Digitalization of Technical Documentation: Extension of e-IFU Scope Under Implementing Regulation (UE) 2025/1234

Technician working in a data center aisle with server racks, a laptop, cables, and gloves on a metal cart.

The evolution of the European regulatory framework for medical devices is establishing a progressive transition toward natively digital healthcare information management models. Within this context, the entry into force of Implementing Regulation (UE) 2025/1234, which supplements and amends the provisions of the previous Regulation (UE) 2021/2226, marks a structural shift for the entire MedTech sector.

What are the main changes?

The main update introduced by the legislator lies in the significant extension of the option to provide instructions for use in electronic format (e-IFU). While this option was previously restricted to specific categories (such as implantable and fixed installed devices), the new regulatory framework extends its application to all medical devices, their accessories, and products without an intended medical purpose listed in Annex XVI of Regulation (EU) 2017/745 (MDR)—provided they are intended for the exclusive use of professional users and that use by laypersons is not reasonably foreseeable.

This reform directly supports industry goals regarding sustainability, environmental impact reduction, and packaging cost optimization. However, eliminating paper support does not translate into a relaxation of regulatory controls. On the other hand, it shifts the focus of risk assessment to stringent IT, logistical, and infrastructural requirements.

Critical criteria compliance

During the conformity assessment of technical documentation, the evidence provided by manufacturers must demonstrate full compliance with specific critical criteria:

Cybersecurity and Business Continuity

Manufacturers must demonstrate adequate protection measures for the hosting servers against cyber threats, in full compliance with Regulation (EU) 2016/679 (GDPR), while ensuring continuous and uninterrupted accessibility for the user.

Infrastructural Risk Management

The quality management system must integrate structured contingency plans to mitigate risks associated with potential downtime of the hosting system, including clear procedures for providing a backup paper version upon request.

Labelling and Data Traceability

The commercial packaging labelling must unequivocally indicate that the instructions are provided in electronic format. Furthermore, strict alignment must be maintained between the e-IFU metadata, the website URL, and the UDI registration within the European database, EUDAMED.

Why Kiwa?

As a Notified Body, Kiwa Cermet Italia actively verifies these compliance requirements within MDR certification processes. Our objective is to ensure that digital innovation and corporate efficiency advance in total alignment with the highest safety standards for both patients and healthcare professionals.

Hospital

Contact us

We invite Regulatory Affairs Specialists and Quality Managers to share their insights: how are your organizations integrating these new cybersecurity and e-IFU risk management requirements into the technical file?

Fill out the form and discuss it with our experts.