MDCG 2022-21: Periodic Safety Update Reports (PSUR), explained
What goes into a PSUR, how often to update it, and how notified bodies assess it.
If you manufacture a class IIa, IIb or III medical device, your PMS data must periodically end up in a PSUR. MDCG 2022-21 explains which devices need one, whether the cycle is annual or every two years, how devices may be grouped, and what the report must contain. The important bit: a PSUR is not a data dump. It must say what the data means for your device's benefit-risk profile.
Who this applies to
You need a Periodic Safety Update Report (PSUR) for MDR class IIa, IIb and III devices, including corresponding custom-made devices and legacy devices still placed on the market under an MDD/AIMDD certificate. Class I devices get a shorter Post-Market Surveillance Report under Article 85 instead.
This guidance only covers medical devices under the MDR. It does not cover IVDs under the IVDR.
How often, and where does it go?
The schedule depends on risk class and whether the device is implantable:
Device |
Minimum frequency |
What you do with the PSUR |
|---|---|---|
Class IIa, non-implantable |
Every two years |
Keep it available to your notified body and competent authorities |
Class IIa, implantable |
Every two years |
Submit through EUDAMED once the relevant module applies |
Class IIb, non-implantable |
Annually |
Keep it available to your notified body and competent authorities |
Class IIb, implantable and class III |
Annually |
Submit through EUDAMED once the relevant module applies |
Legacy class IIa, IIb and III devices |
Based on the MDD/AIMDD class above |
Do not upload to EUDAMED; make it available to the notified body and competent authorities |
Until EUDAMED's post-market surveillance and vigilance module is available, agree the submission route with your notified body for reports that will eventually require upload.
Your data periods must be contiguous: no gaps and no overlapping months. The cycle starts at MDR certification for a new MDR device, or from 26 May 2021 for a legacy device. The obligation does not simply stop when you discontinue sales or the certificate expires. It continues until the lifetime of the last device placed on the market has been covered.
What goes into the PSUR?
The PSUR is a stand-alone summary of what your PMS system found during the reporting period. It should be understandable without opening ten other documents, while referencing the supporting records where a reviewer can inspect the detail.
Section |
What a reviewer is looking for |
|---|---|
Device scope |
The devices, Basic UDI-DIs, intended purposes, market status, and any changes since the previous PSUR |
Sales and exposure |
Units placed on the market, estimated patient exposure, usage frequency, and relevant population characteristics |
Vigilance and CAPA |
Serious incidents, trends, FSCAs, and safety- or performance-related corrective and preventive actions |
Other PMS data |
Complaints and feedback, literature, registries, public databases, similar-device information, and other real-world data |
PMCF |
The main findings from general and specific PMCF activities, with reference to the PMCF evaluation report |
Conclusions |
Data limitations, new or emerging risks, whether benefits were achieved, the resulting benefit-risk determination, and actions taken |
Use rates as well as raw counts wherever possible. Five complaints mean something very different across 50 devices and 50,000 devices. The guidance also asks you to compare the current period with earlier periods and, where relevant, split EEA/Turkey/Northern Ireland data from worldwide data. Serious incidents should use IMDRF adverse-event terminology where available.
Grouping devices in one PSUR
You may cover several Basic UDI-DIs or device families in one PSUR, but you need a reason why the grouping makes sense and the data must still let a reviewer see how each device performs. All grouped devices must be assessed by the same notified body.
Choose one leading device: the highest-risk device, or one you nominate where several share the highest class. Its risk class and certification schedule drive the frequency, reporting period, and submission route for the whole group. You may add or remove other devices later, but you cannot replace the leading device without starting a new PSUR.
What this means for you, practically
- Set the reporting date once. Work backwards to define the collection period, then keep every later period contiguous. Put the deadline in your QMS calendar before the first device ships.
- Build the tables before you need the report. If complaint categories, sales units, regions, and denominators change every year, trend analysis becomes guesswork.
- Analyse; don't just list. For every signal, ask whether it changes a known risk, reveals a new risk, affects a particular population, or shows that an intended benefit was not achieved.
- Explain missing data. If the PMS plan names a dataset and the PSUR omits it, the guidance expects a justification. Silence looks like you forgot it.
- Close the loop. A PSUR conclusion should visibly feed your risk management file, clinical evaluation, PMCF, labelling, and CAPA system. "Benefit-risk remains unchanged" is a conclusion to support with evidence, not boilerplate for the final page.
Turn templates into working QMS documents.
Start from OpenRegulatory templates, fill them out with AI assistance, and keep them connected to your QMS in Formwork.