DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

The CER grew. The clinical evidence didn't. We let the report outpace the data.

The CER arrived on a Friday. 200 pages, polished, confident — the kind of document you can hand to a notified body and not lose sleep. The literature search that backed the equivalence claim? A 2019 copy-paste that had clearly been carried across three device families.

What MDR actually asks for, in plain language

Under EU MDR 2017/745, the Clinical Evaluation Report (CER) is the document that demonstrates your device meets the General Safety and Performance Requirements (GSPRs) on the basis of clinical evidence. It is not a marketing document. It is not a literature review dressed up in regulatory language. It is supposed to be the reasoned argument that the device is safe and performs as intended, supported by data that is sufficient in quantity and quality.

MDCG 2020-5 (on clinical evaluation) and MDCG 2020-13 (on clinical evaluation assessment by notified bodies) made this clearer than the old MEDDEV 2.7/1 rev 4 ever did. The CER is expected to be a living document, updated through the device lifecycle, fed by post-market surveillance, post-market clinical follow-up (PMCF), and complaint data. The intent is that the evidence and the report grow together.

That is the theory.

What I see from the supplier side

I work at a contract manufacturer. We do not write CERs. But we supply the post-market data that ends up in them — complaint trends, lot histories, process deviations, supplier non-conformances. And we read a lot of CERs from our OEM customers.

What I have learned is that the CER and the evidence it summarises are not the same thing. The CER is a document. The evidence is a state of the world. The two can drift.

The pattern looks like this:

  • A Class IIb device with a pre-MDR CE mark gets a new CER for MDR. The CER is 180 pages. The clinical literature on the device itself is a handful of small studies, mostly sponsored.
  • The equivalence justification names a competitor device. The competitor's clinical data is summarised in three paragraphs, with the underlying studies appended as a bibliography. The bibliography is impressive. The actual reading of those studies is often cursory.
  • PMS data is in there — complaint rates, trend reports, vigilance cases. But the analysis often stops at "within expected rates" without explaining what "expected" means for this device, in this patient population, on this indication.
  • The PMCF section says "a PMCF study is planned." The planned study has been planned for three CER versions.

The document is professional. The notified body may accept it. The device is deemed safe. The evidence has not really grown.

Why we let the report outpace the data

I do not think anyone is being dishonest. I think the structure of the regulation makes it easy to do this in good faith.

The CER has to demonstrate conformity now — for the current submission, for the current audit cycle. The evidence is generated over years, across a lifecycle, with all the friction that clinical research involves: ethics approvals, site contracts, patient recruitment, follow-up windows. A document can be drafted in weeks. A meaningful PMCF study cannot.

So we do the only thing we can. We write a thorough, well-structured CER that says what we can say today, and we plan the work that will substantiate the harder claims tomorrow. The problem is that "planned" can become a permanent state. The CER keeps getting updated. The PMCF study stays "in planning." The next revision of the CER describes the same planned study with a slightly later start date.

What I would do differently, in three practices

If I were writing CERs — or supervising the people who do — here is what I would want as standard practice:

  • Treat the CER as a record of what you know, not a plan for what you will know. Every claim should be traceable to a data source that exists today, not a study that will be done. Aspirations belong in the PMCF plan, clearly marked as gaps.
  • State the gaps explicitly. MDCG guidance allows for gaps to be identified, with justification. A CER that says "we have no data on long-term implant performance beyond 24 months" is more defensible than a CER that does not mention the gap at all.
  • Make the equivalence argument honest. If you are claiming equivalence to a competitor device, you need to be able to defend the three criteria (clinical, technical, biological) with specifics. A bibliography is not an equivalence argument.

From the supplier side, the one thing I would ask of every OEM I work with: share the CER's gap list with us. We sit on a lot of manufacturing and complaint data. If the OEM's PMCF plan has a gap, we may be able to help close it — and we should know what the regulator will eventually want to see.

The honest version of the safety claim

Clinical evaluation exists so a device can be deemed safe while the evidence matures. That is the regulatory bargain. The device gets to market. The report gets to grow. The evidence, ideally, catches up.

The failure mode is when the report grows but the evidence does not — when the document gets more polished while the underlying data stays thin. The device is still deemed safe. The CER says so. The notified body accepted it. But "deemed safe" and "demonstrated safe" are not the same sentence, and the gap between them is where post-market problems live.

How do you keep that gap honest in your own CERs — what does your team do to make sure the report and the evidence are moving together, not in opposite directions?

Top comments (0)