Skip to content

Articles · Guide

Last reviewed 21 July 2026

PRRC Under MDR Article 15: What Small Teams Must Know

Of all the roles MDR requires, the PRRC is the one small teams most often treat as a box-ticking formality, right up until a Notified Body audit reveals it is nothing of the sort. This guide sets out what the role actually requires, where early-stage teams typically get it wrong, and how to compare your options for covering it. The audit it prepares you for is covered in the CE marking guide for medical software.

In short: MDR Article 15 requires every manufacturer to have a Person Responsible for Regulatory Compliance (PRRC) with defined qualifications, accountable for release of devices, technical documentation, post-market surveillance, and vigilance. Micro and small enterprises are not required to have one within their own organisation, but must have one permanently and continuously at their disposal.

What Article 15 actually says, in founder language

MDR Article 15(1) requires every manufacturer to have at least one person within their organisation with the qualifications and named responsibility to ensure a defined set of regulatory obligations are actually met. (The exception for micro and small enterprises is covered below.) This is not a nominal title added to an org chart. It's a named, accountable role with specific duties written directly into the regulation.

The core areas of PRRC responsibility, set out in Article 15(3), are: conformity of devices is appropriately checked before release, in accordance with the manufacturer's quality management system; the technical documentation and declaration of conformity are drawn up and kept up to date; post-market surveillance obligations are complied with; and reporting obligations under vigilance, Articles 87 to 91, covering incident reporting and field safety corrective actions, are fulfilled. Article 15(3) adds a fifth, conditional duty: if you run a clinical investigation, the PRRC ensures the investigational-device statement required under Annex XV, Chapter II, Section 4.1 is issued. The first four are the same areas a Notified Body audit will specifically probe, and the same areas where a manufacturer's actual practice, versus its documented process, most commonly diverges.

The qualification requirements and who realistically meets them

Article 15(1) sets out two alternative qualification routes. The first, Article 15(1)(a), requires a formal qualification, a diploma, certificate, or other evidence of formal qualification in law, medicine, pharmacy, engineering, or another relevant scientific discipline, plus at least one year of professional experience in regulatory affairs or quality management systems relating to medical devices. The second route, Article 15(1)(b), requires four years of professional experience in regulatory affairs or quality management systems relating to medical devices, without the formal qualification requirement, an accommodation for experienced practitioners who came into the field through a non-traditional route.

For an early-stage founding team, particularly one led by clinical or technical founders without a regulatory affairs background, few if any team members meet either bar directly. That's precisely why the small-enterprise flexibility discussed next exists, and why most startups end up sourcing this role from outside the founding team rather than growing it internally from day one.

The small-enterprise flexibility, and its limits

Manufacturers that are micro or small enterprises, as defined under EU recommendation 2003/361/EC, broadly fewer than 50 employees and either annual turnover or balance sheet total under EUR 10 million, are not required under Article 15(2) to have the PRRC within their own organisation. They must, however, have a PRRC "permanently and continuously at their disposal," which in practice means a contracted, external PRRC arrangement rather than the absence of the role altogether.

This flexibility is narrower than it first appears. "Permanently and continuously at their disposal" is a meaningful legal standard, not a loose consulting relationship invoked only when convenient. The contracted PRRC needs to be genuinely available to fulfil the role's actual duties, reviewing technical documentation, checking conformity before release, and responding to vigilance obligations, on a timeline consistent with the manufacturer's actual operational needs, not just available for an annual check-in. A Notified Body assessing this arrangement during audit will look for evidence the contracted PRRC is substantively engaged with the specific device and its documentation, not formally named but functionally absent.

What a PRRC is accountable for — and what Article 15 does and doesn't impose

The PRRC is a named, personally accountable role: Article 15(3) attaches its duties to an identified person, not just to the company, reflecting the fact that MDR intends this to be a genuinely responsible, empowered role rather than a delegated formality. Two clarifications are worth being precise about. First, Article 15 does not itself impose personal legal liability on the PRRC. It names the role and its duties; any personal legal liability, if it arises at all, is a matter of national law, not something Article 15 creates. Second, the one PRRC-specific protection the regulation does contain runs the other way: under Article 15(4), the PRRC "shall suffer no disadvantage" within the organisation in relation to the proper fulfilment of their duties, regardless of whether or not they are an employee. In practice, this means the person holding the role, whether an employee or a contracted external PRRC, needs real authority within the organisation to actually perform the duties Article 15 assigns: blocking a device release if conformity checks aren't satisfied, for instance, rather than holding a nominal title with no practical ability to act on the responsibilities it carries.

For founders, this has a direct organisational implication. The PRRC needs a genuine reporting line and real authority, not a title assigned to whoever was available, and the manufacturer needs to be able to demonstrate, if asked, that the PRRC's stated responsibilities match their actual practical authority within the company. The Article 15(4) no-disadvantage protection is the regulation's own signal here: a PRRC is supposed to be able to block a release or flag a conformity gap without career risk, and your organisational structure should make that credible. A PRRC who technically holds the title but has never actually blocked a release, reviewed a technical file update, or filed a vigilance report is a warning sign long before an audit ever surfaces it.

Why early-stage teams routinely underestimate this, and when it bites

The PRRC requirement is easy to underestimate at the point of initial technical file assembly, because its absence doesn't block early development work, and a placeholder arrangement can look sufficient on paper long before it's tested. A founder assembling their first technical file is focused on getting the device classified correctly and the clinical evaluation drafted. The PRRC line item can look like paperwork: name someone, get a contract signed, move on.

Where it bites is almost always at Notified Body audit or a significant post-market event. An auditor asks to speak with the PRRC directly about a specific technical documentation gap, not about the role in the abstract, and expects that person to answer with real command of the file. Or a vigilance event requires the PRRC to actually execute the reporting process Article 15 assigns them, on the clock, with a regulator watching the timeline. That's the moment a nominal PRRC gets exposed: someone who was named on paper but never actually engaged with the documentation, never reviewed a release decision, and can't answer the auditor's question without going back to the team to find out what actually happened. The auditor doesn't just note a training gap. They note that the manufacturer's PRRC arrangement doesn't function as MDR requires, and that finding tends to cascade into broader scrutiny of the quality management system, since if the PRRC arrangement is nominal, an auditor reasonably starts to ask what else in the QMS is nominal too.

This is a materially worse position to discover the gap in than during initial file assembly, both because it surfaces during exactly the moments MDR compliance matters most, and because retrofitting a genuinely functional PRRC relationship under audit pressure is a worse process than establishing one deliberately during initial technical file and quality system build. A hurried, defensive scramble to get your contracted PRRC up to speed on a device they've never actually reviewed, while an auditor is in the room, is not a position any founder wants to be in.

Options: hire, contract, or fractional

Three practical models exist for satisfying the requirement, and the right one depends heavily on company stage and device complexity.

OptionTypical costControlContinuity risk
Hire in-houseHighest ongoing cost: a full salary plus benefits for a dedicated regulatory affairs hire, justified once headcount and device complexity support itHighest: the PRRC is embedded in the team, close to product and quality decisions day to day, with the deepest working knowledge of your specific deviceLowest in principle, but concentrated in one individual; losing your only in-house PRRC to departure creates an acute, immediate gap unless a successor is already identified
Contract externallyModerate, typically structured as a retainer or scoped engagement, scaling with device count and review workload rather than a fixed salaryModerate: effective if the arrangement is genuinely substantive, with real engagement on your specific technical file, but weaker if treated as a name-only arrangementModerate: dependent on a single external individual or small firm, though usually easier to formalise a backup or transition plan than with a sole in-house hire
Fractional or sharedLowest per-manufacturer cost, since the professional's capacity is split across several non-competing clientsLowest of the three by default, since attention is divided, though this can be mitigated with clear service-level commitments written into the contractHighest if capacity isn't explicitly confirmed: a fractional PRRC serving too many clients at once is the arrangement most likely to fail the "permanently and continuously at their disposal" standard under audit scrutiny

Hiring a qualified PRRC directly is the most robust option for a company with sufficient headcount and budget to justify a dedicated regulatory affairs role, and it typically produces the deepest, most continuously engaged PRRC relationship. Contracting an external PRRC, available to micro and small enterprises under the flexibility discussed above, is the more common early-stage route, provided the arrangement is genuinely substantive rather than nominal. A fractional or shared PRRC arrangement, an experienced regulatory professional serving this role for several non-competing small manufacturers simultaneously, can work well provided their capacity genuinely allows the "permanently and continuously at their disposal" standard to be met for each client. That capacity question is worth confirming explicitly, in writing, before entering such an arrangement rather than assuming it exists because the professional says yes.

None of the three options is automatically wrong for a given stage. A five-person startup with one Class IIa device and a contracted PRRC who reviews every release and technical file update is in a stronger position than a fifty-person company with an in-house PRRC hire who was assigned the title alongside three other unrelated responsibilities and has never actually exercised the authority the role requires. Cost and headcount are proxies for the real question, which is whether the person in the role is genuinely equipped, available, and empowered to do what Article 15 requires.

A practical way to stress-test your current arrangement

If you already have a named PRRC, whichever model you use, a useful exercise is to ask three questions honestly. Has this person reviewed and signed off on your most recent technical documentation update, not just been copied on it? Could they answer a Notified Body auditor's specific question about your current post-market surveillance plan without first checking with someone else on your team? Do they have a documented instance of actually exercising their authority, blocking or delaying a release, flagging a conformity gap, filing a vigilance report, rather than the role existing only as a name on a document? If the honest answer to any of these is no, it's worth addressing before an audit forces the issue, not after.

What a functioning PRRC relationship actually looks like month to month

It's easier to spot a nominal PRRC arrangement if you know what a genuinely functioning one looks like in ordinary operation, not just at audit time. A PRRC who is properly engaged with your device typically reviews technical documentation changes as they happen, not in a batch months later. They're consulted before a device release, with real authority to say no if a conformity check hasn't been satisfied, not informed after the fact that a release already happened. They know your post-market surveillance data well enough to notice a concerning trend, not just to receive a summary report they skim. And they have a clear, tested process for what happens if a vigilance-reportable event occurs, including who contacts them, how fast, and what they do next, because a process that's only ever existed on paper tends to fail exactly when it's needed.

None of this requires the PRRC to be full-time or in-house. A well-run contracted or fractional arrangement can hit all of these marks, and a poorly run in-house hire can miss all of them if the role was handed to someone as an afterthought. The model you choose from the table above sets the starting conditions; whether the relationship actually functions this way is a separate question a written contract alone doesn't answer.

How this differs from other manufacturer-side compliance roles

Founders sometimes conflate the PRRC with other compliance functions the company also needs, which can lead to under-resourcing all of them by assuming one person or contract covers everything. A quality management system needs someone accountable for the QMS itself, its procedures, its internal audit programme, its document control, which is a broader role than the PRRC's specific Article 15(3) duties, even though the same individual sometimes holds both roles at a small company. Clinical evaluation and post-market clinical follow-up work is often led by a separate clinical or medical writing function, with the PRRC responsible for confirming the post-market surveillance obligations are met rather than personally authoring every report. And as covered below, the Authorised Representative is a distinct, separately regulated role entirely.

Being explicit about where the PRRC's responsibilities end and where other roles begin matters for two reasons. It prevents a single overloaded person from being nominally responsible for more than they can genuinely execute, which recreates the nominal-role problem described above. And it gives a Notified Body a cleaner picture during audit: a manufacturer that can clearly show the PRRC specifically owns their statutory Article 15(3) areas presents a more credible quality system than one where responsibilities blur together under one busy person's job title.

Frequently asked questions

Can a founder who isn't regulatory-qualified serve as their own company's PRRC? Only if they independently meet one of Article 15's two qualification routes, formal qualification plus one year of relevant experience, or four years of relevant experience without formal qualification. Founding or owning the company doesn't itself satisfy the qualification requirement.

Does a contracted external PRRC need to be based in the EU? The PRRC role itself doesn't have an explicit EU-residency requirement distinct from the manufacturer's own establishment, but in practice, most functional PRRC arrangements involve an EU-based professional given the practical need for genuine engagement with EU regulatory processes and, often, alignment with the manufacturer's Authorised Representative relationship.

What happens if our named PRRC leaves or becomes unavailable? The manufacturer needs to ensure continuity of the role; a gap in genuine PRRC coverage is itself a compliance gap. This is a practical argument for building redundancy or a clear succession plan into your PRRC arrangement rather than depending entirely on a single individual with no contingency, particularly under the hire model, where continuity risk is concentrated in one person.

Is the PRRC the same role as the EU Authorised Representative? No, though they're sometimes confused. The PRRC is a manufacturer-side compliance role under Article 15; the Authorised Representative is a separate, EU-established entity acting on behalf of a non-EU manufacturer for regulatory communication and market access purposes, required specifically for manufacturers based outside the EU. One related point for non-EU manufacturers: under Article 15(6), your Authorised Representative must also have a PRRC of its own permanently and continuously at its disposal — a separate requirement from your own PRRC arrangement.

Does having a PRRC in place mean a Notified Body will approve our technical file faster? Not directly; a properly functioning PRRC doesn't accelerate review, but a demonstrably absent or nominal PRRC arrangement is itself a finding a Notified Body can raise, which does add delay. Getting this right is closer to removing a risk than adding an advantage.

How do we know if a fractional PRRC genuinely has capacity for us, rather than just saying so? Ask directly how many other manufacturers they currently serve, what their typical response time is for a conformity or documentation question, and whether they can point to specific engagement with your device's file, not just your contract. A fractional PRRC confident in their capacity should be able to answer these without hesitation. Vague reassurance is itself a signal worth taking seriously.

Can our PRRC arrangement change as the company grows past the micro or small enterprise thresholds? Yes, and it should be revisited actively rather than left on autopilot. Under Article 15(2) as it stands, once a manufacturer grows past the fewer-than-50-employees or EUR 10 million thresholds under 2003/361/EC, the external-PRRC flexibility no longer applies, and the role needs to move in-house. Growing companies should track their headcount and financials against these thresholds explicitly, since crossing them without adjusting the PRRC arrangement creates a compliance gap that's easy to miss amid other growth-stage priorities.

One development to watch: in December 2025 the European Commission published a proposal to simplify the MDR and IVDR (COM(2025) 1023, procedure 2025/0404(COD)). Among other things it would make external PRRC arrangements explicitly available to SMEs — precisely the flexibility whose current limits are described above. It is a proposal, not law — adoption is realistically ~2027 at the earliest — so plan your organisational structure against the current rules while factoring the possible change into longer-term strategy.

Can one PRRC cover multiple devices or product lines within the same company? Generally yes, provided they genuinely have the capacity and expertise to fulfil the Article 15(3) duties for each device, and this is common practice as manufacturers expand their portfolios. The risk to watch for is the same capacity question that applies to fractional arrangements across companies: adding product lines without confirming the PRRC's bandwidth to genuinely engage with each one can quietly turn a functioning arrangement into a nominal one, simply through volume rather than any change in the contract or job title.

Does the PRRC need to physically sign off on paperwork, or can this be handled electronically as part of a QMS workflow? MDR doesn't mandate a specific mechanism, so an electronic sign-off integrated into your quality management system's document control and release workflow is generally acceptable, provided it creates a genuine, auditable record that the PRRC actually reviewed and approved the specific decision, not just that a system generated a notification they may or may not have acted on.

A structured conversation about which PRRC model fits your stage and device complexity, hire, contract, or fractional, is a quick, high-leverage conversation to have early, given how inexpensive it is to get right compared to the cost of discovering a gap during audit.

This guide is general information about MDR Article 15, not regulatory advice for your specific device or company structure.


Where next: MDR Annex VIII: How Device Classes Are Set · CE Marking Cost and Timeline for Medical Software · Building an MDR Technical File and CER

Talk through which PRRC model fits your stage. Book an expert conversation →

See where you stand, in about ten minutes.

Free, AI-powered, and every gap comes with a next step.

Start the MedTech Compass