EU MDR 2017/745 · ISO 13485

    AI-native regulatory consulting for medtech.

    With focus on SaMD, SiMD, and AI-enabled devices.

    We pair hands-on regulatory experience with technical and AI expertise, so the hard judgment gets expert attention and the document work goes faster.

    What we do

    EU MDR regulatory consulting for software and AI medical devices.

    Hands-on regulatory work, not just advice.

    We write the content and structure your technical files ourselves. Senior, and scoped to where you are now.

    Objective gap analysis

    An independent read of where you stand against MDR and ISO 13485, with the gaps ranked by what matters. The place to start.

    SaMD classification and regulatory strategy

    A defensible classification and a clear route to market, before you commit to building it.

    ISO 13485 quality management system

    An ISO 13485 quality system sized to your stage and shaped to how your team actually works, not a binder that fails its first audit.

    MDR technical documentation (Annex II and III)

    The full technical file a Notified Body expects, pre-market and post-market, shaped to fit how your team already builds.

    Clinical evaluation for software devices

    A realistic evidence plan: what you need, what you can defer, and which studies you can avoid.

    Post-market surveillance and vigilance

    Surveillance, incident tracking and periodic reporting, set up once rather than rebuilt each year.

    Pre-market to post-market. One senior team.

    Who we serve

    SaMD, SiMD, and AI-enabled devices.

    Software that is the device, software inside the device, and the AI models inside them. All three are our core work.

    Software as a medical device (SaMD)

    Standalone software performing a medical function on its own: diagnosis, triage, monitoring, treatment planning. Classified under MDR Rule 11.

    Software in a medical device (SiMD)

    An algorithm embedded in hardware, where the device is classified as a whole. The model is the novelty; the hardware delivers it.

    AI and ML-enabled devices

    Trained models in either shape, where validation, data quality, drift, and the EU AI Act sit on top of MDR.

    If the core of your device is an algorithm, you are in scope.

    Why Artifakt

    SaMD and AI device specialists, not generalist consultants.

    We focus on the detail.

    We go deep, not wide

    We take on a small number of partners and stay with them, rather than spreading thin across many clients and letting quality slip.

    Specialists only

    Software and AI medical devices are all we do. We understand the product and the regulation at the same time.

    We work to your timeline

    Paced to your roadmap and your raise, clearing the next milestone instead of becoming the bottleneck.

    Every output peer-reviewed

    A second specialist checks the work before it reaches you.

    Where we're going

    Consulting today, automation next.

    Alongside the consulting, we're building AI automation for the same work, aimed at significantly reducing the cost and timelines of getting and staying compliant. We're early, and the manufacturers we partner with now help shape it and are the first to benefit as it matures.

    The Problem

    Compliance is fragmented, static, and manual.

    01

    Fragmented

    Compliance lives across binders, spreadsheets, and disconnected QMS tools that don't speak to each other.

    02

    Static

    Technical documentation is treated as a one-time submission. Regulation isn't.

    03

    Manual

    Every regulatory update means human chasing across teams, suppliers, and notified bodies.

    The Thesis

    Regulation is continuous. Compliance should be too.

    First Module Live

    ARTIFAKT VIGILANCE.

    Our live, free tool for EU MDR post-market work. It aggregates eight safety databases in one query, then drafts the literature and clinical sections of your PSUR, PMCF, SSCP, or literature review to the MDCG and MEDDEV templates notified bodies expect. You review, edit, and own the final document.

    Live · Free during launch

    Four report templates, eight safety databases, one workspace.

    PSUR (MDCG 2022-21) · PMCF (MDCG 2020-8) · SSCP (MDCG 2019-9) · PRISMA / MEDDEV 2.7/1 literature review

    FDA MAUDE · FDA Recalls · BfArM · MHRA · Health Canada · PubMed · Europe PMC · ClinicalTrials.gov

    Try Vigilance, free

    Common questions

    Questions we get asked first.

    How is software as a medical device classified under EU MDR Annex VIII?

    Classification follows the intended purpose, and for software the decisive provision is usually Rule 11. Software that provides information used to take diagnostic or therapeutic decisions is Class IIa, and it moves to Class IIb where such a decision could cause serious deterioration of health or a surgical intervention, or to Class III where it could cause death or an irreversible deterioration. Software intended to monitor physiological processes is Class IIa, or Class IIb where variations could result in immediate danger. Software that drives or influences another device is classified in its own right, but not lower than the class of that device. Class I remains only for software with no diagnostic or therapeutic decision role, which is a narrower group than most teams assume.

    Does a Class IIa medical device need a Notified Body?

    Yes. Self certification stops at Class I. Every Class IIa device needs a Notified Body, which assesses your quality management system and samples the technical documentation across the device categories you place on the market. Three Class I subgroups also need a Notified Body, but only for one specific aspect: sterile devices for the sterility, measuring devices for the metrological function, and reusable surgical instruments for reuse. In practice the binding constraint is capacity, not eligibility, so approach a Notified Body well before you plan to submit.

    How does the EU AI Act interact with the MDR?

    They stack rather than replace one another. If an AI enabled device already requires a Notified Body under the MDR, it is generally treated as high risk under the AI Act, so AI Act duties such as data governance, logging, transparency, human oversight, accuracy and robustness apply on top of your MDR obligations. The intent is that this is assessed through the existing medical device conformity assessment rather than a second parallel audit. The timing changed in July 2026: the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high risk obligations for AI embedded in regulated products, which includes medical devices, to 2 August 2028, and moved standalone Annex III systems to 2 December 2027. The prohibitions and the general purpose AI rules already apply. The practical consequence is that most of the work should extend your existing QMS, risk management file and post market plan instead of creating a separate AI compliance system.

    What clinical evidence does a Clinical Evaluation Report need?

    Enough clinical data to show the device achieves its intended purpose, meets the relevant general safety and performance requirements, and that its benefits outweigh its risks in normal use. That means a clinical evaluation plan written before the search, a systematic and reproducible literature search with documented appraisal of what it returned, and then either your own clinical investigation data or an equivalence claim that is technically, biologically and clinically justified and backed by contractual access to the equivalent device's technical documentation. The conclusion must tie back to the risk management file, and it cannot be a one off: post market clinical follow up feeds new data into the CER on a defined cycle. Article 61 and Annex XIV are the legal basis, and MEDDEV 2.7/1 Rev 4 is still the method most Notified Bodies expect to see.

    UKCA or CE marking: what applies in Great Britain?

    They are separate routes with separate infrastructure, and for most manufacturers a CE mark remains the practical route into Great Britain today. The MHRA accepts devices certified under the EU MDR or IVDR until 30 June 2030, and devices still certified under the older MDD or AIMDD until the sooner of certificate expiry or 30 June 2028. UKCA requires a UK Approved Body rather than an EU Notified Body, and a UK Responsible Person if you are not established in the UK, though Class I devices that are neither sterile nor measuring can self certify. Northern Ireland continues to follow EU rules, which is why the UKNI mark exists for devices certified by a UK body. The MHRA consulted in early 2026 on recognising CE marked MDR and IVDR devices indefinitely and has not published an outcome, so confirm the current position before you build a plan around these dates.

    ARTIFAKT MEDICAL

    Start here

    Start with a gap analysis.

    A clear, honest read on where you stand against MDR and ISO 13485, and a low-commitment way to see how we work. From there, we go as deep as you need.