For years, EUDAMED was the regulatory equivalent of “coming soon.” Now that it’s here, it is operational for medical device and IVD companies that are marketing products in the EU and, for many companies, it is no longer a future project. It is now a part of a company’s daily regulatory operations. Since May 2026, medical device and IVD companies have been expected to use the first four mandatory modules: Actor Registration, UDI/Device Registration, Notified Bodies and Certificates, and Market Surveillance. For any company placing devices on the EU market, the question is no longer whether EUDAMED applies, but rather whether your company has the people, data, systems, and governance in place to comply and scale for the next modules.
Today, medical device and IVD companies should be able to show that EUDAMED registration is embedded into the regulatory release process. Doing so ensures that the company knows which legal entities require actor registration, which devices require UDI/device registration, how certificates are linked to products, how market surveillance data is handled, and who has responsibility for data correction when EUDAMED rejects or flags a record. The EUDAMED process should be a part of your quality system (whether it resides with operations or regulatory affairs) and should be governed through documented responsibilities, source-data controls, change management, and periodic reconciliation against internal product and certificate records.
The current requirements are that new devices placed on the EU market on or after May 28, 2026 must be registered in the applicable EUDAMED modules before market placement. Devices already on the market before that date must be managed through the transition period, with completion expected by late November 2026 for applicable existing and legacy records. In reality, companies should already be operating with an EUDAMED readiness dashboard that tracks:
The European Commission’s own message to industry has been blunt: You can already register! Don’t wait! In other words, the Commission is effectively telling industry not to treat the transition period as extra time to begin preparing. It should instead be viewed as time to complete preparation. The Commission’s message is more than an encouragement; it reflects the operational reality that late upload attempts can expose missing Basic UDI-DI relationships, inconsistent UDI-DI records, incomplete EMDN coding, certificate linkage gaps, and unclear ownership for error correction. Companies that treat EUDAMED as a controlled business process are better positioned than companies trying to upload large portfolios with no connecting processes or delaying uploads until the end of the transition period.
The challenge is not whether companies know that EUDAMED is mandatory and they are not uploading in a timely manner. Rather, the bigger issue is whether their data is compatible and accessible for the upload process. Unfortunately, EUDAMED has little interest in how your data “normally works” internally. EUDAMED records require structured, rule-based data. Upload failures often arise when internal regulatory, ERP, PLM, labeling, and UDI datasets do not match the exact fields, formats, identifiers, certificate references, nomenclature codes, or business rules expected by the system. For many organizations, EUDAMED isn’t creating data problems. It’s revealing them.
Common friction points include:
Even when a company uses bulk XML upload, the upload is only as good as the underlying data model. In practice, EUDAMED is exposing data governance weaknesses that may have existed quietly across disconnected systems for years. This is why ERP and other data systems should be added to the quality system audit schedule, and performing a mock traceability audit with these systems is essential for the viability of the business and quality system.
These questions show why M2M is not simply an IT interface – it is a cross-functional operating model involving regulatory affairs, quality, master data, labeling, IT, authorized representatives, and external technology partners.
M2M is not a simple “upload button.” It requires technical onboarding, access point management, proof of testing, security keys, and correct message formatting. The Commission’s M2M documentation explains that economic operators may request a new access point or use an existing access point, including through a third-party provider. This is why many companies are testing the model with a limited portfolio or selected business unit before scaling to their full product catalog.
The benefits are compelling: fewer manual transcription errors, better repeatability, more efficient updates, and stronger alignment between source systems and regulatory submissions. However, M2M does not eliminate the need for regulatory judgment. Companies still need clear ownership for data definitions, change control, certificate references, legacy device treatment, EMDN selection, and exception handling when EUDAMED returns validation errors.
For the remaining modules, the Commission’s current wording is important. The official EUDAMED overview lists Clinical Investigations and Performance Studies as “under analysis” and Vigilance and Post-Market Surveillance as “in development.” It also states that the two remaining modules “will be released when they are mandatory to use.” Companies should not assume the lengthy transition experience associated with the current modules will happen again. The Commission’s wording suggests organizations may have significantly less runway once the remaining modules become available.
Companies should start creating or modifying workflow processes now for clinical investigations, performance studies, vigilance, post-market surveillance, field safety corrective actions, and post-market safety reporting. Until those modules are mandatory, companies should continue to follow applicable national and transitional reporting routes. EUDAMED is expected to become the central EU data repository where product identity, certificates, clinical activity, vigilance activity, and market surveillance information connect across the device lifecycle.
If you only take three actions after reading this, here is what we recommend:
Successfully registering devices is only the beginning. As EUDAMED continues to expand, organizations will need sustainable processes for data governance, certificate management, vigilance reporting, post-market surveillance, and system integration. Whether you are working through device registration challenges, evaluating M2M capabilities, or preparing for future EUDAMED modules, ELIQUENT Life Sciences helps medical device and IVD companies build practical, scalable compliance programs.
Learn more about our EU regulatory consulting and training solutions.
US Office Washington DC

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.