EUDAMED Is Mandatory: How To Use It Without Going Crazy (2026)

Topics EUDAMED

Important 2026 update: EUDAMED is no longer merely a voluntary preview. Since 28 May 2026, its first four modules are mandatory: Actor registration, UDI/Devices, Notified Bodies & Certificates, and Market Surveillance. The remaining Vigilance/Post-Market Surveillance and Clinical Investigations/Performance Studies modules follow their own transition timetable.

The interface still rewards patience, but the workflow becomes manageable when you separate three things that EUDAMED tends to blur together: your personal EU Login, your organisation's Actor registration, and the individual records your organisation submits. This guide focuses on the jobs most manufacturers actually need to complete.

What is mandatory now?

The European Commission declared four systems functional in Commission Decision (EU) 2025/2371. The six-month transition ended on 28 May 2026. The mandatory modules are:

  • Actor registration: economic-operator identities, roles, user access and the Single Registration Number (SRN) or Actor ID.
  • UDI/Devices: Basic UDI-DI and UDI-DI records for MDR and IVDR devices, plus relevant legacy-device data.
  • Notified Bodies & Certificates: notified-body certificate and related registration activities.
  • Market Surveillance: competent-authority market-surveillance activities.

“Four modules are mandatory” does not mean every actor enters data into all four. A manufacturer normally manages its actor and device data; a notified body manages certificate data; authorities manage surveillance data. Determine your obligations from your legal role and the MDR or IVDR, not from the number of dashboard tiles you can see.

Before you log in: prepare the ownership model

Avoid making a departing employee the only person who can administer your actor. EUDAMED distinguishes the organisation from its users and grants profiles per module. The Commission recommends at least two Local Actor Administrators (LAAs), and an actor must retain an active LAA.

Decide and document:

  • who owns the EU Login account used by each person;
  • who acts as LAA and backup LAA;
  • who may prepare, submit and confirm device records;
  • who reviews EUDAMED data against controlled source records;
  • how access is removed when roles change; and
  • how EUDAMED changes enter document control and change control.

Use named personal accounts. Sharing one login destroys accountability and makes offboarding painful.

Step 1: register or join the correct Actor

An Actor is an organisation acting in a specific regulatory role. Manufacturers, authorised representatives, importers, and system or procedure pack producers register as actors. If one legal entity has more than one role, the Commission requires a separate actor registration for each role.

  1. Create or use your personal EU Login.
  2. Search EUDAMED before starting a new registration. If the correct actor already exists, request user access instead of duplicating it.
  3. For a new actor, select the exact country, role and legal-entity details. Match company-register and regulatory documents.
  4. Upload the signed declaration on information-security responsibilities. A non-EU manufacturer also needs an active authorised representative and the required mandate summary; the authorised representative must already be registered.
  5. Submit the request. The responsible competent authority assesses it; for a non-EU manufacturer, the authorised representative verifies it first.
  6. After validation, record the issued SRN or Actor ID in your controlled regulatory data and appoint a backup administrator.

The person submitting a successful new-actor request becomes the first LAA. If you only need access to an existing actor, an LAA or Local User Administrator for that actor approves your request and assigns the appropriate profiles.

Step 2: prepare device data outside EUDAMED

Do not improvise regulatory master data field by field in the browser. Build a reviewed data sheet first. At minimum, coordinate:

  • Basic UDI-DI and issuing entity;
  • UDI-DI and any applicable unit-of-use, direct-marking or packaging identifiers;
  • trade name, model and catalogue reference;
  • risk class and applicable legislation;
  • intended purpose and device characteristics;
  • nomenclature code;
  • sterility, measuring, reusable-surgical, implantable and active-device flags where applicable;
  • authorised representative and notified-body details where applicable; and
  • certificate references and market status.

Review those fields against the declaration of conformity, label, UDI issuing-agency record, technical documentation and certificate. A typo in a public database is much harder to explain and correct than a typo in a draft worksheet.

Step 3: register a regulation device

For MDR or IVDR devices, EUDAMED requires both a unique Basic UDI-DI and a unique UDI-DI. You cannot register only the Basic UDI-DI. The practical sequence is:

  1. Sign in and choose the correct manufacturer actor if your account belongs to more than one actor.
  2. Open the UDI/Devices module and start a regulation-device registration.
  3. Enter the Basic UDI-DI data and save the draft.
  4. Add the first UDI-DI and complete its identification, characteristics, market and packaging information.
  5. Run an independent review while the record is still in draft. Compare the on-screen summary with the controlled data sheet.
  6. Submit or register the record using a user with the required profile. Preserve evidence of the review and submission in your QMS.

Do not confuse the two identifiers. The Basic UDI-DI groups devices with the same intended purpose, risk class and essential design/manufacturing characteristics; it does not appear on the label. The UDI-DI identifies a specific device configuration and is part of the UDI carried on the label, subject to the regulatory rules.

Updating data without losing control

EUDAMED records move through states such as draft, submitted and registered. The default list may show drafts, which makes registered records look as if they disappeared. Change the filters before creating a duplicate.

For a registered record, first decide whether the change is allowed as an update, requires a new version, or requires a new UDI-DI under the UDI rules. Make the same decision in your design/change-control process. Record the reason, affected devices, effective date, approver and EUDAMED evidence. The database should be an output of controlled change, not a parallel source of truth.

Searching the public site

The public device search is useful for checking what patients, customers and competitors can see. Start narrow:

  1. Use an exact UDI-DI, Basic UDI-DI or SRN when you have one.
  2. For names, try the trade name before adding several other filters.
  3. Clear old filters between searches; the interface can preserve state.
  4. Open the Basic UDI-DI and UDI-DI levels separately. They describe different levels of the device family and configuration.
  5. Export or capture the result needed for your review rather than relying on browser history.

If the site returns an internal error, preserve your draft data and retry later. Do not respond to a transient search failure by creating another actor or device.

Common EUDAMED failure modes

  • Duplicate actor: someone registers a new organisation instead of requesting access to the validated actor.
  • Wrong role: an importer role is confused with a manufacturer role, or one registration is assumed to cover several roles.
  • Single administrator: nobody can approve access after the original LAA leaves.
  • Wrong identifier level: family-level Basic UDI-DI data and version-level UDI-DI data are mixed.
  • Uncontrolled free text: intended purpose or names diverge from the technical documentation and label.
  • Duplicate device: a registered record is hidden by a draft-state filter and is entered again.
  • Browser-only evidence: no reviewed source dataset, approval or submission record is retained in the QMS.

A small SOP beats an 82-page panic

Your EUDAMED procedure does not need to reproduce every screen. It should define roles, source records, review and approval, submission evidence, periodic reconciliation, access review, incident handling and change control. Link to the Commission's maintained instructions for the click-by-click workflow so your SOP does not become obsolete after every interface release.

Use the European Commission's EUDAMED Information Centre for current role-specific instructions and the Commission's EUDAMED overview for module status. The legal trigger for the 2026 transition is explained in the Commission's mandatory-use announcement.

For the underlying identifier concepts, see our practical introduction to MDR UDI. Verify the current Commission guidance and your competent authority's instructions for edge cases before submitting production data.

Dr. Oliver Eidel

Dr. Oliver Eidel

I’m a medical doctor, software engineer and regulatory dude. I’m also the founder of OpenRegulatory.

Through OpenRegulatory, I’ve helped 100+ companies with their medical device compliance. While it’s also my job that we stay profitable, I try to dedicate a lot of my time towards writing free content like our articles and templates. Maybe that will make consulting unnecessary some day? :)

If you’re still lost and have further questions, reach out any time!
More about me

Join the discussion. Leave a comment. Guest comments are welcome — add your email to get reply notifications.

No comments yet. Be the first to share your thoughts.

Congratulations! You read this far.

Get notified when we post something new. Sign up for our free newsletter — no spam, only regulatory rants. Unsubscribe anytime.

No spam, only regulatory rants. Unsubscribe anytime.