A certificate issued by a notified body under the MDR has a maximum period of validity of five years. At expiry, if renewal has not been obtained, marketing of the device must cease. This risk is concrete and predictable — and yet some manufacturers find themselves in a critical situation because they planned for renewal too late.
What happens as expiry approaches
The renewal audit is conducted by the notified body in the months preceding the certificate’s expiry. It covers the entire QMS and the technical documentation, like an initial audit — not a simple routine check. The notified body verifies that updates have been carried out, that post-market data has fed into the CER, that the PSUR is up to date, and that any changes to the device have been correctly documented and notified.
A file that has not been maintained during the term of the certificate arrives at the renewal audit in a degraded state. The non-conformities identified may require a remediation period before renewal can be granted — a period during which marketing is legally suspended.
The timeline to observe
The formal renewal application must be submitted to the notified body early enough to allow for scheduling the audit, reviewing the file, and managing any non-conformities before the certificate expires.
In practice: initiate the renewal process at least 12 to 18 months before the expiry of the certificate. Notified bodies have busy schedules. An application submitted six months before expiry risks not being reviewed in time.
What makes renewal easier
A QMS maintained continuously between surveillance audits, a technical file updated as the device and post-market data evolve, a CER updated annually or biennially, and a vigilance history with no unreported incidents: these are the elements that make the renewal audit smooth.
A difficult renewal is almost always the result of a QMS and a technical file that have been neglected between audits. Continuous surveillance is not optional — it is the condition for maintaining CE marking.