A medical device regulatory strategy sets out, before development gets far, which rules apply to a product, which market approvals are needed, and what evidence each approval will demand. For digital health products, that question rarely has a single answer. One product can fall under several regulations at once.
Getting the strategy right early saves rework later. A late change to intended purpose or classification can reset months of documentation and testing.
Start With Intended Purpose and Classification
Every regulatory strategy starts with the intended purpose: what the product does, for which users and patients, in what clinical context, and what claims sit behind it. The intended purpose and indications for use drive the decisions that follow.
Two questions then decide the route:
- Qualification: does the product meet the legal definition of a medical device, an in vitro diagnostic medical device, an AI system, or an electronic health record system?
- Classification: what risk class does it fall under?
The class sets the conformity assessment route and whether an independent body reviews the product. Under the EU MDR (Regulation 2017/745), devices fall into Class I, IIa, IIb, or III. Under the IVDR (Regulation 2017/746), in vitro diagnostic medical devices fall into Class A, B, C, or D. Higher classes require a notified body and more clinical or performance evidence. This early work is the core of regulatory strategy building.
Identify Every Regulation That Applies in the EU
For AI/ML-enabled medical devices and other digital health products, more than one EU regulation often applies to the same product:
- MDR (Regulation 2017/745) for software as a medical device (SaMD).
- IVDR (Regulation 2017/746) for software as an IVD (SaIVD).
- EU AI Act (Regulation 2024/1689). An AI system that is a medical device, or a safety component of one, and that requires a notified body assessment under the MDR or IVDR, is treated as a high-risk AI system.
- EHDS (Regulation 2025/327), which sets requirements for electronic health record systems and the interoperability of electronic health data.
- Cyber Resilience Act (Regulation 2024/2847), which can apply to healthcare software with digital elements that medical device legislation does not already cover.
A single product can carry obligations under two or three of these at the same time. Setting them out at the strategy stage tells the team which standards, technical documentation, and conformity assessment steps to plan for.
Plan the US Route Through the FDA
In the United States, the FDA uses risk-based marketing pathways:
- 510(k) premarket notification, which demonstrates substantial equivalence to a legally marketed predicate device.
- De Novo classification request, for a low to moderate risk device with no legally marketed predicate.
- Premarket approval (PMA), for high-risk Class III devices.
The EU and US systems work differently. The EU route depends on demonstrating conformity with defined requirements. The FDA route often depends on the choice of predicate and product code.
A device cleared in one market is not automatically ready for the other, so a strategy that covers both markets sets out the evidence each one needs.
Turn the Strategy into a Compliance Plan
Once qualification, classification, and market routes are settled, the strategy becomes a compliance plan: the standards to apply (for example ISO 13485 for the quality management system, ISO 14971 for risk management, and IEC 62304 for the software lifecycle), the technical documentation to produce, the clinical or performance evidence to gather, and the order of submissions.
Written down and kept current, this plan gives the whole team one reference for what to build and when.
How MedQAIR Can Help
At MedQAIR, we provide medical device regulatory strategy support from product qualification and classification through to market access planning for medical devices across the EU and US. To discuss your product, book a call or contact our team.