Opens in a new tab

EUDAMED: Why Compliance Is Not a One-Off Project but an Ongoing Discipline

AI-generated image of Christophe Devins, a professional in the medical device regulatory compliance.

Written by

Nicolas Blanquet
Medical device regulatory compliance dashboard on a computer screen.

As EUDAMED progressively becomes operational under the MDR and IVDR framework, many medical device manufacturers still approach it as a data migration project.

The logic often seems straightforward: collect the required information, publish it once, and consider the task completed.

This perception is understandable. Regulatory teams have already invested significant time and resources into UDI implementation, technical documentation, and certification. In that context, EUDAMED may appear as a final administrative step.

However, in regulatory practice, EUDAMED does not function as a one-off exercise. It introduces a new, long-term obligation: the continuous maintenance of regulatory device data throughout the product lifecycle.

Understanding this distinction is essential to avoid operational risk, audit difficulties, and loss of control over regulatory data.

What the Regulation Actually Requires

The obligation to maintain data is not an interpretation. It is written into the framework that established the database.

Commission Implementing Regulation (EU) 2021/2078 of 26 November 2021 lays down the detailed arrangements for the setting up and the maintenance of EUDAMED. Maintenance is part of the design of the system, not an afterthought.

The timeline confirms the same reading. Commission Decision (EU) 2025/2371 of 26 November 2025, published in the Official Journal on 27 November 2025, declared the functionality of the first four modules. Under the transitional provisions of Regulation (EU) 2024/1860, that publication triggered a six-month transition period, and the first four modules became mandatory to use on 28 May 2026.

Two further modules — post-market surveillance and vigilance, and clinical investigations and performance studies — remain under development. According to the European Commission, there will be no voluntary use period for these two modules before they become mandatory.

For a regulatory team, that last point matters more than it appears. It means the scope of what must be maintained in EUDAMED will expand, on a schedule the manufacturer does not control. A dataset that is only accurate because someone checked it once will not absorb that expansion.

EUDAMED in the Regulatory Framework

EUDAMED is designed to support transparency, traceability, and coordination across the European regulatory system. It connects device identification, certification, vigilance, and market surveillance into a single ecosystem accessible to multiple stakeholders.

From a manufacturer’s perspective, this means that device data published in EUDAMED becomes:

  • visible to competent authorities and notified bodies,
  • referenced in regulatory assessments,
  • and, for certain elements, accessible to the public.

As a result, EUDAMED data is no longer isolated. It must remain consistent with certificates, technical documentation, and internal product records over time. This is where the notion of a project quickly reaches its limits.

Why EUDAMED Cannot Be Treated as a One-Shot Migration

A traditional data migration typically has a clear start and end: data is extracted, transformed, loaded into a target system, and the project is closed.

EUDAMED works differently. Once initial publication is completed, regulatory data continues to evolve. Medical devices are not static, and neither are regulatory requirements.

Key events that may trigger updates include:

  • the introduction of new devices,
  • modifications to existing devices,
  • corrections to previously published data,
  • updates to documentation references attached to a device record,
  • changes in classification, nomenclature, or regulatory expectations,
  • and interactions with notified bodies or authorities.

Each of these events can require updates to EUDAMED data. This ongoing nature makes EUDAMED fundamentally incompatible with a publish once and forget approach.

The mechanics of those updates — how a record moves from one version to the next, and what remains visible afterwards — are covered in our guide on how device data versions are managed in EUDAMED.

The Real Risk: What Happens After the First Publication

In practice, the highest risk does not lie in the initial EUDAMED submission. The real risk emerges over time, when updates are not managed consistently.

In many organizations, regulatory data exists across multiple systems: internal product databases, quality management documentation, certificates issued by notified bodies, and EUDAMED itself. Without a structured approach, these data sources can gradually drift apart.

Small discrepancies may go unnoticed at first. But over time, they accumulate, leading to situations where internal data no longer matches published EUDAMED data, the rationale behind changes becomes difficult to reconstruct, and regulatory teams struggle to demonstrate consistency during audits or inspections.

When this happens, EUDAMED shifts from being a compliance support tool to a source of uncertainty.

What a EUDAMED Data Maintenance Plan Covers

A maintenance plan does not need to be long. It needs to answer four questions in writing, and to be applied consistently.

Diagram of the EUDAMED data maintenance cycle: an event triggers a review, the review drives an update, and the update leaves evidence.
The maintenance cycle: an event triggers a review, the review drives an update, and the update leaves evidence behind.

1. What triggers a review? The events listed above are the starting point. Each one should have a named owner and an expected reaction time. A device modification that reaches the regulatory team three months after the fact is not a data problem; it is a process problem.

2. What is compared, and against what? Published EUDAMED data should be reconcilable with the internal product record, the technical documentation, and the certificates in force. The reference is not EUDAMED itself: it is the internal source of truth from which EUDAMED is populated.

3. How often does the review happen when nothing has changed? Event-driven updates cover what the organization knows about. A periodic review covers what it does not. A recurring check on the published portfolio is what surfaces a record that quietly stopped matching its certificate.

4. What is retained as evidence? For each change: what was modified, when, by whom, and on what basis. This is what turns an answer given during an inspection into a demonstrable one.

Legacy devices deserve a specific line in that plan, because their obligations and exceptions differ from those of devices placed on the market under the regulations — a distinction detailed in our guide on legacy devices obligations and exceptions.

EUDAMED as a Continuous Operational Responsibility

Treating EUDAMED as an ongoing discipline requires a change in mindset. Instead of asking how to publish the data, the more relevant questions become how to maintain data accuracy over time, how to ensure traceability of changes, how to keep internal data and published data aligned, and how to demonstrate control during audits.

From this perspective, EUDAMED becomes part of day-to-day regulatory operations, rather than a standalone project. This approach aligns EUDAMED with other MDR / IVDR obligations, which are already managed as continuous processes rather than isolated tasks.

Understanding how the different EUDAMED modules connect to one another helps to map where each obligation lands in that daily routine, and which team owns it.

Governance and Ownership: A Key Success Factor

One of the most common challenges observed over time is unclear ownership of EUDAMED data updates. When responsibilities are fragmented, updates may be delayed, applied inconsistently, or implemented without full visibility across teams.

A sustainable EUDAMED approach typically relies on clearly defined roles and responsibilities, alignment between regulatory, quality, and data owners, and structured processes for reviewing and validating changes.

This does not mean adding unnecessary complexity. On the contrary, clarity of governance often reduces operational friction and improves audit readiness. ACKOMAS describes this in more detail in a structured EUDAMED data governance framework.

Why Manual Approaches Struggle Over Time

Some organizations initially rely on manual processes to manage EUDAMED updates. While this may appear manageable at first, manual approaches tend to become fragile as the number of devices increases, the frequency of updates grows, and regulatory expectations evolve.

Manual handling increases the risk of data entry errors, loss of traceability, and inconsistencies between systems. Over time, maintaining confidence in data accuracy becomes increasingly difficult.

This is why many regulatory teams eventually reassess how EUDAMED fits into their broader data governance strategy, and compare manual entry with a more automated approach before their portfolio grows further.

From Compliance Event to Compliance Capability

Ultimately, EUDAMED introduces a shift from compliance as an event to compliance as a capability.

The objective is no longer only to meet a specific deadline, but to sustain regulatory data quality, adapt to changes without disruption, and demonstrate control throughout the device lifecycle.

Organizations that adopt this perspective are better positioned to manage future regulatory evolution, including the remaining EUDAMED modules and expanded data requirements.

Key Takeaways

  • EUDAMED is not a one-off data migration project.
  • Maintenance is written into the framework that established the database.
  • Initial publication is only the beginning of the compliance journey.
  • The main risk lies in long-term data misalignment.
  • Treating EUDAMED as an ongoing discipline improves control and audit readiness.
  • Clear governance and structured processes are essential to sustainability.

Discussing a Sustainable EUDAMED Approach

Every organization has its own regulatory landscape, data architecture, and operational constraints.

If you would like to discuss how to approach EUDAMED as a long-term regulatory discipline within your organization, you can contact the ACKOMAS team or explore the ACKOMAS compliance solution.

—

Frequently asked questions

Find answers to the most common questions related to this guide.

Turn compliance knowledge into action

Discover how ACKOMAS automates EUDAMED, GUDID & UDI data synchronization — so your RA/QA team stays compliant without the manual work.

EUDAMED & GUDID regulatory alerts — delivered to your inbox

Receive concise updates on MDR/IVDR regulatory changes, EUDAMED registration deadlines, and GUDID compliance requirements. Built for RA/QA and regulatory affairs teams. No promotional content — only actionable changes.

🔒 Our Commitment
ACKOMAS will never share your data with anyone outside the company—for marketing or any other purpose. 100% GDPR compliant.

A smartphone displaying an email about an EU medical regulation update rests on a table next to eyeglasses, a printed regulatory timeline, and a cup of coffee.
  • Webinar replays & regulatory briefings

    Watch recorded sessions on EUDAMED registration, UDI structuring, and data governance

  • Deadline alerts & regulatory changes

    Be notified when EUDAMED deadlines, MDCG guidance, or submission rules change

  • Compliance guidance for your team

    Practical resources to prepare for audits, structure your UDI data, and manage multi-market registration