Market Access

One dossier, three markets: harmonising EU, US & Singapore

A practical framework for structuring evidence once and reusing it across MDR, FDA and HSA submissions.

EuropeUSASingaporeAugust 2026·10 min read

Most medtech companies build their regulatory evidence three times. Once for the notified body, once for the FDA, once — usually last, usually rushed — for HSA. Each version is assembled by a different person, from a different folder, against a different template, and by the time the third one is written nobody is entirely sure which set of performance numbers is current.

That is not a regulatory problem. It is an architecture problem, and it is fixable. The three regimes ask different questions in different formats, but they interrogate the same underlying object: your device, your risk analysis, your validation, your clinical evidence, your quality system. Structure that object properly once and the three submissions become presentation layers over a single source of truth.

Here is what genuinely harmonises in 2026, what never will, and where the sequencing actually saves you money.

What harmonised — and it's more than it was

The single biggest change happened quietly in February. The FDA's Quality Management System Regulation (QMSR) took effect on 2 February 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. One ISO 13485-structured quality system now underpins your FDA position, your MDR Annex IX audit, your MDSAP certificate and your Singapore dealer's licence evidence.

Two caveats that catch people out. First, FDA still inspects against FDA regulations, not against ISO 13485 conformance — an ISO 13485 certificate is not evidence of QMSR compliance, and the agency's own framing is that the two are "substantially similar", not identical. Second, the old §820.180(c) exemption is gone: internal audit reports, supplier audit reports and management review records are now FDA-inspectable. If your internal audits were written on the assumption that no regulator would ever read them, that assumption expired in February.

Alongside QMSR, three other things reuse cleanly:

  • The standards spine. ISO 13485 and ISO 14971 are load-bearing in all three jurisdictions. IEC 62304 and IEC 62366-1 are recognised by FDA and named explicitly in HSA's change-management eligibility criteria. Check the Commission's current summary list before assuming any given standard carries a presumption of conformity under the MDR — the harmonised list lags the published standards badly, so some software and usability arguments still have to be written as GSPR-mapped justifications for Europe even where FDA and HSA accept the certificate directly.
  • MDSAP. Mandatory in Canada, accepted by FDA in place of routine inspections, and accepted by HSA as quality-system evidence for product registration and dealer's licences. The EU is an observer only — an MDSAP certificate does not displace an MDR notified body QMS audit.
  • IMDRF vocabulary. N88 (Good Machine Learning Practice, final January 2025) and N81 (software characterisation and software-specific risk) give you neutral language that all three regulators recognise. MDCG 2020-1's three-limb model for software clinical evaluation — valid clinical association, analytical validation, clinical validation — descends from IMDRF N41 and is the single most reusable conceptual frame in the whole exercise. Structure your software evidence that way and it maps onto all three regimes without re-derivation.

The architecture: core file, three wrappers

Think of it as one evidence core and three market wrappers. The core is jurisdiction-neutral and version-controlled. The wrappers are the assembly instructions and the market-specific content that genuinely cannot be shared.

Core evidence moduleEU MDRUS FDASingapore HSA
Device description & intended purposeAnnex II §1eSTAR device descriptionCSDT §A, Essential Principles
Risk management file (ISO 14971)GSPR 3, Annex IRecognised standard; feeds special controlsReferenced throughout GL-04
Design & manufacturing informationAnnex II §3Design controls, QMSRCSDT, dealer's licence QMS
Bench / analytical validationAnnex II §6.1Performance testing sectionCSDT §D
Software lifecycle (IEC 62304)GSPR 17 — written as a justificationSoftware documentation levelGL-04 R4 lifecycle
Usability (IEC 62366-1)GSPR 5 & 14Human factors contentGL-04
CybersecurityMDCG 2019-16Section 524B; Feb 2026 final guidanceGL-04 R4, incl. OS end-of-support
Clinical evidenceCER, Annex XIV Part A — not reusable as-isOften none in a 510(k)Reference-agency approval or clinical data
Labelling & IFUAll required languages, implant card, SSCP21 CFR 801/809, EnglishGN-23
Post-market planPMS + PMCF + PSURMDR 803 / 806; 522 ordersChange notification, annual declarations

The rows in amber are the ones that do not transfer. Everything above them does — and in most companies those transferable rows are 70–80% of the total page count.

Where reuse actually breaks

1. Clinical evaluation is not clinical data

This is the biggest and most expensive misunderstanding. MDR Article 61 and Annex XIV Part A require a continuously updated Clinical Evaluation Report demonstrating conformity with the relevant GSPRs, including benefit-risk and side-effect evaluation — for every device, including Class I. The FDA's 510(k) route asks a fundamentally different question: is this device substantially equivalent to a legally marketed predicate? The majority of 510(k)s contain no clinical data at all.

A cleared 510(k) file is therefore structurally incapable of satisfying an MDR clinical evaluation. The bench and analytical data underneath it reuses beautifully. The clinical argument has to be built for Europe on its own terms. Budget for it as a separate workstream from day one, not as a translation exercise at the end.

2. Equivalence and predicate are different legal tests

EU equivalence (MDCG 2020-5) demands demonstrated technical, biological and clinical equivalence — and today, for Class III and implantables, a contract giving you ongoing access to the equivalent device's technical documentation. FDA's predicate concept requires neither access nor a contract. The December 2025 MDR revision proposal would remove the contract requirement, which would help considerably. It is not law yet, and nothing in your plan should assume it will be.

3. Three local presences, none interchangeable

The EU Authorised Representative under MDR Article 11 holds documentation for ten years (fifteen for implantables), verifies your conformity assessment, and is jointly and severally liable with you for defective devices where you have breached Article 10 — and you separately need a PRRC under Article 15. The US Agent under 21 CFR 807.40 is a communications conduit with no liability role and no document custody duty. The Singapore registrant is the entity that holds the SMDR registration under a letter of authorisation from the product owner — a distinct construct again, and distinct from the dealer's licence holder, though the same company often does both in practice.

These are three different commercial relationships with three different risk profiles. Do not let a distributor volunteer for all three because it is convenient.

Sequencing: only one market pays you for going elsewhere first

Founders often ask which market to do first, expecting the answer to be a regulatory one. Between the EU and the US it is almost entirely commercial — neither recognises the other. The US–EU mutual recognition arrangement for devices was never implemented and the FDA revoked its implementing regulation (21 CFR Part 26) by final rule on 19 February 2026.

Singapore is the exception, and it is generous about it. HSA's GN-15 (Revision 13, effective 10 March 2026) makes prior approval by a reference agency — US FDA, Health Canada, Japan MHLW, Australia TGA, or an EU notified body — a formal, published precondition for its faster routes. Malaysia's MDA now also counts, under a reliance programme operational since February 2026. Note that UKCA is not on the reference-agency list.

RouteWhat unlocks itFee (SGD)Target TAT
Class C — FullNothing; no prior approval6,250220 wd
Class C — Abridged1 reference approval3,900160 wd
Class C — Expedited (ECR-1)1 approval + 3 years marketed + clean safety record3,340120 wd
Class C — Expedited (ECR-2)2 independent approvals, no waiting period3,340120 wd
Class C — Immediate (ICR)Standalone mobile app + 1 approval3,340immediate
Class B — Immediate (IBR)Standalone app + 1 approval, or 1 approval + 3 years, or 2 approvals1,000immediate
Class D — Expedited (EDR)2 independent approvals (the only expedited route at Class D)5,930180 wd

Read the highlighted rows carefully if you sell software. For a standalone mobile app, a single FDA clearance converts a 220-working-day Class C registration into an immediate one — with no three-year marketing history required, which is the condition that blocks everyone else. For a non-app Class C device, one clearance plus three years on the US market takes you from 220 to 120 working days and from S$6,250 to S$3,340. Two independent approvals — FDA and a CE certificate, say — remove the waiting period entirely.

The practical shape for most SaMD and AIaMD companies: FDA first, Singapore immediately behind it, EU on its own longer track.

Not because Europe matters less, but because MDR Rule 11 pushes most clinical software to Class IIa or above with a notified body attached, while comparable US software often clears via 510(k) without clinical data. The EU file takes longer and costs more on the clinical side. Starting it early and running it in parallel is the answer — not starting it late because the US went well.

One more codified reliance point worth knowing: Canada requires MDSAP certification for a Class II–IV licence. If you are building an MDSAP audit for FDA purposes anyway, Canada is close to free.

Change control is the real test of your architecture

Any dossier can be assembled once. The question is what happens at version 2.3.

The FDA finalised its Predetermined Change Control Plan guidance for AI-enabled device software functions in December 2024 — you pre-specify the modifications, the validation protocol and the impact assessment, and implement within that envelope without a new submission. Singapore's analogue is the Change Management Program in HSA GN-37, which requires ISO 13485 or MDSAP certification plus IEC 62304 compliance as an entry ticket, and then lets you implement pre-approved changes without a change notification — with an implementation declaration within a year and annually thereafter. Europe has no direct equivalent yet; you are working within MDR significant-change rules and your notified body's appetite.

Write one change plan. The pre-specified modification list, the validation protocol, the acceptance criteria and the rollback plan are the same document in all three filings. Only the wrapper and the approval mechanics differ. Teams that write three separate change plans end up with three divergent products.

Six things to do this quarter

01

Declare a single source of truth

One controlled location for the risk file, V&V reports, software documentation and performance data. Submissions reference it; they do not contain private copies. If a number changes, it changes once.

02

Build a three-column traceability matrix

Every claim mapped to MDR GSPRs, FDA special controls or performance expectations, and HSA Essential Principles. Gaps become visible immediately instead of at submission.

03

Re-audit your internal audits

Under QMSR those reports are inspectable. Read the last two years as an FDA investigator would, and fix the tone as well as the findings.

04

Separate the clinical workstream

Plan the MDR clinical evaluation as its own project with its own budget, not as a downstream conversion of your US file. Decide early between equivalence and own-data.

05

Diarise the 2026–28 dates

EUDAMED mandatory since 28 May 2026 with legacy devices to be registered by 28 November 2026; Singapore UDI for Class C from 1 November 2026; MDR transition ends 31 December 2027 (Class III / IIb implantable) and 31 December 2028 (most others); AI Act Annex I from 2 August 2028.

06

Write the change plan once

A single pre-specified modification envelope, presented as a PCCP to FDA and a CMP to HSA, with the MDR significant-change position documented alongside it.

What is still moving

Two live processes could change the picture, and neither is law. The Commission's December 2025 MDR/IVDR revision proposal (COM(2025) 1023) would broaden acceptable clinical data, relax equivalence, allow representative-device assessment for Class IIa/IIb, extend PSUR intervals, lengthen serious-incident reporting from 15 to 30 days — and, notably, includes the first legislative language contemplating EU participation in MDSAP and other reliance mechanisms. It is in the ordinary legislative procedure with no adoption date. Separately, the FDA's draft guidance on lifecycle management for AI-enabled device software functions has been sitting in draft since January 2025 and is not on the agency's priority list for finalisation.

Plan for the framework you have. Design the file so that if either lands, you benefit without restructuring.

The one-line version: you cannot file one submission in three markets, but you can maintain one evidence base and generate three submissions from it — and in Singapore, the order you do them in is worth real money.

Sources & further reading

  1. FDA — Quality Management System Regulation (QMSR), effective 2 February 2026.
  2. HSA — Medical device product registration and GN-15 Revision 13 (March 2026); HSA fees and turnaround targets.
  3. HSA — Regulatory reliance programme (Malaysia MDA).
  4. HSA guidance index — GL-04 R4 (software lifecycle, Dec 2025), GN-37 (Change Management Program), GN-36 (UDI).
  5. FDA — PCCP for AI-enabled device software functions, final guidance.
  6. MDCG endorsed guidance — including MDCG 2020-1, 2020-5, 2020-7/8 and 2025-6.
  7. COM(2025) 1023 final — proposal amending Regulations (EU) 2017/745 and 2017/746.
  8. MDSAP — benefits and use by authority; FDA MDSAP page.
  9. IMDRF AI/ML working group — N88 GMLP guiding principles (2025), N81 software characterisation.

General information current as at 12 August 2026, not regulatory or legal advice. Fees, turnaround targets and guidance revisions change frequently — verify against the regulator's current published version for your device class and market before acting.

Running EU, US and Singapore in parallel?

We structure the evidence base once and drive all three submissions from it — with the clinical, quality and market-access work sequenced so nothing waits on anything else.

Start a conversation →