Annex III of the EU MDR contains a short line that quietly creates one of the harder tasks in post-market surveillance. Your PMS plan must address the collection and use of “publicly available information about similar medical devices”. Not information about your device — information about everyone else’s. The obligation is clear enough. The problem is where to go and get it, because the European database built to hold exactly this kind of information was never designed to make most of it public, and the American database that many manufacturers quietly rely on instead is being switched off this year.

What the Regulation Actually Asks For

The requirement appears in more places than most PMS procedures acknowledge. Taken one at a time it looks like housekeeping; taken together it is a standing obligation to know your competitors’ failure history.

Article 83(3) then sets out what all of it feeds: the benefit-risk determination, the risk management, the design and manufacturing information, the instructions for use, the clinical evaluation and the summary of safety and clinical performance. If you are working through PMCF planning, the same data lands there too.

Read together, the position is unambiguous. You are expected to know what has been going wrong with devices like yours, to compare your own performance against them, to write that comparison down, and to defend it in an audit. Which leaves the only question that matters in practice: where do you look?

Why EUDAMED Answers Only Part of the Question

The instinctive answer is EUDAMED. It is partly right, and the part it gets wrong is structural rather than a delay in the rollout.

Article 33(1) sets out what EUDAMED is for. Two of its five purposes are about informing the public: point (a), so that the public is adequately informed about devices placed on the market, the certificates issued by notified bodies and the relevant economic operators; and point (c), so that the public is adequately informed about clinical investigations.

Vigilance is not in that group. It appears at point (d) — to enable manufacturers to comply with their obligations under Articles 87 to 90 — and at point (e), so competent authorities and the Commission can do their work. Recital 46 says the same thing in plainer words: the electronic system on vigilance “should enable manufacturers to report serious incidents and other reportable events and to support the coordination of the evaluation of such incidents and events by competent authorities”.

So the vigilance system, listed at Article 33(2)(f), was built as a reporting channel and a supervisory tool. It was not built as a public record of what has gone wrong. Devices, certificates, economic operators and clinical investigations: public by design. Incidents: not.

There is one significant exception, and it is the most underused public source in Europe. Under Article 32, manufacturers of implantable and class III devices must draw up a summary of safety and clinical performance, and it “shall be made available to the public via Eudamed”. The notified body validates it and uploads it. Its required content includes the intended purpose, indications, contraindications and target populations, a description of the device and its previous generations, the standards applied — and, at point (d), the possible diagnostic or therapeutic alternatives. That is state-of-the-art material, written by the manufacturer, checked by a notified body, in public.

What the SSCP does not give you is failure experience, and it only covers implantables and class III. For everything else the European picture stays incomplete: in its position paper of 6 August 2026, Team-NB, the association representing 46 notified bodies across 20 countries, records that the vigilance module is in playground with mandatory use planned for 2027, and the module for clinical investigations and performance studies is still under development.

Where the Data Actually Is

In practice, manufacturers meeting the Annex III obligation lean heavily on non-European sources. There is no polite way to put it: European post-market obligations are routinely discharged using American, Australian and Canadian data.

Jurisdiction Adverse event data Also public
United States Reports have been public for more than thirty years through MAUDE, now migrating into the Adverse Event Monitoring System launched in March 2026. Clearance and classification decisions (510(k), De Novo, HDE), recalls, and the Total Product Life Cycle database of reported problem codes.
Australia The TGA’s Database of Adverse Event Notifications has covered medical devices since 2012. The ARTG gives manufacturer, classification, nomenclature and intended purpose for devices on the market.
Canada Health Canada publishes mandatory problem reports for medical devices. Regulatory Decision Summaries setting out the scientific reasoning behind decisions — there is no European equivalent of reading a regulator’s argument.
Japan PMDA publishes adverse events, largely in Japanese, with safety communications issued as Yellow Letters and Blue Letters. A searchable device database covering classification, intended use and safety information.
Brazil, Singapore, South Korea ANVISA has collected device adverse events since 2006; Singapore’s HSA since 2010; Korea’s MFDS runs a patient safety reporting portal. Device registers in all three, and Korea’s integrated system includes current recall status.
European Union No central public source. Field safety notices and corrective actions are published nationally, authority by authority. The public parts of EUDAMED for devices, certificates and economic operators — and the SSCPs described above.

One item on that table needs acting on this quarter. MAUDE appears by name, and often by URL, in PMS procedures across the industry. Historical device reports have been migrated into AEMS, new reports are processed there, and MAUDE’s retirement has been announced for dates that have already moved more than once. At the time of writing the legacy search page still responds — but it is on its way out, and the AEMS search interface behaves differently from the one your procedure describes.

And the sources that are not databases at all still matter most: scientific literature remains the backbone of a similar-device search, alongside clinical registries in the relevant specialty, standards and their rationale sections, and, for a named competitor device rather than a whole class, its instructions for use and public safety information.

Keeping this in spreadsheets? The Submission & Document Tracker holds documents and their status against each submission, so a dated search strategy stays attached to the file it belongs to.

Open the Tracker

How to Use These Sources Without Fooling Yourself

This is where a real search strategy separates itself from a screenshot pasted into a clinical evaluation report.

Used properly, these sources answer questions like: what failure modes have been reported for this type of device, what harm did they cause, what corrective actions followed, and does my risk file contain them. Used improperly, they produce a number an auditor can dismantle with one question.

What the Revision Changes

The information gap is not only a manufacturer’s problem, and this year it acquired a second, more visible half.

The Commission’s proposal of 16 December 2025 to simplify the MDR and IVDR, now with Parliament and Council, removes the five-year cap on certificate validity. Instead of recertification, notified bodies would carry out periodic reviews proportionate to the risk class of the device, decide when a certificate’s validity should be limited on justified grounds, and reserve unannounced audits for cause. That is a shift from scheduled checks to judgement, and judgement runs on information.

Which is what the Team-NB paper is about. Its members, it says, cannot see most of EUDAMED — not the vigilance module, not clinical investigations, in some cases not even what their own clients file. Their request is a single amendment to Article 106b(4) of the proposal, which as drafted grants that access to the EMA alone. ENISA and the national CSIRTs are already on the access list for cybersecurity incident reporting; the bodies that issue the certificates are not.

The same gap, seen from the other side of the table. You are asked to compare yourself against similar devices without a European source of similar-device failure experience. Your notified body is being asked to calibrate its scrutiny of you without one either.

What to Do About It Now

“The data is not available in Europe” is not an answer an auditor accepts, and after the sections above it is not even accurate.

If the device in question is software

How much surveillance you owe follows from your class, and your class follows from a paragraph most teams write last. The 33-page guide covers qualification, the intended purpose statement that decides the class, Rule 11 with the implementing rules that can override it, and three worksheets for your technical documentation.

Get the guide