturers, and other stakeholders. Its primary objectives include ensuring the safety, quality, and effectiveness of medical devices, as well as improving transparency and accessibility of information to support regulatory decision-making processes. By registering in EUDAMED, the manufacturer receives a “Single Registration Number” (SRN) [89]. The SRN is required to apply to a NB for a conformity assessment and to gain access to EUDAMED. This is required to comply with notification and reporting obligations. The “EUDAMED user guide: Economic perators – Actor module” describes the manufacturers registration process [90]. The Unique Device Identification (UDI) database is part of EUDAMED. UDI serves for the identification and traceability of individual products on the market. The UDI system and corresponding requirements are described in Annex VI part C, MDR. The Basic UDI Device Identifier (UDI-DI) is the central registration number for a group of devices with the same intended purpose, the same risk class and comparable design and manufacturing features [91]. It can be understood as the identifier of a product model or product family. The Basic UDI-DI base does not appear on the label or packaging of a product. It is used, for example, in the manufacturer's declaration of conformity, certificates and the technical documentation. The manufacturer registers the device with the Basic UDI-DI together with other required data elements in the UDI database [92]. Within a basic UDI-DI each product has its own unique UDI-DI. It is the main identifier of a medical device and is used on its label [92]. A UDI-DI can only be linked to one basic UDI-DI. A unit of device production is identified by the Product Identifier (UDI-PI). The UDI-PI is not registered in EUDAMED, however, the UDIPI type (e.g., expiry date or manufacturing date, lot number, serial number) needs to be provided for device registration in EUDAMED [92]. The UDI-PI type shows how production is controlled [91]. The UDI-PI is used when reporting vigilance incidents such as serious incidents and field safety corrective actions [92]. Figure 8. Unique Device Identification (UDI) hierarchy. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 35 The MDR specifies the UDI system in Art. 27 (4) and Part C of Annex VI MDR. The MDCG released various guidance documents regarding the UDI system and the integration of the UDI within the manufacturers QMS such as [92], [93] and [94]. For procedure packs and systems as well as Unique Device Identifier (UDI) obligations apply [95], [96]. Additionally, there are existing a UDI help desk on the European Commission’s Webpage and the “UDI Devices - User guide” [91] assisting in the registration of basic UDI-DIs in EUDAMED. By the Commission Implementing Decision (EU) 2019/939 [97] four issuing entities were designated to provide manufacturers with a list of UDIs for assigning to medical devices. The manufacturer must apply for the allocation of UDIs to one of these four issuing entities. In the case of ThrombUS+ device, a legal manufacturer is required who can register itself and the product (if necessary). It must be determined to what extent different variants or packaging units should exist to clarify the assignment of UDI-DIs. 4.4.9. Financial protection in the event of liability Art. 10 (16) MDR obliges the medical device manufacturer to take precautions to ensure sufficient financial cover potential liability. These precautions must be appropriate to the risk class, the type of product and the size of the company. The amount of financial cover depends individually on the type and risks of the medical device in question and the size of the company. The exact structure is subject to a case-by-case assessment and should include risk analysis. Depending on where a medical device is to be marketed, country-specific circumstances may also play a role. 4.4.10. Post-market surveillance and post-market clinical follow-up The medical device manufacturer is obliged to monitor his medical device after it has been placed on the European market (Art. 10 (10) MDR). For this, the manufacturer must establish a post-market surveillance (PMS) process as part of his quality management system. This must be appropriate to the risk class and type of product and ensure that data on the quality, performance and safety of a product is actively collected and analysed throughout the entire product life cycle. Based on the information gathered through post-market surveillance, the manufacturer must keep the technical documentation, and particularly the risk management up to date and determined the need for measures, e.g., corrective actions (Art. 2 (67) MDR) and field safety corrective actions (FSCA) (Art. 2 (68) MDR). According to Art. 83 MDR, the PMS process is based on a PMS plan. The PMS plan outlines the manufacturers strategy for actively gathering and analysing data from the use of the medical device on the market. Annex III MDR describes in more detail which information is to be utilized and which aspects regarding the implementations of PMS shall be defined in the PMS plan. As with the PMS process in general, the PMS plan must be appropriate to the risk class and type of product. For AI-based products, additional effort is required to monitor the AI model and the live data. The results of the data collection and evaluation laid down in the PMS plan are to be documented in a PMS report (Art. 85 MDR) or periodic safety update report (PSUR) (Art. 86 MDR). These report formats differ in terms of their specified content and schedule and depend on the risk class of the medical device. The PMS report essentially contains the PMS results and any preventive and corrective measures taken. In addition, the PSUR contains information on total sales volume and number of applications of the product as well as a benefit-risk assessment. For risk class I devices a PMS report and for devices of risk class IIa, IIb and III a PSUR is created. The MDCG published a guidance document regarding PSUR, which can also be consulted for the PMS report as long as there is no dedicated compliance document for the PMS report [98]. The collection of data for PMS is not limited to the manufacturer's own products, but also includes similar devices. Publicly available information on similar devices contributes to insights on the state of the art and D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 42 − evaluation of further representative samples of the technical documentation. The NB continues the assessment of the technical documentation in line with the sampling plan (Annex VII, 4.5.2. a) MDR), if applicable. The sampling plan shall ensure that all devices covered by the certificate are sampled over the period of validity of the certificate. During the surveillance assessment the manufacturer provides the NB any findings and results obtained from the application of the PMS plan and the PMCF plan as well as any findings from the vigilance requirements according to Art. 87 to 92 MDR (Annex I 3.2. MDR). The NB checks this information to determine whether the manufacturer complies with the obligations properly. 5.3. Notification obligations of the manufacturer regarding the Notified Body In addition to the reporting obligations to the CA, the manufacturer also has reporting obligations to the NB that issued certificates for the manufacturers’ devices. The manufacturer must report vigilance data continuously to the NB (Chapter VII section 2 and Annex VII 4.10. MDR). The NB reviews the available vigilance data to examine their influence - if any - on the validity of existing certificates. For this, the manufacturer reports vigilance data according to Art. 87 MDR to the corresponding NB at the same time as they are reported to the CA. Depending on the case reported, the NB decides on the measures to be taken including (Annex VII 4.10. MDR): − take no action on the basis that the vigilance case is clearly not related to the certification granted, − observe the manufacturer's and CA's activities and the results of the manufacturer's investigation to determine whether the certification granted is at risk or whether adequate corrective action has been taken, − perform extraordinary surveillance measures, such as document reviews, short-notice or unannounced audits and product testing, where it is likely that the certification granted is at risk, − increase the frequency of surveillance audits, − review specific products or processes when the next audit of the manufacturer is performed, or − take any other relevant measure. If the post-market surveillance reveals that preventive or corrective actions or both are necessary, the manufacturer shall take appropriate measures and inform the CAs and, where applicable, the NB (Art. 83 (4) MDR). However, the MDR and associated guidelines lack more detailed guidance on this topic, such as precise reporting criteria and information on the form of reporting. Additionally, the PSURs compiled shall be made available to the NB (Art. 86 2-3 MDR). While for class III and implantable devices, the PSURs are to be made available to the NB on a mandatory basis, the PSURs for class IIa and IIb non-implantable devices are only to be made available to the NB upon request. The results of the evaluation of the PSUR by the NB is provided to the manufacturer in form of a PSUR evaluation report for class III and implantable devices, and for class IIa and IIb non-implantable devices as part of the clinical evaluation assessment report (CEAR) (see guidance MDCG 2020-13 for CEAR template) [65]. Furthermore, manufacturers are obliged to inform the NB regarding planned changes that affect the valid certificates issued by the NB. In each case, the NB assesses whether and what type of measures (e.g. additional audits) are required. For conformity assessments based on an assessment of a QMS and technical documentation (Annex IX MDR) planned substantial changes to the QMS, or the product range covered by it (Annex IX 2.4. MDR) and changes to the device that affect the safety and performance of the device, or the conditions prescribed for use of the device (Annex IX 4.10. MDR) shall be reported in advance to the corresponding NB. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 43 In cases of an issued EU type examination certificate (Annex X MDR) the manufacturer shall inform the corresponding NB of any planned change to the approved type that may affect conformity with the general safety and performance requirements, or changes of the devices’ intended purpose and conditions of use (Annex X 5. MDR). For conformity assessments utilizing Annex XI part A the manufacturer shall inform the NB about planned substantial changes to the QMS, or the product range covered by it (Annex XI 6.4. MDR). 6. Further applicable European legislations Besides the medical device legislation, further European legislation is applicable for medical devices. This chapter discussed further existing European legislations to be considered for medical devices. 6.1. General Data Protection Regulation (GDPR) If personal data are processed during the development and use of a medical device, the European general data protection regulation (GDPR) applies [105]. Many provisions in the GDPR are challenging for medical devices and, in particular, for AI applications. Personal data are defined as “any information relating to an identified or identifiable natural person” (Art. 4 (1) GDPR). It is important to notice that pseudonymized data are still regarded as personal data (Recital 26 GDPR). Health data belong to the category of special personal data (or sensitive data), the processing of which is only permitted under strict conditions (Art. 9 GDPR). Having sensitive data re-identified may result in serious consequences for the person concerned. Moreover, the interference of sensitive data with other personal data “may expose the concerned individuals to discrimination or manipulation” [106]. For example, the purchase of mobile health apps from platforms as Apple App Store or Google Playstore may link personal data as date of birth to a certain disease. Manufacturers and users of medical devices must apply the data processing principles set out in Art. 5 (1 -e) GDPR: − fairness and transparency, − purpose limitation, − data minimization, − accuracy, and − storage limitation. The data subject's consent to personal data processing of his or her personal data must be specific and voluntary (Art. 6 (1) GDPR). The manufacturer must implement technical and organizational measures for data protection as early as the development phase (Art. 25 GDPR). This may include data encryption or default settings preserving the privacy of users. As Art. 22 (1) GDPR essentially prohibits automated decision-making, including profiling, manufacturers of autonomous AI systems must take the measures required by law. This also includes the application of AIbased medical devices with automated processing of health data [106]. According to Art. 35 (1) GDPR a data protection impact assessment is required for technologies which pose a high risk to the rights and freedoms of natural persons. For example, this is the case, if “AI-based profiling contributes to automated decision-making affecting individuals, since such profiling is likely to be systematic and extensive” [106]. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 44 Sensitive personal data will be part of the training sets for the development of ThrombUS+ AI models and during the clinical use of the ThrombUS+ device. Only in the second case will the collection and processing of data have a significant impact on individual patients. 6.2. Data Act (DA) and Data Governance Act (DGA) Both regulations (EU) 2022/868 (Data Act, DA) [107] and 2023/2854 (Data Governance Act, DGA) [107] are results of the European data strategy [108]. The DA regulates the sharing of data originating from connected devices between different stakeholders, i.e., businesses, consumers and governments and will become applicable in September 2025. According to DA recital 14, connected medical devices fall within the scope of this regulation. It contains the following main chapters [109]: − Chapter I on general provisions − Chapter II on business-to-business and business-to-consumer data sharing in the context of IoT − Chapter III on business-to-business data sharing − Chapter IV on unfair contractual terms − Chapter V on business-to-government data sharing − Chapter VI on switching between data processing services − Chapter VII on unlawful third country government access to data − Chapter VIII on interoperability − Chapter IX on enforcement The GDPR continues to take precedence regarding data protection issues. As well as EU intellectual property and competition law are not affected by the DA. The DGA became applicable in September 2023 setting out rules on the re-use of certain categories of data by European public sector bodies [110]. 6.3. Cybersecurity Directive (NIS 2) With the revision of the NIS Directive (NIS 2), regulating network and information security, the healthcare sector was also identified as a critical infrastructure [111]. The directive must be implemented by the member states by October 2024. As part of the healthcare industry, medical device manufacturers must proactively implement the requirements of the directive. The NIS 2 directive addresses cybersecurity in the manufacturing companies and does not define any obligations in relation to the medical device or the invitro diagnostic medical device itself. This includes dealing with potential cyberattacks, introducing security concepts, training employees, and complying with reporting obligations and deadlines in the event of security incidents. 6.4. Radio Equipment Directive (RED) The radio equipment directive 2014/53/EU sets out the regulatory framework for placing on the market and putting into service radio equipment. Radio equipment is any product that “intentionally emits and/or receives radio waves for the purpose of radio communication and/or radio determination” (Art. 2.1 (1) RED). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 45 When radio equipment is incorporated in a fixed and permanent manner in a non-radio product, that product is considered a single radio device [112]. For medical devices incorporating radio equipment like Wi-Fi, Zigbee, Bluetooth, RFID, or mobile radio (e.g., 5G) technology, therefore RED and MDR apply simultaneously. When RED is applicable simultaneously with any other EU legislation covering the same hazard (safety or EMC), the issue of overlap might be resolved by giving preference to the more specific EU legislation [112]. The essential requirements for radio equipment are described in Art. 3 RED including: − protection of health and safety (Art. 3.1 a), − electromagnetic compatibility (EMC) (Art. 3.1 b), − effective and efficient use of the radio spectrum (Art. 3.2), and − additional requirements for certain classes and categories of radio equipment (Art. 3.3). To demonstrate compliance with the essential requirements either harmonized standards or other available standards may be applied. For example, ETSI EN 300 328 is one of the most widely used standards for testing products with radio technology, regulating the requirements for broadband transmission systems that are operated in the 2.4 GHz band [113]. Guidance on the application of harmonized standards covering Art. 3.1 b and Art. 3.2 RED for combined radio and non-radio equipment is provided in ETSI EG 203 367 [114]. For the assessment of the fulfilment of the essential requirements covered by Art. 3.1 a and 3.1 b RED, the manufacturer may choose to involve an NB on a voluntary basis. On the other hand, to demonstrate compliance with the essential requirements covered by Art. 3.2 and Art. 3.2 RED, the manufacturer must follow a conformity assessment procedure involving an NB if the manufacturer has not applied, or has not fully applied, all relevant parts of the harmonized standards to demonstrate compliance. 6.5. Battery Regulation (BR) In December 2020, the EU Commission proposed the new Regulation (EU) 2023/1542 (Battery Regulation, BR) to replace the existing Battery Directive [115]. It came into force in August 2023 and applies in the member states since February 2024. The BR regulates the battery market much more comprehensively and contains provisions on due diligence obligations in the supply chain, restrictions on hazardous substances, product design requirements such as the interchangeability of batteries, the carbon footprint, recyclate use quotas and the battery passport, as well as the collection and treatment of waste batteries. A medical device manufacturer is concerned by the BR if he produces batteries or has them produced and supplies them for the first time under its own name or trademark (Art. 3 (47) BR). Obligations for economic operators, including manufacturers (named “producers” in BR) and suppliers, are laid down in Art. 38-42 BR. Manufacturers must carry out the design and production of the batteries according to the following provisions (Art. 38 (BR): − compliance with new substance restrictions (Art. 6 BR), − issuing a declaration on the CO2 footprint (Art. 7 BR), − providing information on the recycled content of the active materials (Art. 8 BR), − ensuring adherence to certain electrochemical parameters in accordance with Annex IV Part A (Art. 9-10 BR), − ensuring safety of stationary battery energy storage systems (Art. 12 BR), and − meet requirements for battery parameters to determine the state of health and service life (Art. 14 BR). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 46 Suppliers must provide “the information and documentation necessary to comply with the requirements” (Art. 39 BR). Moreover, extended producer responsibilities are applicable for “batteries that they make available on the market for the first time within the territory of a Member State” (Art. 56 BR). Standardization organizations are working intensively on the development of new standards for conformity with the requirements of the BR [116]. The BR contains separate entry into force or transitional provisions for some provisions. 6.6. Artificial Intelligence Act (AIA) To create a uniform horizontal legal framework for the development, placing on the market, and use of artificial intelligence, the Regulation (EU) 2024/1689, the so-called Artificial Intelligence Act (AIA), entered into force on 1 August 2024 [117]. The AIA will apply from 2 August 2026 (Art. 113 MDR). Some parts of the AIA will apply earlier: − Chapters I (General provisions) and II (Prohibited practices) from 2 February 2025, − Chapter III (High-risk systems) Section 4 (Notifying authorities and notified bodies), Chapter V (General Purpose AI Models), Chapter VII (Governance) and Chapter XII (Penalties) and Art. 78 (Confidentiality) from 2 August 2025, with the exception of Art. 101 (Fines for providers of generalpurpose AI models), and − Art. 6(1) (Classification rules for high-risk AI systems) and the corresponding obligations from 2 August 2027. The following section discusses the requirements of the AIA that are or can be applied to medical devices. According to AIA an AI system is defined as “a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments” (Art. 3 (1) AIA). The risk-based approach of the AIA differentiates between four categories [118]: − prohibited artificial intelligence practices (Art. 5 AIA), − high-risk AI systems (Art. 6 AIA, e.g., medical devices of MDR risk classes IIa, IIb, and III, or in-vitro medical devices of IVDR risk classes B, C, and D), − limited risk AI systems (Recital 53, e.g., chatbots), and − minimal or no risk AI systems (e.g., AI-enabled video games or spam filters) The AIA uses in contrast to the MDR for some stakeholder different names: − providers (Art. 3 (3) AIA, comparable with manufacturer in MDR) − deployers (Art. 3 (4) AIA, comparable with users in MDR) It is noteworthy to emphasize that the AIA does not only lay down provisions for providers, NBs, and national CAs but also for deployers. In accordance with Art. 6 (1) AIA, AI-based medical devices and in vitro diagnostic devices are classified as high-risk AI systems. The following explanations focus on medical devices with integrated AI technology or independent medical device software. However, Art. 8 (2) AIA states that the provider of a high-risk AI system being also a medical device is responsible for full compliance with the MDR. By practical means providers shall have the choice to integrate the AIA provisions in their respective MDR processes and documentation. High-risk AI systems must meet the requirements of Art. 8 to 15 AIA from Section 2 “Requirements for highrisk AI systems” in Chapter III. These include, for example, obligations regarding risk management system (Art. 9), technical documentation (Art. 11 AIA), as well as accuracy, robustness, and cybersecurity (Art. 15). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 47 Data governance requirements shall ensure that training, validation, and test datasets are “relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose” (Art. 10 AIA). Providers must implement an automatic recording (“logging”) function in their AI system to ensure traceability of system functions (processes and events) and post-market surveillance (Art. 12 AIA). Transparency of AI systems is an important aim of the European legislator: “To address concerns related to opacity and complexity of certain AI systems and help deployers to fulfil their obligations under this Regulation, transparency should be required for high-risk AI systems before they are placed on the market or put it into service. High-risk AI systems should be designed in a manner to enable deployers to understand how the AI system works, evaluate its functionality, and comprehend its strengths and limitations” (Recital 72). Therefore, Art. 13 AIA provides detailed explanations of how transparency is to be implemented by the provider, particularly regarding the IFU. Further requirements are laid down in Art. 16 to 29 AIA of Section 3, “ bligations of providers and deployers of high-risk AI systems and other parties” in Chapter III, e.g., regarding quality management system (Art. 17 AIA), and post-market surveillance/vigilance (Art. 21)). The safety of medical devices is a joint responsibility of providers and deployers. The AIA recognizes this through separate requirements for deployers in Art. 26 AIA and mandatory human oversight in Art. 14 AIA. High-risk AI systems must undergo a conformity assessment procedure (Art. 43 AIA). In the case of medical devices Art. 43 (3) AIA shall follow the relevant MDR conformity assessment and in addition be the compliant with requirements in Section 2 of Chapter III as well as No. 4.3., 4.4., 4.5. and the fifth paragraph of No. 4.6. of Annex VII AIA. In Q4 of 2024 the MDCG plans to launch an FAQ on the interplay between MDR/IVDR and AIA [9]. The AIA introduces in Chapter V “General Purpose AI Models” general obligations for providers of General Purpose AI (GPAI) 7 models, i.e. to produce a technical documentation, to provide information to other manufacturers who wish to integrate a GPAI model into their own AI system, to produce a copyright policy based on the relevant legislation and to publish a summary of the training data used. In addition, for GPAI models with systemic risks 8 , evaluations incl. adversarial testing, cybersecurity measures, self-assessment and mitigation of systemic risks and serious incident reporting are mandatory. The national CAs are comprehensively authorized to carry out their market surveillance activities. They are granted unrestricted access to the training, validation and test data sets used to the code and to further documentation (Art. 74 (12-13) AIA). The setting up of regulatory sandboxes is intended enabling manufacturers to develop, train, test and validate AI systems for a certain period before they are placed on the market (Art. 57 AIA). This is intended to promote innovation and competitiveness and facilitate market access for start-ups and small and mediumsized enterprises (SMEs). In addition, under certain conditions, providers will be able to test their systems under real conditions outside the sandboxes. These conditions include obtaining authorization from the competent national authority based on a test plan submitted in advance by the manufacturer. Future guidance from the EC is expected to define the conditions under which real-world test facilities will be implemented in each member state. With the AIA the new institution AI ffice is installed that shall contribute “to the implementation, monitoring and supervision of AI systems and AI governance […]” (Art. 3 (47) AIA). The mission and tasks of the AI ffice are laid down in the Commission decision of 24.01.2024 [119]: 7 “General-purpose AI system means an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems” (Art. 3 (66) AIA). 8 “A general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 1025” (Art. 51 (2) AIA). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 48 − Supporting the AI Act and enforcing general-purpose AI rules − Strengthening the development and use of trustworthy AI − Fostering international cooperation − Cooperation with institutions, experts, and stakeholders The recently published “Standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation in support of Union policy on artificial intelligence” will ensure the production of standards playing an important role in the proof of conformity with the AIA requirements [120]. The AIA applies for high-risk AI systems that were placed on the market or put into operation before the date of application of the AIA only if the design of these systems was significantly changed after the date of application (Art. 111 (2) AIA). Overall, the AI Act represents a major challenge for the industry. However, to support AI startups and SMEs the Commission has launched a package of measures [121]. The ThrombUS+ device utilizes artificial intelligence and, thus, the AIA requirements must be considered as well. The proof of conformity will be achieved through the respective technical documentation. 7. Upcoming European legislation The existing EU legislation is continuing to develop. Therefore, the respective consolidated versions of the legal texts should be considered. In addition, European legislation is changing to ensure patient safety and take account of evolving technologies. Therefore, a continuous monitoring of the European legislation landscape is necessary for medical device manufacturer. The following describes legislative proposals that would be applicable to the ThrombUS+ device as well. 7.1. European Health Data Space (EHDS) Act On 3 May 2022, the EU Commission proposed a regulation on the European Health Data Space (EHDS), which is intended to ensure an efficient linkage of the health systems of the member states through a secure and efficient exchange of health data [122]. It also emerges from the European strategy for data. The EHDS builds on GDPR, DA, DGA, and NIS2 and complements these legislations where additional rules for the health sector are needed [123]. Manufacturers of medical devices and high-risk AI systems (according to the AIA) for which interoperability with Electronic Health Record (EHR) systems is claimed in the intended purpose must demonstrate the essential requirements according to Annex II. The EHDS regulation is expected to be published in the Official Journal in autumn. It will then become applicable in different stages according to use case and data type. 7.2. Directive on liability for defective products The proposal for a new EU product liability directive aims to establish strict liability for defective products. [124]. This now also includes software. Among other things, medical devices are the focus of this proposed legislation. Recital 22 states: “Some products, such as life-sustaining medical devices, entail an especially high risk of damage to people and therefore give rise to particularly high safety expectations. In order to take such expectations into account, it should be possible for a court to find a product defective without establishing D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 49 its actual defectiveness, where it belongs to the same production series as a product already proven to be defective”. 7.3. Regulation on packaging and packaging waste On 30 November 2022, the EU Commission published a proposal for a packaging regulation that sets the target that all packaging used in the European Union (EU) must be recyclable in the future [125]. Packaging for medical devices and in-vitro diagnostics would also be affected by this regulation in future. However, a transitional period of 5 years would apply to these products. 8. Ethical Consideration 8.1. Ethics in clinical investigations with medical devices The Declaration of Helsinki of the World Medical Association requires the involvement of an ethics committee in the assessment of a research project involving humans [126]. The aim is to assess human research projects from an ethical, legal and social perspective and to ensure the protection of individuals from the consequences of these research projects. In Art. 62 (3) MDR an ethical review by an ethics committee for clinical investigations with medical devices is requested. An ethics committee usually consists of physicians, possibly also scientists, theologians, lawyers and academics specialized in the humanities. The setup of ethics committees is defined by national laws of the member states. In Germany, the procedure of the ethics committee is laid down in the Medical Device Law Implementation Act (MPDG). Only in case of a positive opinion of the ethics committee the clinical investigation may be carried out (Art. 62 (4b) MDR). 8.2. Ethics in artificial intelligence In 2019 the High-Level Expert Group on Artificial Intelligence (AI HLEG) set up by the European Commission published the document “Ethics Guidelines for Trustworthy AI” [127]. Accordingly, trustworthy AI is based on three basic principles throughout its lifecycle: 1. it should be lawful, i.e. comply with all applicable laws and regulations, 2. it should be ethical, i.e. ensure compliance with ethical principles and values, and 3. it should be both technically and socially robust, as AI systems can cause unintended harm even with good intentions. Regarding ethics in artificial intelligence, it is recommended to adhere to the ethical principles of respect for human autonomy, prevention of harm as well as fairness and explicability. Particular attention shall be given to situations “involving more vulnerable groups” or “characterized by asymmetries of power or information”. Finally, “adequate measures to mitigate these risks when appropriate, and proportionately to the magnitude of the risk” shall be adopted. Based on this a checklist was developed guiding developers and deployers of AI in implementing such principles in practice [128]. The European Commission continued to develop an ethically focused approach to designing, developing and deploying and/or using AI systems [129]. The guideline defines the ethical principles that AI systems should follow and derives requirements for their development, explains the concept of "ethics by design" and describes common practices for the use of AI systems in research projects. In the ethics by design approach ethical requirements are addressed during each step of a generic AI development model: 1. Specification of objectives D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 50 2. High-level design 3. Data collection and preparation 4. Detailed design and development 5. Testing and evaluation In 2021 the WH published the general guideline “Ethics and governance of artificial intelligence for health”, which highlighted both the potential benefits and risks of using AI in healthcare and set out six principles that governments, developers and providers using AI should consider in their policies and practices [130]. The principles are: 1. protect autonomy, 2. promote human well-being, human safety, and the public interest, 3. ensure transparency, explainability, and intelligibility, 4. foster responsibility and accountability, 5. ensure inclusiveness and equity as well as 6. promote AI that is responsive and sustainable. Recently, a more specific guideline was developed by the WH addressing “one type of generative AI, large multi-modal models (LMMs), which can accept one or more type of data input and generate diverse outputs that are not limited to the type of data fed into the algorithm” [131]. The VDE specification 90012 introduces the so-called Values Criteria Indicators Observables (VCIO) model, which makes it possible to describe whether a product with AI technology conforms to certain values and can be trusted. This standard can therefore be used as the basis for applying a trust label to a product [132]. Another valuable resource is the OECD collection of tools and resources for the development of trustworthy AI systems [133]. However, in healthcare two major ethical principles, transparency and explainability, are often not addressed adequately as has recently been shown by Fehr et al. [134]. To counteract this, ethical principles for AI systems will be considered early in development of the ThrombUS+ device. For example, the respective technical documentation will contain details on the AI model development and to the user a transparency information will be offered. 9. Literature [1] E. Kaldoudi et al., “Towards Wearable Continuous Point-of-Care Monitoring for Deep Vein Thrombosis of the Lower Limb,” in 9th European Medical and Biological Engineering Conference, T. Jarm, R. Šmerc, and S. Mahnič-Kalamiza, Eds., Cham: Springer Nature Switzerland, 2024, pp. 326–335. doi: 10.1007/9783-031-61628-0_36. [2] European Parliament and Council, Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC. 2017. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2017/745 [3] European Parliament and Council, Regulation (EU) 2024/1860 of the European Parliament and of the Council of 13 June 2024 amending Regulations (EU) 2017/745 and (EU) 2017/746 as regards a gradual roll-out of Eudamed, the obligation to inform in case of interruption or discontinuation of supply, and transitional provisions for certain in vitro diagnostic medical devices. 2024. [Online]. Available: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401860 [4] Global Harmonization Task Force, “Role of Standards in the Assessment of Medical Devices.” May 03, 2008. [Online]. Available: http://www.imdrf.org/docs/ghtf/final/sg1/procedural-docs/ghtf-sg1-n0442008-standards-in-assessment-of-medical-devices-080305.pdf D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 51 [5] Medical Device Coordination Group, Ed., “MDCG 2021-5 Rev. 1 Guidance on standardisation for medical devices.” Jul. 2024. [ nline]. Available: https://health.ec.europa.eu/medical-devices-sector/newregulations/guidance-mdcg-endorsed-documents-and-other-guidance_en [6] European Commission, Ed., “Summary of references of harmonised European standards published in the fficial Journal of the European Union in support of Regulation (EU) 2017/745 on medical devices.” Mar. 08, 2024. [Online]. Available: https://single-market-economy.ec.europa.eu/single-market/europeanstandards/harmonised-standards/medical-devices_en [7] S. Nativi and S. De Nigris, “AI Watch - AI Standardisation Landscape: state of play and link to the EC proposal for an AI regulatory framework.” JRC, Jul. 13, 2021. [ nline]. Available: https://publications.jrc.ec.europa.eu/repository/handle/JRC125952 [8] J. Garrido Soler et al., “AI Watch: Artificial Intelligence Standardisation Landscape Update.” JRC, 2023. [9] “ ngoing/planned guidance development and deliverables of MDCG Subgroups.” MDCG, Mar. 2024. [10] WG SaMD, “Medical Device Software: Considerations for Device and Risk Characterization.” 2024. [11] A. Smirthwaite, “Clinical evaluation under EU MDR.” ct. 22, 2021. [12] Medical Device Coordination Group, Ed., “MDCG 2021-24 Guidance on classification of medical devices.” Oct. 2021. [Online]. Available: https://health.ec.europa.eu/medical-devices-sector/newregulations/guidance-mdcg-endorsed-documents-and-other-guidance_en [13] Medical Device Coordination Group, Ed., “MDCG 2019-11 Guidance on Qualification and Classification of Software in Regulation (EU) 2017/745 – MDR and Regulation (EU) 2017/746 – IVDR.” 2019. [ nline]. Available: https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcgendorsed-documents-and-other-guidance_en [14] European Commission, Ed., “The ‘Blue Guide’ on the implementation of EU products rules 2022.” Jun. 29, 2022. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A52022XC0629%2804%29&qid=1656498610278 [15] “IEC 60601-1-8 Medical electrical equipment - Part 1-8: General requirements for basic safety and essential performance - Collateral Standard: General requirements, tests and guidance for alarm systems in medical electrical equipment and medical electrical systems.” IEC, 2007. [ nline]. Available: https://www.iso.org/obp/ui#iso:std:iec:60601:-1-8:ed-2:v1:en [16] “IEC 60601-1 Medical electrical equipment - Part 1: General requirements for basic safety and essential performance.” IEC, 2006. [17] IECEE, “Test Report Form (TRF) IEC60601_1U,” Test report forms. Accessed: May 23, 2024. [ nline]. Available: https://www.iecee.org/certification/iec-test-report-forms/iec-60601-12005-iec-6060112005amd12012-iec-60601-12005amd22020 [18] “IEC 60601-1-2 Medical electrical equipment - Part 1-2: General requirements for basic safety and essential performance - Collateral standard: Electromagnetic compatibility - Requirements and tests.” IEC, 2020. [Online]. Available: https://webstore.iec.ch/publication/67554 [19] “IEC 60601-1-11 Medical electrical equipment - Part 1-11: General requirements for basic safety and essential performance - Collateral Standard: Requirements for medical electrical equipment and medical electrical systems used in the home healthcare environment.” IEC, 2021. [ nline]. Available: https://webstore.iec.ch/publication/59650 [20] European Commission, “SCHEER Guidelines on the benefit-risk assessment of the presence of CMR/ED phthalates in certain medical devices (preliminary version).” Jun. 14, 2024. [ nline]. Available: https://health.ec.europa.eu/system/files/2020-10/scheer_o_015_0.pdf D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 58 data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). 2016. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2016/679 [106] European Parliamentary Research Service, Ed., “The impact of the General Data Protection Regulation (GDPR) on artificial intelligence.” Jun. 2020. [107] European Parliament and Council, Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act), vol. 2023/2854. 2023. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2023/2854 [108] European Commission, Ed., “Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: A European strategy for data.” Feb. 19, 2020. [ nline]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:52020DC0066 [109] European Commission, “Data Act explained,” Shaping Europe’s digital future. Accessed: Jun. 04, 2024. [Online]. Available: https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained [110] European Parliament and Council, Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act). 2022. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:32022R0868 [111] European Parliament and Council, Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). 2022. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:02022L2555-20221227 [112] Telecommunication Conformity Assessment and Market Surveillance Committee, Ed., “Guide to the Radio Equipment Directive 2014/53/EU.” Dec. 19, 2018. [ nline]. Available: https://ec.europa.eu/docsroom/documents/33162 [113] ETSI, Ed., “ETSI EN 300 328 Wideband transmission systems; Data transmission equipment operating in the 2,4 GHz band; Harmonised Standard for access to radio spectrum (V2.2.2).” Jul. 2019. [ nline]. Available: https://www.etsi.org/deliver/etsi_en/300300_300399/300328/02.02.02_60/en_300328v020202p.pdf [114] ETSI, Ed., “ETSI EG 203 367 Guide to the application of harmonised standards covering articles 3.1b and 3.2 of the Directive 2014/53/EU (RED) to multi-radio and combined radio and non-radio equipment (V1.1.1).” Jun. 2016. [ nline]. Available: https://www.etsi.org/deliver/etsi_eg/203300_203399/203367/01.01.01_60/eg_203367v010101p.pdf [115] European Parliament and Council, Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries, amending Directive 2008/98/EC and Regulation (EU) 2019/1020 and repealing Directive 2006/66/EC, vol. 2023/1542. 2023. [Online]. Available: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1542 [116] L. Dorrmann et al., “VDE Infopapier zur Batterieverordnung (EU) 2023/1542 über Batterien und Altbatterien.” Feb. 13, 2024. [117] European Parliament and Council, Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act). 2024. [Online]. Available: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689 D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 59 [118] European Commission, “AI Act,” Shaping Europe’s digital future. Accessed: Apr. 11, 2024. [ nline]. Available: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai [119] European Commission, Commission Decision of 24 January 2024 establishing the European Artificial Intelligence Office. 2024. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=OJ:C_202401459 [120] European Commission, Commission Implementing decision of 22.5.2023 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation in support of Union policy on artificial intelligence. 2023. [Online]. Available: https://ec.europa.eu/transparency/documents-register/detail?ref=C(2023)3215&lang=en [121] European Commission, “Commission launches AI innovation package,” European Commission - European Commission. Accessed: Mar. 21, 2024. [Online]. Available: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_383 [122] European Commission, Proposal for a Regulation of the European Parliament and of the Council on the European Health Data Space. 2022. Accessed: Apr. 21, 2021. [Online]. Available: https://eurlex.europa.eu/legal-content/EN/TXT/?uri=celex:52022PC0197 [123] European Commission, Ed., “Questions and Answers on the European Health Data Space.” Apr. 24, 2024. [Online]. Available: https://ec.europa.eu/commission/presscorner/api/files/document/print/en/qanda_24_2251/QANDA_ 24_2251_EN.pdf [124] European Commission, Proposal for a Directive of the European Parliament and of the Council on liability for defective products. 2022. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:52022PC0495 [125] European Commission, Proposal for a Regulation of the European Parliament and of the Council on packaging and packaging waste, amending Regulation (EU) 2019/1020 and Directive (EU) 2019/904, and repealing Directive 94/62/EC. 2022. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:52022PC0677 [126] “Declaration of Helsinki - ethical principles for medical research involving human subjects.” World Medical Association, 2022. [Online]. Available: https://www.wma.net/policies-post/wma-declarationof-helsinki-ethical-principles-for-medical-research-involving-human-subjects/ [127] High-Level Expert Group on Artificial Intelligence, Ed., “Ethics Guidelines for Trustworthy AI.” Apr. 08, 2019. [Online]. Available: https://ec.europa.eu/digital-single-market/en/news/ethics-guidelinestrustworthy-ai [128] High-Level Expert Group on Artificial Intelligence, Ed., “Assessment List for Trustworthy Artificial Intelligence (ALTAI) for self-assessment.” 2020. [ nline]. Available: https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=68342 [129] European Commission, Ed., “Ethics By Design and Ethics of Use Approaches for Artificial Intelligence (Version 1 .0).” Nov. 25, 2021. [130] World Health rganization, Ed., “WH guidance: Ethics and governance of artificial intelligence for health.” 2021. [ nline]. Available: https://www.who.int/publications-detail-redirect/9789240029200 [131] World Health rganization, Ed., “Ethics and governance of artificial intelligence for health. Guidance on large multi-modal models.” 2024. [ nline]. Available: https://www.who.int/publications/i/item/9789240084759 [132] “VDE SPEC 90012 VCI based description of systems for AI trustworthiness characterisation (V. 1.0).” VDE, Apr. 25, 2022. [Online]. Available: D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 60 https://www.vde.com/resource/blob/2177870/a24b13db01773747e6b7bba4ce20ea60/vde-spec90012-v1-0--en--data.pdf [133] ECD, “Catalogue of Tools & Metrics for Trustworthy AI.” Accessed: Mar. 13, 2024. [ nline]. Available: https://oecd.ai/en/catalogue [134] J. Fehr, B. Citro, R. Malpani, C. Lippert, and V. I. Madai, “A trustworthy AI reality-check: the lack of transparency of artificial intelligence products in healthcare,” Front. Digit. Health, vol. 6, Feb. 2024, doi: 10.3389/fdgth.2024.1267290. 10. Other sources − European Commission > Public Health > Medical Devices – Sector > New Regulations: https://health.ec.europa.eu/medical-devices-sector/new-regulations_en#about-the-revision − European Commission > Public Health > Medical Devices – EUDAMED: https://health.ec.europa.eu/medical-devices-eudamed_en − FDA Artificial Intelligence and Machine Learning (AI/ML)-Enabled Medical Devices: https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-andmachine-learning-aiml-enabled-medical-devices − Health AI Register: https://healthairegister.com/ − ISO/IEC JTC 1/SC 42 Artificial intelligence: https://www.iso.org/committee/6794475.html − ISO Update International Standards in process: https://www.iso.org/iso-update.html − Medical AI Evaluation: https://ericwu09.github.io/medical-ai-evaluation/ − MedTech Europe: https://www.medtecheurope.org/new-medical-technology-regulations/ − The Alan Turing Institute: https://www.turing.ac.uk/news/publications − WHO Medical Devices Newsletter: https://www.who.int/teams/health-product-policy-andstandards/assistive-and-medical-technology/medical-devices/newsletter D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 61 Annex 1. Special MDR requirements for respective risk classes Requirement Reference Class I Class IIa Class IIb Class III Implants Respective text passage in MDR Implant card and information to be supplied to the patient with an implanted device Art. 18 --- --- --- --- X --- Special provisions regarding Unique Device Identification (UDI) system Art. 27 --- --- --- --- X Economic operators shall store and keep, preferably by electronic means, the UDI of the devices which they have supplied or with which they have been supplied, if those devices belong to: class III implantable devices [...] Health institutions shall store and keep preferably by electronic means the UDI of the devices which they have supplied or with which they have been supplied, if those devices belong to class III implantable devices. Summary of safety and clinical performance (SSCP) Art. 32 --- --- --- X X For implantable devices and for class III devices, other than custom-made or investigational devices, the manufacturer shall draw up a summary of safety and clinical performance. Conformity assessment procedures Art. 52 X X X X X --- Clinical evaluation consultation procedure for certain class III and class IIb devices Art. 54 --- --- X --- X […] Notified Body shall also follow the procedure regarding clinical evaluation consultation […] when performing a conformity assessment of the following devices: (a) class III implantable devices, and (b) class IIb active devices intended to administer and/or remove a medicinal product Mechanism for scrutiny of conformity assessments of certain class III and class IIb devices Art. 55 --- --- X --- X A Notified Body shall notify the Competent Authorities of certificates it has granted to devices for which the conformity assessment has been performed pursuant to Article 54(1). D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 62 Requirement Reference Class I Class IIa Class IIb Class III Implants Respective text passage in MDR Special provisions regarding clinical evaluation and investigation as well as postmarket clinical follow-up Art. 61 --- --- X X X For all class III devices and for the class IIb devices referred to in point (b) of Article 54(1), the manufacturer may, prior to its clinical evaluation and/or investigation, consult an expert panel as referred to in Article 106, with the aim of reviewing the manufacturer's intended clinical development strategy and proposals for clinical investigation. The manufacturer shall give due consideration to the views expressed by the expert panel. Such consideration shall be documented in the clinical evaluation report referred to in paragraph 12 of this Article. The manufacturer may not invoke any rights to the views expressed by the expert panel with regard to any future conformity assessment procedure. In the case of implantable devices and class III devices, clinical investigations shall be performed, except if: [...] à note restrictions! For class III devices and implantable devices, the PMCF evaluation report and, if indicated, the summary of safety and clinical performance referred to in Article 32 shall be updated at least annually with such data. Application for clinical investigations Art. 70 X X X --- --- The sponsor may start the clinical investigation in the following circumstances: In the case of investigational class I devices or in the case of non-invasive class IIa and class IIb devices, unless otherwise stated by national law, immediately after the validation date of the application pursuant to paragraph 5, and provided that a negative opinion which is valid for the entire Member State, under national law, has not been issued by an ethics committee in the Member State concerned in respect of the clinical investigation Coordinated assessment procedure for clinical investigations Art. 78 --- --- X X --- For class IIb and class III devices, the coordinating Member State may also extend the periods referred to in paragraph 4 (of Art. 78 MDR) by a further 50 days, for the purpose of consulting with experts. Post-market surveillance report Art. 85 X --- --- --- --- Manufacturers of class I devices shall prepare a post-market surveillance report [...]. D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 63 Requirement Reference Class I Class IIa Class IIb Class III Implants Respective text passage in MDR Periodic safety update report Art. 86 --- X X X X Manufacturers of class IIa, class IIb and class III devices shall prepare a periodic safety update report (‘PSUR’) for each device and where relevant for each category or group of devices [...]. Manufacturers of class IIb and class III devices shall update the PSUR at least annually. Manufacturers of class IIa devices shall update the PSUR when necessary and at least every two years. For class III devices or implantable devices, manufacturers shall submit PSURs by means of the electronic system referred to in Article 92 to the Notified Body involved in the conformity assessment in accordance with Article 52. Transitional provisions Art. 120 X X X X X Devices which have a certificate that was issued in accordance with Directive 90/385/EEC or Directive 93/42/EEC and that is valid by virtue of paragraph 2 of this Article may be placed on the market or put into service until the following dates: (a) 31 December 2027, for all class III devices, and for class IIb implantable devices except sutures, staples, dental fillings, dental braces, tooth crowns, screws, wedges, plates, wires, pins, clips and connectors; (b) 31 December 2028, for class IIb devices other than those covered by point (a) of this paragraph, for class IIa devices, and for class I devices placed on the market in sterile condition or having a measuring function. By way of derogation from Article 5, class III custom-made implantable devices may be placed on the market or put into service until 26 May 2026 […] Entry into force and date of application of MDR (transition periods) Art. 123 X X X X X Until EUDAMED is fully functional, the corresponding provisions of Directives 90/385/EEC and 93/42/EEC shall continue to apply for the purpose of meeting the obligations laid down in the provisions listed in the first paragraph of this point regarding exchange of information including, and in particular, information regarding vigilance reporting, clinical investigations, registration of devices and economic operators, and certificate notifications. […] for implantable devices and for class III devices Article 27(4) shall apply from 26 May 2021. For class IIa and class IIb devices Article 27(4) shall apply from 26 May 2023. For class I devices Article 27(4) shall apply from 26 May 2025; […] with regard to reusable devices that are required to bear the UDI carrier on the device itself, Article 27(4) shall apply to: D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 64 Requirement Reference Class I Class IIa Class IIb Class III Implants Respective text passage in MDR (i) implantable devices and class III devices from 26 May 2023; (ii) class IIa and class IIb devices from 26 May 2025; (iii) class I devices from 26 May 2027; General safety and performance requirements Annex I --- --- --- --- X Special requirements for active implantable devices Information to be submitted for the registration of devices and economic operators as well as to be entered in the UDI database Annex VI --- X X X X Information on the device for class IIa, class IIb or class III devices: Member States in which the device is available or intended to be made available for class III or implantable devices: Summary of safety and clinical performance. Implantable devices are labeled at their lowest packaging level ("individual packs") with a UDI (UDI-DI + UDI-PI) or marked with it using the AIDC format. The UDI-PI shall include at least the following characteristics: a) the serial number for active implantable devices, b) the serial number or lot number for other implantable devices. The UDI of implantable devices is identifiable prior to implantation Requirements to be fulfilled by the Notified Bodies Annex VII --- X X --- --- Verification by examination and testing of each device The Notified Body shall draw up a test plan specifying all the relevant and critical parameters to be checked by or under the responsibility of the Notified Body in order to: - for class IIb devices, to verify the conformity of the individual device with the type described in the EU-type examination certificate and with the relevant requirements of this Regulation that apply to those devices, - for class IIa devices, to confirm conformity with the technical documentation referred to in Annexes II and III and with the relevant requirements of this Regulation that apply to those devices, D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 65 Requirement Reference Class I Class IIa Class IIb Class III Implants Respective text passage in MDR Conformity assessment based on a quality management system and an assessment of the technical documentation Annex IX --- --- X X X For class III devices, the surveillance assessment shall also include an examination of the approved parts and/or materials that are essential for the integrity of the device, including, where appropriate, a verification that the quantities of parts and/or materials manufactured or procured correspond to the quantities of finished devices. Assessment of the technical documentation for class III and class IIb devices referred to in the second subparagraph of Article 52(4) Assessment procedure for certain class III and class IIb devices (a) For class III devices and for active class IIb devices referred to in Section 6.4 (Rule 12) of Annex VIII intended to deliver a medicinal product to and/or remove a medicinal product from the body, the Notified Body shall, after having verified the quality of the clinical data on which the clinical evaluation report of the manufacturer is based in accordance with Article 61(12), draw up a clinical evaluation assessment report Administrative provisions: The manufacturer or, where the manufacturer has no registered place of business in a Member State, his authorized representative shall, for a period ending no earlier than 10 years, and in the case of implantable devices no earlier than 15 years, after the last device has been placed on the market, keep at the disposal of the Competent Authorities [...] D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 66 Annex 2. Compliance with MDR requirement regarding the quality management system by application of the EN ISO 13485 Requirements in paragraph 3 of Art. 10 (9) Coverage by EN ISO 134859 Corresponding (sub-)chapter of EN ISO 13485 Gap between MDR and EN ISO 13485 (a) strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for management of modifications to the devices covered by the system Partially covered 4.1.1, 7.3.9 No documented strategy for regulatory compliance required in EN ISO 13485. (b) identification of applicable general safety and performance requirements and exploration of options to address those requirements Partially covered 4.2.3, 7.2.1c), 7.3.3b), 7.3.4a), 7.3.5 GSPRs, harmonized standards, or common specifications are not explicitly mentioned in EN ISO 13485. (c) responsibility of the management Fully covered 5 --- (d) resource management, including selection and control of suppliers and sub-contractors Fully covered 4.1.5, 6, 7.4.1 --- (e) risk management Partially covered 4.1.2, 7.1 Details on product-related risk management as laid down in Annex I MDR are not available in EN ISO 13485. (f) clinical evaluation including PMCF Not covered --- Details on clinical evaluation and PMCF as laid down in Chapter VI and Annex XVI MDR are not available in EN ISO 13485. (g) product realization, including planning, design, development, production and service provision Fully covered 7.1, 7.3.2, 7.3.8, 7.5.1, 7.5.4 --- (h) Unique Device Identifier (UDI) assignments Not covered --- Details on UDI as laid down in Art. 27 and Annex VI MDR are not available in EN ISO 13485. (i) setting-up, implementation and maintenance of a post-market surveillance system Partially covered 8.2.1, 8.5.1 Details on PMS system as laid down in Section 1 of Chapter VII are not available in EN ISO 13485. (j) handling communication with competent authorities, Notified Bodies, other economic operators, customers and/or other stakeholders Partially covered 7.2.3 Not all economic operators as well as Competent Authorities and Notified Bodies are mentioned in EN ISO 13485. (k) processes for reporting of serious incidents and field safety corrective actions in the context of vigilance Partially covered 8.2.2, 8.2.3, 8.3.3 Details on vigilance as laid down Section 2 of Chapter VII are not available in EN ISO 13485. (l) management of corrective and preventive actions and verification of their effectiveness Fully covered 8.5.2, 8.5.3 --- (m) processes for monitoring and measurement of output, data analysis and product improvement Fully covered 8.2.5, 8.2.6, 8.4, 8.5 --- 9 Source: Annex ZA of EN ISO 13485 [51] D2.2| Regulatory framework, security, safety and ethics v2.0 | 12 Nov 2025 67 Annex 3. Interplay of technical documentation, standards, and guidelines The following table shows exemplarily technical documentation (TD) chapters and section as well as related standards and guidelines for the ThrombUS+ device. TD chapter TD section Standard(s) and guideline(s) 1-Product description and specification Intended purpose, qualification, classification and selection conformity assessment procedure MDCG 2021-24, MDCG 2019-11 2-Information to be supplied by the manufacturer Instructions for use and other accompanying documents ISO 15223-1, ISO 20417 2-Information to be supplied by the manufacturer Technical information AI model IG-NB / Team-NB Questionnaire „AI in medical devices”, standards of ISO/IEC JTC 1/SC 42 Artificial intelligence 2-Information to be supplied by the manufacturer Transparency information AI model IG-NB / Team-NB Questionnaire „AI in medical devices”, standards of ISO/IEC JTC 1/SC 42 Artificial intelligence 3-Design and manufacturing information Use requirements and validation IEC 62366-1, IEC 62366-2 3-Design and manufacturing information System requirements and test IEC 60601-1, IEC 60601-1-2, IEC 60601-18, IEC 60601-1-11, IEC 62304 3-Design and manufacturing information System architecture IEC 62304 3-Design and manufacturing information Software safety classification IEC 62304 3-Design and manufacturing information Software development plan IEC 62304 3-Design and manufacturing information Verification of software system (test protocols) IEC 62304 3-Design and manufacturing information AI model development plan IG-NB / Team-NB Questionnaire „AI in medical devices”, standards of ISO/IEC JTC 1/SC 42 Artificial intelligence 3-Design and manufacturing information Data management report IG-NB / Team-NB Questionnaire „AI in medical devices”, standards of ISO/IEC JTC 1/SC 42 Artificial intelligence 3-Design and manufacturing information AI model development report IG-NB / Team-NB Questionnaire „AI in medical devices”, standards of ISO/IEC JTC 1/SC 42 Artificial intelligence 3-Design and manufacturing information Pre-determined change control plan ‘--- 3-Design and manufacturing information Software maintenance plan IEC 62304 3-Design and manufacturing information Software release IEC 62304 3-Design and manufacturing information Design and development plan ISO 13485