Select your language

Article

Team-NB BPG Version 4: What the Update Reveals About Evolving Notified Body Expectations

Posted on the 10th September 2026

1

In April 2026, The European Association of Medical Devices Notified Bodies (Team-NB),  published Version 4 of its Best Practice Guidance (BPG) for the Submission of Technical Documentation under Annex II and III of Regulation (EU) 2017/745 (MDR). 

Although the guidance is not legally binding, it remains one of the most influential documents available to manufacturers preparing MDR technical documentation because it represents a consolidated view of expectations across notified bodies.

Note: Team-NB Best Practice Guidance documents do not create new legal requirements under the MDR. However, they provide valuable insight into current notified body expectations and common issues identified during conformity assessment activities.

At first glance, the increase from 79 pages in Version 3 to 92 pages in Version 4 may appear to be little more than an expansion of administrative detail. However, focusing on these additions in isolation risks missing the more important story.

The most significant value of Version 4 is not that it introduces entirely new regulatory requirements. Rather, it provides insight into where notified bodies continue to encounter deficiencies, where scrutiny is increasing, and what manufacturers should prioritise if they want to reduce review cycles, minimise non-conformities, and improve the efficiency of MDR conformity assessments.

A Move from Compliance to Demonstrable Compliance

One of the clearest themes running through Version 4 is the increasing emphasis on the quality, structure and traceability of technical documentation.

Manufacturers have always been required to demonstrate compliance with MDR Annex II and Annex III. What Version 4 makes clear is that how that compliance is presented is becoming almost as important as the underlying evidence itself.

The guidance introduces more detailed expectations around:

  • Technical documentation structure
  • File organisation and naming conventions
  • Document consistency
  • Version control
  • Traceability between technical documentation elements


Manufacturers are encouraged to align documentation structures with the principles of the IMDRF Regulated Product Submission (RPS) framework, while practical expectations have become more specific. Version 4 recommends limiting PDF size, avoiding scanned documents where possible, bookmarking PDFs, and using consistent naming conventions throughout the submission.

The guidance also highlights increasingly common administrative issues encountered during MDR reviews. Examples include excessive file path lengths, inconsistent terminology across documents, and discrepancies in intended purpose statements appearing in different sections of the technical file.

These may seem minor, but they are often responsible for unnecessary review questions and delays.

The Growing Importance of Consistency

Version 4 also places repeated emphasis on alignment across the technical file. 

The guidance repeatedly highlights discrepancies between:

  • Intended purpose statements
  • Labeling
  • Instructions for use
  • Clinical evaluation documentation
  • Risk management outputs
  • Post-market documentation


This is particularly evident in the expanded "Common Pitfalls" sections, which highlight situations where information exists in multiple locations but is presented differently.

The underlying message is clear: notified bodies increasingly expect manufacturers to treat the technical documentation as an integrated system rather than a collection of individual documents.

Many of these issues are unlikely to generate major safety concerns on their own, but they can trigger significant numbers of review questions and can undermine confidence in the overall submission.

Expanded Regulatory References

Version 4 introduces several additional regulatory and technical references that were either absent or received less attention in Version 3.

These include:

  • Harmonized standards
  • The Blue Guide on the implementation of EU product rules
  • Commission Implementing Regulation (EU) 2025/1234, amending Implementing Regulation (EU) 2021/2226 on electronic instructions for use (eIFU)
  • REACH requirements
  • Substances of Very High Concern (SVHC)
  • European Chemicals Agency (ECHA) requirements
  • Classification, Labeling and Packaging (CLP) requirements
  • IMDRF guidance documents                   


While relatively few manufacturers will be directly impacted by all of these references, their inclusion reflects a broader expectation that MDR compliance should be considered within the wider European regulatory landscape.

Device Description and Intended Use: Greater Detail Expected

Version 4 significantly expands expectations regarding device description and intended use.

Manufacturers are now expected to provide greater clarity regarding:

  • Intended medical purpose
  • Intended patient population
  • Intended user profile
  • Intended use environment
  • Anatomical site of use
  • Operating principle


The guidance aligns these expectations with usability engineering principles and emphasises that any claimed patient populations, use environments or user groups should be supported by appropriate evidence.

This reflects a growing tendency among notified bodies to challenge broad intended-use claims that are not adequately supported by pre-clinical, clinical or usability data.

For many manufacturers, this may require a tighter alignment between intended use statements, usability engineering files, clinical evaluations and risk management documentation.

Labeling and Instructions for Use

Version 4 also reinforces expectations around labeling and instructions for use.

Where a device is supplied without an IFU, leaflet or other instructions, manufacturers are expected to provide the information required by MDR Annex I so that the absence of a conventional IFU does not create a gap in the safety and performance information available to users.

The guidance also highlights language consistency and market-specific language requirements as areas that frequently create challenges during reviews.

Software, AI and Cybersecurity Continue to Move Centre Stage

Perhaps the most notable technical development within Version 4 is the increased attention given to software-based devices.

The guidance expands expectations relating to:

  • Software architecture
  • Software version control
  • Software lifecycle documentation
  • Software validation
  • Software traceability
  • Cybersecurity


None of these topics are entirely new under MDR. However, the level of detail included in Version 4 suggests that software documentation remains one of the more challenging areas during conformity assessment.

Artificial Intelligence and Machine Learning

One of the most significant additions is dedicated guidance for AI and machine learning-enabled devices.

Manufacturers are now expected to provide substantially more information on:

  • Training datasets
  • Testing datasets
  • Validation datasets
  • Data quality
  • Representativeness
  • Bias management
  • Fairness
  • Transparency
  • Human oversight
  • Technical robustness and safety
  • Privacy and data governance
  • Accountability


Importantly, these expectations extend beyond traditional software validation and reflect a broader concern with how AI-enabled devices are developed, controlled and maintained throughout their lifecycle.

The guidance references principles consistent with the EU's broader approach to trustworthy AI and signals increasing scrutiny of AI-enabled medical devices by notified bodies.

While MDR itself was not drafted specifically with modern AI systems in mind, Version 4 demonstrates that notified bodies are already adapting their expectations to address emerging technologies.

Cybersecurity Is Becoming a Core Safety Issue

Historically, cybersecurity was often treated as an IT or post-market issue. Increasingly, however, regulators and notified bodies view cybersecurity as a fundamental aspect of device safety and performance.

Version 4 reflects this shift by embedding cybersecurity within broader discussions of software documentation, verification and validation.

For manufacturers, this means cybersecurity can no longer be treated as a standalone activity. Instead, it is increasingly expected to form part of the overall safety case for the device.

Design and Manufacturing: More Evidence Required

The guidance expands expectations surrounding manufacturing validation.

Manufacturers are now expected to provide validation documentation for all critical validated processes, including outsourced activities where relevant.

Additional emphasis is placed on:

  • Worst-case justification
  • Sample-size rationale
  • Site-specific validation
  • Process consistency across manufacturing locations


A recurring theme throughout Version 4 is the expectation that justification should be risk-based and clearly documented.

The guidance also introduces dedicated "Common Pitfalls" sections highlighting issues frequently identified during assessments, including incomplete subcontractor information, insufficient manufacturing flow descriptions and missing validation documentation.

Risk Management: Improved Traceability

Version 4 strengthens expectations for traceability between:

  • Hazards
  • Risks
  • Risk control measures
  • Verification activities
  • Validation activities


The document places greater emphasis on alignment with ISO 14971 terminology and concepts.

Another notable addition is the expectation that risk management should address software updates and operating system changes where relevant.

This reflects the increasingly dynamic nature of modern medical devices and the challenges associated with software maintenance throughout the product lifecycle.

Biocompatibility and Biological Safety

The biocompatibility section has been substantially expanded.

Manufacturers are expected to consider:

  • Device families
  • Cleaning agents
  • Device-contacting materials
  • Foreseeable misuse
  • Interactions with other devices
  • Interactions with medicinal products


The guidance emphasises biological risk estimation and stronger justification regarding biological equivalence and biological testing strategies.

It also sets out more detailed expectations for devices incorporating materials of human or animal origin, including sourcing, processing and traceability information, together with risk assessments covering microbial, viral and prion safety.

Notified bodies are increasingly looking for evidence that biological risks have been systematically identified, evaluated and controlled throughout the product lifecycle.

More Detailed Expectations for Validation and Testing

Several areas of product verification and validation receive additional attention.

Examples include:

  • Packaging validation
  • Shelf-life studies
  • Stability studies
  • Transport validation
  • Sterilisation validation
  • Reprocessing validation


Version 4 makes clear that transport and storage validation should align with the environmental conditions defined within the device specifications.

The guidance also places greater emphasis on representative sample selection and the justification of worst-case testing approaches.

Another recurring theme is the expectation that manufacturers provide concise executive summaries of testing activities rather than relying solely on lengthy underlying reports.

Clinical Evaluation and Post-Market Surveillance

Version 4 recommends that the Summary of Safety and Clinical Performance (SSCP), where applicable, should be reviewed at least annually in conjunction with PMCF and PSUR updates.

The guidance also makes clear that PSURs form a key component of the overall technical documentation package and should remain fully aligned with the wider body of supporting evidence.

What Does Version 4 Tell Us About Notified Body Expectations?

Taken as a whole, Version 4 provides a useful window into current notified body thinking.

The document suggests that recurring concerns are less about fundamental MDR compliance and more about:

  • Documentation quality
  • Traceability
  • Consistency
  • Software governance
  • AI oversight
  • Validation rationale
  • Biological risk justification


The substantial expansion of the "Common Pitfalls" sections strongly suggests that many conformity assessment challenges arise not because manufacturers lack evidence, but because the evidence is incomplete, poorly connected, weakly justified or inconsistently presented.

For manufacturers, this may be one of the most valuable insights in the entire document.

What Should Manufacturers Do Next?

Manufacturers planning future MDR submissions should avoid viewing Version 4 as simply another guidance update.

Instead, it should be treated as an indication of where notified bodies are concentrating review effort and where technical documentation deficiencies continue to emerge.

Particular attention should be paid to:

  • Software and AI documentation
  • Cybersecurity evidence
  • Intended purpose consistency
  • Risk management traceability
  • Validation justification
  • Biological evaluation rationale
  • Common pitfalls highlighted throughout the guidance


Organizations that previously structured technical documentation using Version 3 should consider performing a targeted gap assessment against these areas rather than focusing solely on individual wording changes.

Importantly, the extent of any assessment or remediation activity is likely to depend on several factors, including:

  • Device type and intended purpose
  • Technology and software content
  • Risk classification
  • Whether AI or machine-learning functionality is incorporated
  • The maturity and quality of the existing technical documentation
  • Previous notified body feedback and certification history


For some manufacturers, the impact may be limited to document restructuring, traceability improvements or clarification of existing evidence. For others, particularly those developing software-driven or AI-enabled technologies, more substantial updates may be required to address the expanded expectations outlined in Version 4.

Rather than treating V4 as a checklist of new requirements, manufacturers should view it as an opportunity to evaluate whether their current technical documentation supports efficient review and clearly demonstrates compliance with MDR Annex II and Annex III requirements.

Conclusion

The guidance does not fundamentally change the MDR requirements manufacturers must satisfy. What it does provide is a clearer picture of how notified bodies expect compliance to be demonstrated in practice.

The update suggests an ongoing shift towards more structured, traceable and evidence-driven submissions, alongside increasing scrutiny of software, AI and cybersecurity. Perhaps most importantly, it highlights the recurring deficiencies that continue to delay conformity assessments.

The practical implications of Version 4 will not be the same for every manufacturer. The extent of any remediation effort will depend on the nature of the device, its technology, risk classification and the maturity of the existing technical documentation. Manufacturers with well-structured, traceable and up-to-date technical files may find only limited changes are required, whereas others may identify gaps that could result in additional notified body questions, non-conformities or longer review cycles.

For manufacturers, the key lesson is that successful MDR submissions increasingly depend not only on having the right evidence, but on presenting that evidence in a way that is coherent, traceable and readily assessable. In that respect, Version 4 is less a collection of new requirements and more a guide to avoiding the issues that notified bodies continue to encounter most frequently during technical documentation reviews.

G&L Scientific offers support with technical documentation gap assessments, remediation activities and MDR submission readiness reviews to help manufacturers align existing technical documentation with evolving notified body expectations and reduce the risk of unnecessary review cycles, non-conformities and certification delays.

Mike Picchioni is Associate Director, Regulatory Affairs at G&L Scientific

Useful References

  1. Team-NB. Best Practice Guidance for the Submission of Technical Documentation under Annex II and III of Regulation (EU) 2017/745 (MDR), Version 4. April 2026.
  2. Team-NB. Best Practice Guidance for the Submission of Technical Documentation under Annex II and III of Regulation (EU) 2017/745 (MDR), Version 3. April 2025.
  3. Regulation (EU) 2017/745 on Medical Devices (MDR).
  4. The Blue Guide on the implementation of EU product rules.
  5. Commission Implementing Regulation (EU) 2025/1234 amending Implementing Regulation (EU) 2021/2226 concerning electronic instructions for use.
  6. Regulation (EC) No 1907/2006 (REACH).
  7. Regulation (EC) No 1272/2008 (CLP).
  8. EN 62304: Medical Device Software – Software Life Cycle Processes.
  9. ISO 14971: Medical Devices – Application of Risk Management to Medical Devices.
  10. ISO 10993-1: Biological Evaluation of Medical Devices.
  11. IMDRF Regulated Product Submission (RPS) Guidance Documents.