Regulatory Approval Is Not the Finish Line
Approval starts a second set of deadlines. Most of them are not on the project plan.
The clearance letter arrives and the mood in the building changes. Months of work behind a submission resolve into a single document, and for most teams that document reads like an ending.
It is closer to a permission slip. Clearance or approval authorizes you to market a specific device, described a specific way, manufactured under a specific set of controls. It says nothing about whether you are ready to ship, and it quietly converts a long list of dormant obligations into active ones.
That distinction is worth understanding early, because the work it implies does not appear on most submission timelines. Teams plan design verification, validation and review cycles in detail, then discover that the period between clearance and first shipment has its own set of dependencies, some with lead times measured in months, not days.
What clearance actually authorizes
Clearance covers the device as you described it, including its intended use, specifications, labeling, manufacturing processes and suppliers. Those details are the limits of what you are authorized to market.
Change management does not end when development does. A component substitution, a new supplier, a process adjustment or a manufacturing site move all have to be evaluated against that description. The assessment is the same one you ran before approval. What changes is the baseline, which is now fixed in a regulatory record.
The United States UDI framework adds another layer of considerations to change management. A new device identifier is required when a change meets the criteria of a UDI trigger: a change to intended use, a significant change to safety or performance, or whether the device is provided sterile or non-sterile. A change that reaches that threshold does not just require a regulatory assessment. It propagates into labeling, packaging and your database records (e.g., FDA GUDID).
The work that stands between clearance and shipping
None of what follows depends on which pathway you used. These items come due because you are about to place a product into commercial distribution.
Establishment registration and device listing. Registration under 21 CFR Part 807 is an annual obligation with a fee, renewed each year between October 1 and December 31, and device listings are reviewed and updated in that same window. Foreign manufacturers designate a US Agent as part of registration. The requirements themselves are straightforward. The timing is what catches teams out, since the renewal window has nothing to do with your launch date.
Labeling and UDI. Labeling must comply with 21 CFR Part 801, and devices subject to UDI requirements need identifiers assigned under Part 830, carried on the label and packaging, with corresponding records submitted to the Global Unique Device Identification Database. These sit at the end of a chain that starts with final specifications. A late change to a specification or an indication statement does not stop at the specification. It moves through artwork revision, barcode verification and a database update, each with its own review step, and each dependent on the one before it.
Manufacturing at production scale. Process validation performed on development-scale equipment does not automatically transfer to production volumes. Sterilization validation, packaging and shelf-life or stability data are frequently still maturing at the point of clearance, and some of that work cannot be compressed because it depends on elapsed time rather than effort. Shelf life is the clearest case. An initial claim is typically supported by accelerated aging data, with real-time aging running in parallel to confirm it. A three-year claim eventually needs three years of real-time data, and no amount of resourcing shortens that.
Distribution readiness. Storage and handling conditions, distribution controls, training for the people who will field questions, and a functioning intake point for complaints with a dedicated person or group to handle complaints all need to exist before the first unit ships rather than after the first issue surfaces.
Obligations that switch on the day you launch
Post-market requirements are usually described as things you build before launch. What is less often said is that they become legally binding the moment a device reaches the market, and several run on clocks you do not control.
In the United States, medical device reporting under 21 CFR Part 803 requires manufacturers to report deaths, serious injuries and certain malfunctions, submitted electronically through eMDR. Reporting timeframes vary depending on the nature of the reported event and run from the date you become aware of an event, which means your complaint intake process is what determines whether you can meet them.
The trap is where awareness actually begins. A customer who mentions a malfunction to a sales representative has put your organization on notice, whether or not that conversation ever reached the complaint file. Intake has to capture the channels people actually use, not the one you designed. Corrections and removals reporting under Part 806 applies when you take field action, and certain devices carry tracking requirements under Part 821.
In the European Union, the post-market surveillance system required under Article 83 of the EU MDR is not a document you produce on request. It is a planned, active system, with a surveillance plan under Article 84 and defined reporting obligations that scale with device class. Manufacturers of Class IIa devices update a periodic safety update report at least every two years, while Class IIb and Class III manufacturers update annually. For Class III and implantable devices, the report goes to the notified body through the EUDAMED electronic system, where the notified body’s evaluation is recorded alongside it. Class I manufacturers prepare a post-market surveillance report under Article 85 instead.
One item to watch rather than plan around: a European Commission proposal from December 2025 would reduce PSUR frequency for some classes. It has not been adopted, and legislative review means adoption is not expected before 2027 at the earliest, so current Article 86 frequencies remain in force.
Your regulatory file now has a maintenance schedule
The most consequential shift after approval is that documentation stops being something you assemble and starts being something you maintain.
Risk management is the clearest example. ISO 14971 treats production and post-production information as an input to the risk management process, which means complaint data, service records, manufacturing nonconformances and field experience are supposed to flow back into the risk file and prompt reassessment when they change the picture. A risk file frozen at the date of clearance is not a completed document. It is an out-of-date one.
A concrete version: field data shows a failure mode occurring at a rate higher than your original analysis estimated. Nothing about the device has changed, but the risk assessment behind it now rests on a number you know to be wrong, and the acceptability conclusion built on that number needs to be revisited.
The same logic applies across the file. Design controls extend through the product lifecycle rather than closing at transfer. Supplier qualification requires ongoing monitoring rather than a one-time approval. For PMA devices, post-approval study commitments may be conditions of approval, and changes generally require a supplement submitted and cleared before implementation rather than documented after it.
The second half of the project
Approval is the point where a device stops being a development program and becomes a marketed product with continuing obligations. Both phases require evidence, planning and calendar time. A project plan does not always – but should – include post-marketing requirements or reference existing procedures for handling post-market information.
The practical move is to build the post-approval phase into your timeline while the submission is still in progress, since that is when you can still influence the sequence.
Six questions worth answering:
- What data supporting the launch depends on elapsed time rather than effort, and has it started?
- Is process validation established at production scale or at development scale?
- What is the full sequence from final specification to approved artwork to a submitted database record, and how long does it take?
- Which registrations, listings or certifications are prerequisites to shipping, and what calendar do they run on?
- Can our complaint intake capture an event from any channel a customer might actually use?
- Which post-market reports will be due, on what cycle, and who owns them?
The answers rarely change the submission. Several of them change the launch date, and you want to know that while there is still time to act on it.