What to do if there is new version of standard, but hasn’t been harmonised yet?
Periodically standards will be updated, but any updated versions of standards are not automatically harmonised. When a new version is released, manufacturers have 2 options:
- Continue using the harmonised version
- Adopt the new standard
In both cases, the newest version of the standard should be reviewed and a gap analysis created so that the impact of any changes can be assessed and a full, documented justification for the decision of which standard to use is recorded.
How a Notified Body Assesses Harmonised Standards
When DQS conducts a technical documentation review as part of MDR conformity assessment, harmonised standards play a specific role in the assessment logic. A claim of conformity with a harmonised standard creates a presumption of conformity - but it is not automatically accepted. Assessors verify: - That the correct version of the standard was applied (harmonised version vs. latest published version) - That the scope of the standard covers the specific device, material, or process in question - That the standard was applied in full, not selectively - That where deviations exist, they are documented with justified alternatives - That normative annexes were treated as requirements, not guidance A common finding in technical documentation reviews is the citation of a standard without evidence of its application — listing ISO 14971 in the GSPR matrix without a corresponding risk management file that demonstrates its requirements have been met. The standard cited is only as strong as the evidence behind it.
What to Do When No Harmonised Standard Exists
As of 2026, only 17% of the standards requested for harmonisation under MDR have been published in the OJEU. This means that for the majority of technical areas - including most software lifecycle, cybersecurity, AI, and many biocompatibility topics, manufacturers cannot rely on presumption of conformity.
In these cases, manufacturers have two options:
1. Apply the non-harmonised standard and justify conformity
The manufacturer uses the most current relevant standard (even if not harmonised), maps it against the applicable GSPR requirements, and provides documented justification for why it demonstrates conformity. This justification becomes part of the technical documentation.
2. Use Common Specifications (CS)
Where the Commission has adopted Common Specifications to fill gaps in harmonisation, these carry the same presumption of conformity as harmonised standards and are mandatory where no adequate harmonised standard exists.
From a Notified Body perspective, the absence of a harmonised standard does not reduce the evidence burden — it increases it. Assessors will look for a documented rationale that is proportionate, current, and explicitly mapped to the relevant GSPR clauses.
What is different about harmonised standards?
Whilst the core content of a harmonised standard generally mirrors the original published version of the standard, there are two key differences:
- A European or national forward describing the harmonisation process and may contain country-specific details.
- ‘Z’ Annexes mapping the standard clauses to relevant EU legislation. For instance, in EN ISO 13485, the Z annexes show how the standard correlates to the QMS requirements in the EU MDR and EU IVR. Some standards will also have the ‘NZ’ annex. This is a national annex, which will show the differences between the standard and the national laws from the country that published that version of the standard.
Structure of ISO standards
National/European Forwards
The forwards in harmonised standards, will often contain information about the process of harmonisation and the committees that approved or prepared that version. They may also contain extra requirements that can be country specific.
Introductions:
The introduction in a standard is optional. It can add background information or commentary, but it will not contain any requirements.
Scope
The scope in a standard is mandatory. The scope explains what the standards do and where it is applicable. It will only contain factual statements and cannot contain any requirements or recommendations.
Annexes
There are two types of annexes:
- Normative annexes are mandatory and give additional requirements.
- Informative annexes give additional information and guidance. You can choose whether to follow informative annexes or not; however, it is good practice to provide a justification as to why you are not following informative annexes.
The annexes are used to separate out information that might not be appropriate in the body of the text and are cited in the document.
Language
Standards are written in plain language, to make it easier to read and understand, and avoid misinterpretation. At the start of ISO standards, they tell you about the verbal forms which are used in the standard and how the words should be interpreted:
Shall – Requirement (You must comply with this)
Should – Recommendation
May – Permission
Can – Possibility or capability.
What’s the difference between common specifications and harmonised standards for medical devices?
Common Specifications (CS) were a new term that was introduced in the EU MDR to describe documents to fill gaps for products where no harmonised standards exist, or the existing harmonised standards are not sufficient. Like harmonised standards, CSs can be used to demonstrate presumptive conformity with the regulatory requirements of the EU MDR.
Conclusion: Leveraging harmonised standards for medical devices effectively
Harmonised standards for medical devices are a cornerstone of regulatory compliance within the EU framework. While their use is not mandatory, they provide a powerful and efficient way for manufacturers to demonstrate conformity with essential requirements under the EU MDR and
IVDR. Understanding how to identify, access, and interpret these standards—particularly their structure, annexes, and legal relevance—can make the difference between basic compliance and a robust, future-proofed quality system.
Whether you’re navigating horizontal standards like EN ISO 13485 or vertical product-specific ones, aligning your approach with harmonised standards ensures consistency, clarity, and regulatory confidence. By staying informed about updates and effectively managing transitions between versions, your organisation can turn these standards from a checklist into a strategic advantage.