Medical Device M&A Due Diligence: MDR Compliance Risks

Medical Device M&A Due Diligence: MDR Compliance Risks

Image: Plausity

Key Takeaways

  • Regulatory approvals create significant market barriers; securing a PMA can require up to 75 million dollars and 3 to 7 years of investment.
  • The EU MDR framework applies 22 strict classification rules, leading to frequent up-classifications for software under Rule 11.
  • Acquirers must verify that targets maintain valid CE certificates, compliant technical documentation, and robust clinical evaluation reports.
  • Importers and distributors share explicit regulatory liability under MDR Articles 13 and 14, requiring EUDAMED registration and CE mark verification.

Why product and market compliance matters in M&A

In medical device mergers and acquisitions, regulatory compliance is not merely an operational check. It directly dictates transaction structure, valuation multiples, and go-or-no-go investment decisions. The regulatory status of a target company's portfolio governs legal market access across key jurisdictions. Valid CE mark certifications and regulatory clearances establish high barriers to entry that protect market share and pricing power. However, regulatory non-compliance, lapsed certificates, or unresolved transition bottlenecks under the European Union Medical Device Regulation represent immediate liabilities that can halt commercial distribution overnight.

The enforcement of Regulation (EU) 2017/745 (EU MDR) has fundamentally transformed the European market by replacing legacy Directives 90/385/EEC and 93/42/EEC with stringent requirements for clinical evidence, technical documentation, and lifecycle traceability. For private equity funds and corporate acquirers, failing to verify the target's underlying regulatory dossier introduces catastrophic downside risk. If a target relies on invalid CE certificates or lacks a viable pathway to complete Notified Body conformity assessments, the buyer faces immediate revenue interruption, inventory write-downs, substantial remediation expenses, and potential regulatory sanctions.

  • Deal valuation and revenue defensibility: Regulatory clearances directly underpin recurring revenue; any risk of certificate suspension or cancellation erodes projected EBITDA.
  • Remediation capital expenditure: Transitioning legacy technical documentation and conducting required post-market clinical follow-up (PMCF) studies can require substantial unbudgeted capital.
  • Transaction structuring and indemnities: Unresolved non-conformities from Notified Body audits frequently necessitate special escrows, specific indemnities, or deferred consideration mechanisms.
  • Integration velocity: Unaligned quality management systems or non-compliant economic operator networks delay post-merger commercial synergy realisation.

Consequently, rigorous product-level regulatory compliance due diligence must identify the exact regulatory status of every SKU, assess the validity of existing conformity assessments, and stress-test the operational timeline for ongoing compliance across European and international target markets.

Main medical device due diligence framework

A comprehensive medical device regulatory diligence framework requires systematic evaluation of product classification, conformity assessment pathways, and technical documentation completeness under EU MDR 2017/745. Annex I (general safety and performance requirements), Annex II (technical documentation) and Annex III (technical documentation on post-market surveillance) apply to every device regardless of risk class, while the applicable conformity assessment procedure in Annexes IX to XI depends on the class. The framework establishes an objective, evidence-grounded baseline for every device in the target portfolio by verifying documented claims against statutory classifications and Notified Body records.

Under MDR Article 51, devices are divided into Class I, Class IIa, Class IIb, and Class III according to their intended purpose and inherent risks, with classification carried out in accordance with the classification rules in Annex VIII; Class I is further subdivided into Is (sterile), Im (measuring function) and Ir (reusable surgical). Those rules combine criteria such as duration of contact, degree of invasiveness, local versus systemic effect, potential toxicity, the part of the body affected, and whether the device depends on a source of energy, and where several rules apply the strictest one giving the highest class prevails. Diligence teams must carefully scrutinize the target's stated intended purpose to detect improper down-classification, especially for software, implantable devices, and substance-based medical products.

Under the MDR framework, the requirement for third-party Notified Body oversight expands compared to legacy Directives: conformity assessment for Class I devices is generally carried out under the sole responsibility of the manufacturer, while an appropriate level of Notified Body involvement is compulsory for Class IIa, Class IIb and Class III devices, increasing with the risk class. Deal teams must therefore determine whether the target's product classifications mandate Notified Body intervention and verify that the target has engaged a designated Notified Body with appropriate scope codes.

Transitional provisions under Regulation (EU) 2023/607

Regulation (EU) 2023/607 amended the transitional provisions of Article 120 of the EU MDR, extending certificate validity for qualifying legacy devices provided strict conditions are met. Higher-risk devices (Class III and Class IIb non-well-established implantable devices) benefit from an extension until 31 December 2027, while medium- and lower-risk devices (other Class IIb, Class IIa, and Class I upclassified devices) are extended until 31 December 2028.

  • No significant changes in design or intended purpose: The device must not undergo substantial modifications that alter its safety or clinical profile under MDCG guidance.
  • Quality Management System compliance: The manufacturer was required to put in place an MDR-compliant QMS no later than 26 May 2024.
  • Formal application submitted: A formal application for MDR conformity assessment must have been lodged with a Notified Body by 26 May 2024.
  • Written agreement executed: A formal written agreement between the manufacturer and the Notified Body must have been signed by 26 September 2024.

During diligence, teams must verify that the target company has complied with each of these statutory milestones to confirm that its legacy devices legally benefit from the extended transitional deadlines. Regulation (EU) 2023/607 makes the extension conditional on the devices continuing to comply with Directive 90/385/EEC or 93/42/EEC, on there being no significant changes in design and intended purpose, on an MDR-compliant quality management system under Article 10(9) being in place no later than 26 May 2024, and on the notified body and manufacturer having signed a written agreement no later than 26 September 2024.

What buyers, PE teams, and advisers should test

When evaluating a medical device acquisition target, investment teams and their advisory partners must test specific regulatory workstreams against primary data room evidence. Diligence cannot rely solely on executive representations; it requires examining technical documentation, clinical datasets, and commercial operator networks.

Technical documentation and clinical evaluation

Diligence teams must audit technical files against the detailed requirements of Annex II and Annex III of the EU MDR, both of which apply to devices in every risk class. A complete technical file must encompass design verification and validation, comprehensive risk management files under ISO 14971, and manufacturing process validation. In particular, Clinical Evaluation Reports (CER) require close inspection. A clinical evaluation is mandatory for every device under MDR Article 5(3), Article 61 and Annex XIV, and for implantable and Class III devices a pre-market clinical investigation is compulsory unless a narrow exemption applies, such as demonstrated equivalence to a CE-marked device with sufficient existing clinical data.

Post-market surveillance and vigilance systems

A compliant quality system must demonstrate active, continuous post-market surveillance. Diligence teams must review Post-Market Surveillance (PMS) plans, Periodic Safety Update Reports (PSURs), and Post-Market Clinical Follow-up (PMCF) plans and evaluation reports. For Class IIa, IIb and III devices the manufacturer must prepare a PSUR for each device, updated at least annually for Class IIb and III devices and at least every two years for Class IIa devices, while Class I manufacturers must instead maintain a post-market surveillance report under Article 85. Furthermore, incident reporting logs and vigilance files must be checked to confirm that serious incidents and Field Safety Corrective Actions (FSCAs) were reported to competent authorities within statutory deadlines.

Software-as-a-Medical-Device (SaMD) and AI qualification

For digital health and software-driven medtech targets, diligence must scrutinize software qualification under MDR Annex VIII Rule 11 and MDCG 2019-11 guidance. Under Rule 11, software intended to provide information used to take decisions with diagnostic or therapeutic purposes is Class IIa, rising to Class IIb where the decision could cause serious deterioration of health or surgical intervention and Class III where it could cause death or irreversible deterioration, which leaves only a narrow residual category of self-certified Class I software. In medtech due diligence, verifying software version controls, cybersecurity documentation, and clinical validation is essential.

Economic operator obligations under Articles 13 and 14

The EU MDR imposes direct statutory responsibilities across the entire distribution chain, from manufacturers and authorised representatives to importers and distributors, as set out in Chapter II of the Regulation. Deal teams must verify that the target and its commercial partners satisfy each of these economic operator obligations.

  • Importer verification (Article 13): Importers must verify CE marking, EU Declaration of Conformity, appropriate labelling, UDI assignment, and storage condition compliance.
  • Distributor verification (Article 14): Distributors must verify that the device bears CE marking, that required information accompanies the device, and that non-conforming devices are quarantined.
  • Person Responsible for Regulatory Compliance (PRRC): Manufacturers must document the appointment of a qualified PRRC under Article 15 meeting statutory education and experience criteria.
  • Authorised Representative mandates: Non-EU manufacturers must maintain a valid written mandate with an EU Authorised Representative (EC REP) under Article 11.

Medical device regulatory red-flag table

To facilitate structured decision-making and risk register automation, findings should be categorized by severity, deal impact, and required remediation action. The following table provides a standard taxonomy for medical device regulatory risks encountered during M&A due diligence.

Risk CategoryFinding DescriptionSeverity LevelDeal & Financial Impact
Licensing & Market AccessCommercial sales without valid CE certificate or missing Notified Body contract under Regulation (EU) 2023/607High (Deal-Breaker)Immediate sales halt across EU, inventory obsolescence, potential regulatory enforcement and revenue loss.
Product ClassificationStandalone software misclassified as Class I instead of Class IIa/IIb under MDR Rule 11HighMandatory re-certification with Notified Body, clinical study requirements, commercial delays.
Quality & Audit FindingsMajor non-conformities from Notified Body audits or unaddressed competent authority warning lettersHighRisk of certificate suspension, substantial remediation costs, escrow holdback requirement.
Clinical EvidenceLack of direct clinical data for legacy devices and reliance on unsubstantiated equivalence claimsMedium to HighRequirement to design and fund prospective PMCF clinical trials, potential narrowing of claims.
Post-Market SurveillanceMissing or outdated PSURs and PMCF evaluation reports for Class IIa/IIb devicesMediumAudit findings during upcoming surveillance reviews, regulatory remediation plan required.
Economic Operator SetupIncomplete importer/distributor agreements or missing Article 15 PRRC appointment documentationLow to MediumAdministrative non-compliance, contract remediation, potential customs clearance delays.

High-severity findings often necessitate adjustments to the headline transaction price, indemnity carve-outs, or pre-closing conditions precedent requiring target management to cure identified deficiencies before funds are released.

Evidence checklist and data room request list

A disciplined due diligence process requires requesting and verifying specific regulatory artifacts. Acquirers should structure their data room requests to obtain primary source documentation rather than summary memoranda.

  • Active CE Certificates and Declarations: Current CE marking certificates issued by designated Notified Bodies, accompanied by the target's signed EU Declarations of Conformity under MDR 2017/745.
  • Transition Eligibility Records: Formal applications submitted to Notified Bodies prior to 26 May 2024 and signed Notified Body written agreements executed before 26 September 2024 under Regulation (EU) 2023/607.
  • Quality Management System Certifications: ISO 13485:2016 certificates, Notified Body audit reports for the preceding 36 months, and open Corrective and Preventive Action (CAPA) logs.
  • Technical Files and Risk Management: Complete Annex II technical documentation, risk management files complying with ISO 14971, and usability engineering files.
  • Clinical Evaluation Documentation: Current Clinical Evaluation Reports (CER), Clinical Evaluation Plans, and Post-Market Clinical Follow-up (PMCF) plans and evaluation reports.
  • Post-Market Surveillance and Vigilance Logs: Post-Market Surveillance plans, Periodic Safety Update Reports (PSURs), trend reports, and historical incident reporting logs to competent authorities.
  • Regulatory Governance and Registrations: Confirmation of Single Registration Number (SRN) in EUDAMED, Unique Device Identification (UDI) documentation, and formal PRRC appointment letters under MDR Article 15.

Cross-referencing these requested items against the target's operational commercial SKUs ensures that no uncertified product variants or unapproved claim expansions exist within the target's revenue base.

Explicit regulatory disclaimers

Conducting product and market regulatory due diligence requires clear legal boundaries and strict operational protocols. Deal teams, corporate acquirers, and investment professionals must note the following structural principles:

  • No legal advice: Due diligence software, analytical workflows, and structured evidence matrices do not constitute, and must not be construed as, formal legal advice or statutory regulatory counsel.
  • No compliance certification: Platform findings, risk scores, and automated documentation gap analyses do not constitute formal regulatory clearance, conformity assessment, or official compliance certification.
  • Qualified advisor confirmation required: All findings, identified red flags, document gap assessments, and risk classifications generated during the diligence process must be reviewed and confirmed by qualified external legal counsel and specialised regulatory affairs advisors prior to executing binding transaction agreements.
  • Evidence structuring and risk intelligence: Due diligence technology serves exclusively to support evidence structuring, issue spotting, source grounding, and risk register preparation across data room archives.

By adhering to these boundaries, transaction teams ensure that diligence findings are methodically validated by licensed regulatory specialists while accelerating the initial identification of critical risk factors.

How to use this in your next diligence workflow

Modern transaction timelines leave little room for manual, spreadsheet-based document review across thousands of pages of medical device technical files. Implementing an AI-native diligence workflow allows investment teams and advisors to systematically ingest, cross-reference, and evaluate regulatory evidence at transaction speed.

Plausity streamlines regulatory product due diligence through a purpose-built suite of deal intelligence capabilities. By deploying Data Room Ingestion, deal teams can connect directly to virtual data rooms and automatically process complex technical files, audit reports, and quality certificates. The AI-Analysis Engine then cross-references product intended use claims against Annex VIII classification rules and active Notified Body certificates, rapidly identifying ungrounded claims or missing transition documentation.

Identified anomalies and compliance gaps are automatically categorized within Risk Radar, which ranks findings by severity, deal impact, and required remediation. Deal teams can then collaborate seamlessly in Collaboration Hub to align on findings with external regulatory counsel, and utilize Report Builder to generate audit-ready regulatory risk registers and investment committee evidence packs with full source traceability back to primary data room records.

How Plausity accelerates this workflow

Plausity is an AI-native due diligence and deal intelligence platform that helps M&A advisory firms, VC and PE funds, corporate development teams and family office investment teams structure evidence, findings and questions across a data room. Plausity does not provide legal advice, does not issue compliance certification and does not replace qualified legal or regulatory advisors — it supports evidence structuring, issue spotting, source grounding and risk register preparation, and all findings should be confirmed by qualified legal or regulatory advisors.

To explore the underlying capabilities, see the Plausity AI analysis engine and the findings and risk intelligence product page. For team-level workflows, see how VC and PE funds and M&A advisory firms use Plausity across live deals.

Sources

Frequently Asked Questions

PLAUSITY

AI Summary

Ask an AI assistant to summarise Plausity.