Five years into MDR, the question I get most often from small Class II teams is not "which eQMS is best". It is closer to: what is the smallest thing we can buy that will still pass a notified body audit when we get there, and that will not make us re-implement the whole system in eighteen months.
That is the right question. The wrong answer is the demo-driven one — picking whatever the salesperson showed you with the slickest workflow. The right answer is a shortlist built against what ISO 13485:2016 and MDR Annex IX actually expect from your QMS, scaled to where your team is today, with a credible growth path to where MDR will push you tomorrow.
Here is the practitioner checklist I walk small teams through.
What you actually need digitised before your first notified body audit
For Class IIa under MDR, conformity assessment typically runs through Annex IX (quality management system and assessment of technical documentation). In practice this means your QMS has to demonstrate control over at least:
- Document and record control (ISO 13485 clauses 4.2.4 and 4.2.5)
- Design and development, including the design history file (clause 7.3, MDR Annex II)
- CAPA and nonconforming product (clauses 8.5.2 and 8.3)
- Internal audit and management review (clauses 8.2.2 and 5.6)
- Supplier control and incoming product verification (clause 7.4)
- Post-market surveillance, including PMS, PSUR, and PMCF where applicable (MDR Articles 84–86)
You do not need all of this on day one. But the eQMS you shortlist should be able to hold each of these without a custom build.
"Online forms over our existing processes" — what that phrase should mean
The starting position you describe is sensible, and more common than vendors admit. Most Class II SMEs I have worked with have a working QMS on paper or in shared drives. The mistake is treating the eQMS as a reason to rewrite the SOPs.
What you want from a forms-first deployment:
- The system mirrors your current SOPs. You upload the existing forms; the eQMS provides workflow, signatures, and an audit trail.
- Approval routing matches your actual org chart, not an idealised one.
- Training records are linked to documents, so a revision automatically re-assigns training tasks.
- You can extract a clean PDF or XML export on demand for your notified body reviewer.
If a vendor pushes you into a process redesign before you can go live, that is a sign their product assumes you have a larger team than you do.
Shortlist criteria that predict a clean audit later
When I evaluate eQMS for a Class II SME, I score against five criteria that have actually mattered in audit findings:
- ISO 13485:2016 clause coverage you can see in the product, not in marketing. Ask the vendor to show you, not tell you.
- Document control with version history, approval workflow, and a real audit trail. Audit trails must be tamper-evident and time-stamped.
- A CAPA workflow that can be linked upstream to complaints and risk, and downstream to change controls and design history. This is the connected workflow that audit findings hinge on.
- Training records tied to documents and roles, with completion evidence.
- A clear validation story for electronic records — at minimum EU GMP Annex 11 style controls, even if you are not claiming 21 CFR Part 11 compliance.
Granted, not every vendor will be honest about which ISO clauses their out-of-the-box workflows truly cover. Ask for a mapping document before signing anything.
Red flags worth walking away from
In demos, watch for:
- "AI-driven CAPA assistance" with no explainability, no reviewability, no clear human-in-the-loop. If a tool drafts root causes or CAPA plans and you cannot see the reasoning, your notified body will ask, and you will not have a good answer.
- Claims of "full MDR support" but no module for PMS plans, PSUR generation, or PMCF. Those are mandatory under MDR Articles 84–86 for most Class II devices and cannot wait.
- Pricing that punishes you for adding a fourth or fifth seat. Small teams grow; if the marginal seat is punitive, you will be migrating again in two years.
- Mandatory paid implementation services. Templates and configuration should be doable by your own QA/RA lead.
- No clear data residency story. EU/EEA residency is a hard requirement under GDPR for most device data.
To be fair, none of these are deal-breakers on their own. They are signals to ask sharper questions.
The growth path — does it survive the next MDR cycle?
The question that matters in year two is whether your eQMS can keep up with what MDR keeps adding. EUDAMED's UDI module is live in parts and broken in others; PMS expectations are tightening under recent MDCG guidance; PMCF methodology under MDCG 2020-13 is becoming more demanding every notified body cycle.
Shortlist only systems where:
- You can add EUDAMED-compatible UDI assignment and basic submission support later, without re-platforming.
- PSUR generation can pull from PMS, complaints, and CAPA data already in the system — that is what native workflow integration actually means in practice.
- Validation documentation can be updated for each release, not redone from scratch.
If a vendor cannot articulate their roadmap against MDCG guidance from the last eighteen months, they are not investing in MDR compliance at the pace you need.
What I would do if I were starting over
- Map the six ISO clauses above to your current paper process. Pick the eQMS that covers them most cleanly with the least configuration.
- Run a two-week pilot on one process — document control or CAPA, not both — before you commit.
- Get the vendor's clause-mapping document and have your QA lead score it against your last mock audit.
- Ask three reference customers of similar size how their last audit went with that eQMS in place.
The cheapest mistake is buying the wrong system. The second cheapest is buying the right one at the wrong moment, before your team has the bandwidth to validate it properly. A controlled, reviewable deployment beats a fast one every time.
One question back to anyone reading: for those of you who have already gone through a notified body audit on a small eQMS deployment, what was the single ISO 13485 clause that turned out to matter most in the findings, and did your eQMS handle it out of the box or did you bolt something on?
Top comments (0)