DEV Community

Priya Nair
Priya Nair

Posted on

Miss a PSUR and your surveillance close‑out can stall — who’s actually tracking your calendar?

Miss your PSUR and the notified body will notice. I don’t mean a gentle nudge — I mean surveillance close‑out stalled, paperwork reopened, and yes, the CE certificate itself pushed onto a very uncomfortable timeline.

I work on CE marking and post‑market surveillance for Class IIa/IIb devices. Over the last few years I have watched the same issue crop up at different manufacturers: the technical and clinical teams are focused on vigilance and CAPAs, QA owns the audits, but nobody owns the PSUR schedule. The regulatory text is clear — per Article 86 MDR the Periodic Safety Update Report is required for class IIa, IIb and III devices — but in practice the cadence and the handoffs are where it breaks.

The cadence trap (the simple rule nobody remembers under pressure)

  • Class IIa: PSUR every 2 years.
  • Class IIb and III: PSUR annually.
  • PSURs are submitted to your notified body as part of surveillance (and form part of what the NB needs to close a surveillance cycle).

That’s the rule. In practice this means:

  • You can have staggered schedules across product lines and DIs, so it’s easy to lose sight of which device is due when.
  • If your NB expects a PSUR to complete a surveillance activity and it’s missing, they will not close the surveillance — and that administrative pause can cascade into certificate timelines.

To be fair, notified bodies are doing their job: they need evidence you’re monitoring benefit–risk over time. But granted, the downstream effect — halted surveillance close‑outs and potential certificate risk — is a consequence many teams didn’t budget for.

What I see go wrong

  • No single owner. PSUR tasks are split between RA, clinical, PMS and QA with no central checklist.
  • Calendar fragmentation. Teams use Outlook, spreadsheets, and “memory” rather than a single source of truth mapped to DIs/UDIs.
  • Late inputs. Vigilance, PMCF summaries, and CAPA actions arrive after the draft PSUR is due.
  • NB expectations differ. Some notified bodies want the PSUR with the surveillance pack; others will accept it a few weeks later — but you can’t rely on goodwill.

I’ve seen notified bodies delay surveillance close‑out because a PSUR was missing or incomplete. The consequence: follow‑up requests, extra NB time charges, and, in the worst cases, extension of administrative review that eats into your certificate validity planning.

Practical checklist to avoid the trap

Make the PSUR an owned, auditable process in your QMS. Minimum items I enforce:

  • Single master PSUR calendar:
    • Map by device, DI/UDI, classification and cadence.
    • Assign a named owner (not “clinical team” — an actual person).
  • Trigger points and lead times:
    • 90 days: initial data collection starts (vigilance, complaints, PMCF interim).
    • 60 days: draft PSUR ready for internal review.
    • 30 days: final for management sign‑off and NB submission packaging.
  • Pre‑submission checklist:
    • Vigilance summary since last PSUR (including trends).
    • PMCF results and ongoing plan status.
    • Benefit–risk conclusion and any new signals.
    • Summary of FSCA/field actions and CAPA status.
  • Integration with change control and CAPA:
    • PSUR findings that require action should open CAPAs automatically or flag existing CAPAs for linkage.
    • Link CAPAs to risk controls — CAPA‑driven risk assessment must be traceable.
  • Communication with your notified body:
    • Confirm preferred submission timing and format at least 3 months in advance.
    • If late, notify NB immediately with a mitigation plan — silence is not in your favour.

Tools that actually help (not buzzwords)

You don’t need magic, you need connected workflow:

  • A single calendar linked to device records and UDIs.
  • Document control where PSUR drafts are versioned and reviewers are tracked.
  • Traceability between PSUR, vigilance records, PMCF and CAPA.
  • Reminders that create tasks (not just emails) for owners.

In practice this means using an eQMS or QMS workflow that supports:

  • automated CAPAs (or automated creation prompts) when PSURs identify issues,
  • CAPA‑driven risk assessment templates,
  • reviewability (audit trail of who edited what and when),
  • and connected workflow so the clinical, QA and RA inputs live in one place.

I’m pragmatic about AI: AI‑assisted drafting can speed the first pass, but the clinical owner still needs to validate the benefit–risk text and the data sources. Controlled assistance, not magic.

If you’ve already missed one

  • Don’t hide it. Notify your NB immediately and explain the remedial steps and timeline.
  • Prioritise the PSUR — get interim data, close urgent CAPAs, and submit as soon as you have a coherent benefit–risk statement.
  • Document root cause: was it process design, resource shortage, or tool failure? Open a CAPA and map the corrective action to prevent recurrence.

Notified bodies will vary in tone. Some will accept a close‑in‑time submission and proceed; others will hold the surveillance until they have the full PSUR. I’ve seen the latter. It’s not punitive; it’s procedural. But it’s also avoidable.

My rule of thumb

If your next NB surveillance is within six months, the PSUR clock is now your critical path. Start the PSUR sprint three months out. Start the data harvest four months out.

You’re building evidence that your device remains safe and performs as intended. Treat PSURs as part of your product lifecycle, not as an audit checkbox.

Who’s tracking your PSUR calendar, and what process or tool changed that for you?

Top comments (0)