MDCG 2025-4: Medical device software apps on online platforms, explained
How MDR/IVDR and Digital Services Act responsibilities apply when medical device software apps are offered through app stores and online platforms.
MDCG 2025-4 explains who is responsible when medical device software is offered through an app store or other online platform. A manufacturer places the app on the market by uploading it. A platform may remain an intermediary, but can become an MDR/IVDR distributor or importer when it directly supplies the software. Either way, medical-device listings need specific regulatory information before download.
Who this applies to
This guidance applies to manufacturers offering medical device software (MDSW) through app stores, software marketplaces or other online platforms. It also applies to platform operators, including platforms established outside the EU, and to economic operators deciding who performs the importer or distributor role.
The guidance reads the MDR and IVDR together with the Digital Services Act (DSA). The two regimes do different jobs: the MDR/IVDR governs the device and its supply chain, while the DSA governs the platform's intermediary service, trader traceability, notices about illegal content and the way listings are presented.
Uploading an app is placing it on the market
When a manufacturer uploads an MDSW app to an online platform so EU users can obtain it, that is placing the device on the market. Making the app available through the platform is a supply of the device, even when it is free of charge.
The delivery mechanism does not dilute the manufacturer's obligations. The app still needs the correct conformity assessment, CE marking, UDI where applicable, registration, labelling and instructions. Updates also remain regulated device changes; calling them “app updates” does not create a separate, lighter pathway.
Is the platform an intermediary, distributor or importer?
The platform's role depends on what it actually does, not what its terms and conditions call it.
Platform model |
Likely regulatory position |
|---|---|
Hosts a third-party manufacturer's app and connects the trader with the user |
Generally an online intermediary/marketplace under the DSA, not automatically an MDR/IVDR distributor or importer |
Obtains the app from the manufacturer and directly supplies or transfers the right to use it to the customer |
May be a distributor and must meet MDR Article 14 / IVDR Article 14 obligations |
EU platform directly makes a third-country manufacturer's app available in the Union |
May be the importer and must meet MDR Article 13 / IVDR Article 13 obligations |
Uses different arrangements for different apps |
Can have a hybrid role and must assess each supply model separately |
A platform that remains an intermediary still has DSA responsibilities. These can include verifying and displaying trader information, providing notice-and-action mechanisms, designing the interface so traders can supply required compliance information, and making reasonable efforts to check that information. Very large online platforms also have additional systemic-risk duties.
For a non-EU manufacturer, the usual authorised-representative requirement remains. The existence of an app store does not fill that role.
What the product page should show
The guidance expects users to receive essential device information before they decide to download the app. A medical-device listing should make the following readily accessible:
- the device name or trade name;
- the manufacturer's name, address and Single Registration Number (SRN), where applicable;
- whether it is a medical device or IVD, together with its indication and intended purpose;
- warnings, contraindications and other information needed for safe use;
- a link to the electronic instructions for use;
- the UDI-DI;
- where applicable, the authorised representative, notified-body identification number and certificate information; and
- operating-system, hardware and information-security requirements needed to run the software safely.
Platforms should distinguish medical device apps from generic health, wellness and lifestyle products. A dedicated medical-device category and filters make the regulatory status clearer and reduce the risk that users treat an unregulated wellness app as equivalent to CE-marked MDSW.
What this means for you, practically
- Map the transaction, not just the interface. Record who contracts with the user, who grants the licence or access right, who receives payment, and who first supplies a third-country app in the EU. That determines the economic-operator roles.
- Build a release gate for store listings. Do not let marketing upload screenshots and a short description without regulatory review. The listing is part of how the device is placed and presented on the market.
- Create a minimum listing dataset. Store the intended purpose, manufacturer and authorised-representative details, UDI-DI, certificate data, eIFU link, warnings and technical requirements in a controlled source that can feed every platform.
- Plan app updates through change control. Assess whether each release affects intended purpose, performance, cybersecurity, clinical evidence, UDI data or conformity assessment before it reaches the store.
- Contract for platform cooperation. Your agreement should cover listing corrections, complaint and incident forwarding, recalls or access restriction, records, cybersecurity notices and the speed at which unsafe software can be removed.
Turn templates into working QMS documents.
Start from OpenRegulatory templates, fill them out with AI assistance, and keep them connected to your QMS in Formwork.