MDCG 2022-21: Periodic Safety Update Reports (PSUR), explained

What goes into a PSUR, how often to update it, and how notified bodies assess it.

Current Published August 12, 2026 Reviewed by Dr. Oliver Eidel

If you manufacture a class IIa, IIb or III medical device, your PMS data must periodically end up in a PSUR. MDCG 2022-21 explains which devices need one, whether the cycle is annual or every two years, how devices may be grouped, and what the report must contain. The important bit: a PSUR is not a data dump. It must say what the data means for your device's benefit-risk profile.

Who this applies to

You need a Periodic Safety Update Report (PSUR) for MDR class IIa, IIb and III devices, including corresponding custom-made devices and legacy devices still placed on the market under an MDD/AIMDD certificate. Class I devices get a shorter Post-Market Surveillance Report under Article 85 instead.

This guidance only covers medical devices under the MDR. It does not cover IVDs under the IVDR.

How often, and where does it go?

The schedule depends on risk class and whether the device is implantable:

Device

Minimum frequency

What you do with the PSUR

Class IIa, non-implantable

Every two years

Keep it available to your notified body and competent authorities

Class IIa, implantable

Every two years

Submit through EUDAMED once the relevant module applies

Class IIb, non-implantable

Annually

Keep it available to your notified body and competent authorities

Class IIb, implantable and class III

Annually

Submit through EUDAMED once the relevant module applies

Legacy class IIa, IIb and III devices

Based on the MDD/AIMDD class above

Do not upload to EUDAMED; make it available to the notified body and competent authorities

Until EUDAMED's post-market surveillance and vigilance module is available, agree the submission route with your notified body for reports that will eventually require upload.

Your data periods must be contiguous: no gaps and no overlapping months. The cycle starts at MDR certification for a new MDR device, or from 26 May 2021 for a legacy device. The obligation does not simply stop when you discontinue sales or the certificate expires. It continues until the lifetime of the last device placed on the market has been covered.

What goes into the PSUR?

The PSUR is a stand-alone summary of what your PMS system found during the reporting period. It should be understandable without opening ten other documents, while referencing the supporting records where a reviewer can inspect the detail.

Section

What a reviewer is looking for

Device scope

The devices, Basic UDI-DIs, intended purposes, market status, and any changes since the previous PSUR

Sales and exposure

Units placed on the market, estimated patient exposure, usage frequency, and relevant population characteristics

Vigilance and CAPA

Serious incidents, trends, FSCAs, and safety- or performance-related corrective and preventive actions

Other PMS data

Complaints and feedback, literature, registries, public databases, similar-device information, and other real-world data

PMCF

The main findings from general and specific PMCF activities, with reference to the PMCF evaluation report

Conclusions

Data limitations, new or emerging risks, whether benefits were achieved, the resulting benefit-risk determination, and actions taken

Use rates as well as raw counts wherever possible. Five complaints mean something very different across 50 devices and 50,000 devices. The guidance also asks you to compare the current period with earlier periods and, where relevant, split EEA/Turkey/Northern Ireland data from worldwide data. Serious incidents should use IMDRF adverse-event terminology where available.

Grouping devices in one PSUR

You may cover several Basic UDI-DIs or device families in one PSUR, but you need a reason why the grouping makes sense and the data must still let a reviewer see how each device performs. All grouped devices must be assessed by the same notified body.

Choose one leading device: the highest-risk device, or one you nominate where several share the highest class. Its risk class and certification schedule drive the frequency, reporting period, and submission route for the whole group. You may add or remove other devices later, but you cannot replace the leading device without starting a new PSUR.

What this means for you, practically

  1. Set the reporting date once. Work backwards to define the collection period, then keep every later period contiguous. Put the deadline in your QMS calendar before the first device ships.
  2. Build the tables before you need the report. If complaint categories, sales units, regions, and denominators change every year, trend analysis becomes guesswork.
  3. Analyse; don't just list. For every signal, ask whether it changes a known risk, reveals a new risk, affects a particular population, or shows that an intended benefit was not achieved.
  4. Explain missing data. If the PMS plan names a dataset and the PSUR omits it, the guidance expects a justification. Silence looks like you forgot it.
  5. Close the loop. A PSUR conclusion should visibly feed your risk management file, clinical evaluation, PMCF, labelling, and CAPA system. "Benefit-risk remains unchanged" is a conclusion to support with evidence, not boilerplate for the final page.

Turn templates into working QMS documents.

Start from OpenRegulatory templates, fill them out with AI assistance, and keep them connected to your QMS in Formwork.

app.openregulatory.com / cardio-monitor / audit
Cardio Monitor · v2.4

Audit readiness

100%
32 SOPs signed QMS
47 requirements traced Techdoc
18 risks mitigated Risk
21 CFR Part 11 ready Compliance
Ready for ISO 13485 audit