MiBB Regulatory
← Back to insights
PRRCJun 2026 · 7 min

When do you need a PRRC under MDR Article 15? A practical guide for SaMD manufacturers

Every EU manufacturer needs a Person Responsible for Regulatory Compliance — but what that means in practice, when you need one, and whether fractional coverage is legitimate are questions I hear constantly from SaMD start-ups.

Under MDR Article 15, manufacturers must have at least one Person Responsible for Regulatory Compliance (PRRC) permanently and continuously at their disposal. The PRRC is not a ceremonial title — they carry legal responsibility for ensuring the conformity of devices, maintaining the technical documentation, and fulfilling post-market obligations.

For SaMD and AI device start-ups, the PRRC requirement often arrives before the team has the headcount to justify a full-time regulatory hire. That makes Article 15 one of the most practical compliance questions you face early on.

Who needs a PRRC?

The obligation applies to manufacturers placing devices on the EU market under MDR. If you are the legal manufacturer — the entity whose name appears on the label and who holds the conformity assessment responsibilities — you need a PRRC.

Authorised representatives, importers, and distributors have their own obligations under MDR, but the manufacturer's PRRC is the role that start-ups most often need to solve first. If you outsource manufacturing, the PRRC sits with the legal manufacturer, not necessarily the development team — though in practice for SaMD companies these are usually the same entity.

What qualifications does a PRRC need?

Article 15 sets out two routes to qualification. The PRRC must either hold a diploma in law, medicine, pharmacy, engineering, or another relevant scientific discipline from a recognised university — plus at least one year of professional experience in regulatory affairs or quality management relating to medical devices — or four years of professional experience in those fields without the formal diploma.

For SaMD manufacturers, the engineering or scientific discipline route is common. But the experience requirement is not waived for founders with strong technical backgrounds. A software CEO who has never worked in regulatory affairs does not automatically qualify. This is why many start-ups engage an external PRRC while building internal regulatory capability.

Full-time hire vs. fractional PRRC

MDR requires the PRRC to be permanently and continuously at the manufacturer's disposal. That does not strictly mean full-time employment — it means the person must be genuinely available to fulfil the role, not listed nominally on paper without capacity to act.

Fractional PRRC arrangements are widely used and legitimate when structured correctly: a named, qualified person with a defined scope of responsibility, documented in the quality management system, with clear lines for sign-off, vigilance reporting, and communication with authorities. What does not work is appointing someone who cannot respond when a serious incident occurs or a competent authority requests information.

For most SaMD start-ups below roughly 30–50 employees, fractional coverage is the pragmatic choice until post-market activity and product portfolio complexity justify a dedicated hire.

When should you appoint a PRRC?

The legal requirement applies once you are a manufacturer under MDR. In practice, you need a PRRC before you place a device on the market and before your declaration of conformity is signed.

The earlier mistake is waiting until CE marking is imminent. A PRRC should be involved while the QMS is being established, while the technical file is being built, and while clinical evaluation and post-market surveillance plans are being designed — because those are precisely the systems the PRRC is accountable for overseeing.

If you are preparing for Notified Body submission, the assessor will expect to see the PRRC identified, qualified, and integrated into your QMS — not added as an afterthought in the final weeks before audit.

What does the PRRC actually do?

The PRRC ensures that the conformity of devices is appropriately checked before release, that technical documentation and the declaration of conformity are maintained and updated, that post-market surveillance obligations are met, and that reporting obligations to competent authorities are fulfilled.

In a SaMD context, this translates to oversight of software lifecycle documentation under IEC 62304, risk management file maintenance, vigilance and serious incident reporting, change control for software updates, and ensuring that post-market clinical follow-up and cybersecurity surveillance are not just documented but actually running.

The PRRC does not have to personally write every document — but they are accountable for the regulatory compliance of what the manufacturer releases. That distinction matters when NB assessors ask who owns regulatory decisions inside the organisation.

Common mistakes I see

Appointing an unqualified founder or advisor without documented regulatory experience. Competent authorities and Notified Bodies do check qualifications.

Treating the PRRC as a signature slot on the declaration of conformity without integrating them into release decisions, change control, or PMS review.

Assuming your ISO 13485 consultant or RA consultant automatically serves as PRRC without a formal appointment, job description, and evidence of availability.

Leaving the appointment until after the technical file is complete — which forces rework when the PRRC identifies gaps in QMS coverage, vigilance procedures, or documentation control.

What to do next

Document your PRRC need as part of your regulatory strategy, not as a final checkbox. Identify whether you have someone internally who meets the Article 15 requirements, or whether fractional coverage is the right model for your current stage.

If you appoint externally, ensure the arrangement is documented in your QMS: role description, responsibilities, deputy arrangements, and evidence of how the PRRC is consulted on conformity decisions. Notified Bodies will look for this during QMS audits.

If you are unsure whether your current setup meets Article 15, a short gap review against MDCG 2019-7 is faster and cheaper than discovering the problem during an assessment.

Have a classification or compliance question?

I am happy to discuss your device and where you are in the regulatory journey.

Get in touch