Key Summary

An in-depth analysis of when and how existing test reports can be reused for software medical device registration across multiple jurisdictions, covering regulatory judgment logic, evidence mapping, common pitfalls, and AIMEILI's practical recommendations.

Answer: Test reports for software medical devices can be reused for overseas registration, but not universally. Whether reuse is acceptable depends on the target country's regulatory framework, the product's risk classification, the chosen registration pathway, and the compliance status of the reports themselves. Manufacturers must first confirm whether the product falls under the target country's medical device definition, then determine the risk class and registration route, and finally assess whether existing test reports from NMPA, CE, FDA, or ISO 13485 frameworks meet local technical documentation requirements.

Executive Summary

Reuse of test reports is a practical issue for many companies registering software medical devices overseas. The answer is not a simple yes or no; it depends on the target country's regulatory framework, product risk class, registration path, and the compliance status of the reports themselves. Companies should first confirm whether the product is within the scope of medical device regulation in the target country, then determine the risk classification and registration method, and then evaluate whether existing test reports under NMPA, CE, FDA, or ISO 13485 frameworks satisfy local technical documentation requirements.

Reusable items typically include foundational test data such as electrical safety, EMC, software lifecycle, and cybersecurity, but the standard versions, laboratory qualifications, and report validity periods must be checked. Items that cannot be directly reused often involve country-specific requirements such as local testing, clinical evaluation, labeling and instructions, and language localization. Even if reports can be reused, companies must still prepare complete quality system documentation, risk management files, post-market surveillance plans, and local agent arrangements. Common risks include report invalidation due to updated standards, inability to submit applications without an authorized representative, and delays in product launch due to lengthy correction cycles. Companies should establish a global registration documentation repository, separate reusable evidence from localization requirements, and plan testing strategies in advance to reduce the cost of duplicate testing and corrections.

Applicable Scenarios and Core Questions

Overseas registration of software medical devices often raises the question of test report reusability. Test reports here include verification and validation records for electrical safety, electromagnetic compatibility, software performance, cybersecurity, risk management, and usability. Companies want to leverage existing NMPA, CE, or FDA registration files for other countries to save time and costs. However, different countries have significantly different requirements for test reports. Whether foreign test data is accepted often depends on mutual recognition agreements or whether local regulations allow the use of reports from overseas laboratories.

The first step is to confirm whether the product is classified as a medical device in the target country. For example, in the EU, software qualifying as a medical device must meet MDR requirements; in the US, the FDA has specific classifications and premarket submission requirements for SaMD (Software as a Medical Device); in Southeast Asia, the Middle East, and Latin America, some countries have not yet established dedicated regulatory guidelines for software medical devices and may manage them as general medical devices or health software. If the product is not considered a medical device, test reports become irrelevant, and the product only needs to meet local general electronic product requirements.

The core question is: Can the data be used, how to prove its usability, and what local evidence needs to be supplemented. Companies should not assume that all test reports are reusable, nor should they believe that none are. The correct approach is to establish an evidence mapping table that checks each item against the target country's technical documentation checklist.

Registration Decision Logic

Determining whether test reports can be reused requires first establishing the registration pathway. The target country's risk classification determines the scope of submitted documentation. Generally, the lower the risk, the fewer the requirements and the higher the likelihood of report reuse; the higher the risk, the stricter the review, and retesting or additional clinical data may be required.

Step 1: Confirm the classification of the software medical device

For instance, under EU MDR Rule 11, most medical decision software is Class IIa or IIb; the US FDA classifies SaMD as Class I, II, or III; China's NMPA classifies software as Class II or III according to the Medical Device Classification Catalog. If the product is classified into a higher risk category in the target country, existing low-risk test reports may not be sufficient to support registration.

Step 2: Confirm the registration pathway

Some countries accept CE certificates as a fast-track proof; for example, some GHWP member states may accept CE reports as a basis. Other countries require local registration or national approval, such as China, Brazil, and South Korea. Still others allow self-declaration of conformity with technical documentation only, such as Australia's ARTG inclusion process. The pathway determines the requirements for test reports.

Step 3: Evaluate the compliance status of existing documentation

If test reports are issued by qualified laboratories and are based on international standards (such as IEC 62304, IEC 60601-1, ISO 14971), the likelihood of acceptance is higher. If reports are based on outdated standards or non-international methods, updated testing or a gap analysis may be required.

Documentation and Evidence

Reusable documentation typically includes software requirements specifications, software architecture design, software test reports, risk management reports, usability engineering reports, and cybersecurity explanations. These documents are based on common standards and are recognized by most countries. In particular, IEC 62304 (software lifecycle), ISO 14971 (risk management), and IEC 62366 (usability) are international consensus standards that many countries directly reference or accept as evidence of compliance.

Electrical safety and EMC reports are also key reusable items. If the hardware portion has passed IEC 60601-1 and IEC 60601-1-2 testing, and the reports are issued by an ISO 17025-accredited laboratory, most countries will accept the data. However, attention should be paid to special voltage, frequency, or language requirements in the target country. For example, Japan requires PSE-related safety testing, and Brazil requires INMETRO certification, which may mean additional local testing.

Clinical evaluation documentation requires extra caution. For certain software functions that claim clinical efficacy or are used for diagnosis, the target country may require local clinical evidence or epidemiological data. Even if existing clinical literature can be cited, a localized assessment is needed, particularly regarding differences in race, disease spectrum, and medical practice.

Local agent and authorized representative documents cannot be reused. Almost all countries require a local agent or authorized representative to communicate with regulatory authorities and assume post-market surveillance and adverse event reporting responsibilities. Companies must sign agreements with local agents and provide powers of attorney. These documents are required on a country-by-country basis.

Labels and instructions must be localized. Even if the same test report is used, the user interface, warning statements, contraindications, and instructions for use must be adjusted to meet local language and regulatory requirements. If the test report's labeling and instruction content is only in English, it may not directly satisfy the target country's requirements.

Common Errors

  • Submitting test reports without classification assessment, leading to risk classification errors and requests for additional testing or reclassification.
  • Ignoring standard version differences. For example, some countries do not accept declarations based on older versions of ISO 14971 or IEC 62304 and require compliance with the latest versions.
  • Assuming CE certificates or FDA 510(k) are globally valid, when in fact many countries only accept national approvals or reports in their own language.
  • Failing to appoint a local agent early, only realizing the need at the time of submission, causing project delays.
  • Providing only test data without complete quality system evidence, such as ISO 13485 or MDSAP certificates, or failing to integrate the software lifecycle process into the quality management system.
  • Overlooking cybersecurity requirements. An increasing number of countries require cybersecurity testing and vulnerability management plans for software medical devices, while many companies still use outdated reports.
  • Being unfamiliar with post-market surveillance and local adverse event reporting requirements, thinking that obtaining a registration certificate is the end, and failing to establish post-market documentation that meets the target country's requirements.

Enterprise Preparation Checklist

  • Identify the target country list and research each country's medical device definition, regulatory authority, registration pathway, and fee schedule.
  • Complete product classification and risk level assessment for each target country and output a classification matrix.
  • Build an evidence repository for test reports and technical documents, noting the standard version, issuance date, certifying body, and language of each document.
  • Sign contracts with local agents or authorized representatives in target countries and obtain entity information for qualification.
  • Prepare a technical document comparison table, checking existing evidence against the target country's submission checklist item by item.
  • Arrange translation and localization work, including labels, instructions, user interface language, and units of measurement.
  • Check local clinical evidence requirements and initiate clinical evaluation or literature searches in advance if necessary.
  • Develop a supplementary testing plan for outdated standards or missing test items and arrange additional tests promptly.
  • Establish a post-market surveillance plan, including customer complaint handling, adverse event reporting, document version updates, and internal audits.

AIMEILI Regulatory Interpretation

The most common mistake companies make is equating a “test report” with a “registration certificate.” A report is merely evidence that a product meets specific standards, whereas registration is an overall process involving quality management systems, local agents, labeling, post-market maintenance, and other elements. We have seen many companies use a CE certificate copy as a universal key, only to be rejected in Southeast Asian and Latin American countries. The reason is not that the report is invalid, but that they failed to satisfy local requirements for local agents, local languages, or national technical reviews.

At the project outset, conducting a “gap analysis” is more important than translating old documents. We recommend that companies first list the regulatory requirements of the target countries and then compare them item by item with existing evidence. This step can avoid substantial supplementary testing and document rework later. Especially for software medical devices, cybersecurity and usability evidence should be checked in advance against emerging guidelines in the target country.

What must be localized? Labels, instructions, user interface language, local legal requirements, registration entity, and agent agreements must be localized. What can be reused? Test reports based on consistent standards, software lifecycle documents, risk management documents, and quality system certificates can be reused, provided the standard versions are current and the reports are issued by qualified laboratories.

Local agents and certificate control are the most overlooked aspects in overseas registration. Many companies rely on importers or distributors as registration certificate holders. If the partnership breaks down, the certificate may be controlled by the other party, preventing the product from being sold. We recommend that companies strive to hold certificates in their own name or that of a subsidiary, and sign agreements with agents clearly defining rights and ownership.

To reduce repetitive documentation and correction risks in multi-country registration, the core is to build a unified core technical document library and a differentiated management process. Use one set of basic test reports and make small adjustments for each country, rather than redoing everything for each country. Through rigorous gap analysis, change management, and post-market surveillance, companies can turn overseas registration from a one-time firefighting exercise into a reusable asset.

Frequently Asked Questions

Does a CE certificate equate to a test report for overseas registration?

No. A CE certificate is a declaration of conformity indicating that the product meets EU regulatory requirements. Some countries, including certain GHWP member states, accept CE as a basis for registration and may simplify test report requirements, but not all countries directly recognize it. For example, Indonesia, the Philippines, and Brazil may still require local registration and local testing. Furthermore, a CE certificate is not a test report and cannot replace detailed test data and reports in the technical file. Companies must retain complete evidence records.

If software is part of a medical device, are test reports harder to reuse?

Yes. When software is embedded in or connected to hardware, test reports must address hardware-software interaction, including electrical safety, EMC, usability, and cybersecurity. The hardware portion may require local testing due to differences in power supply, plug types, or communication modules. The software portion, especially algorithm and decision-making functions, may require additional clinical validation. Therefore, test reports for an entire system are more difficult to reuse than those for a standalone software app and should be evaluated module by module.

After a standard update, must old test reports be discarded?

Not necessarily. Many updated standards provide transition periods, and companies can assess based on differences between old and new standards. If the new standard merely adds clarification or supplemental requirements, old testing may remain partially valid. However, updates to software safety, cybersecurity, and risk management standards often entail substantive new requirements—for example, revisions to IEC 62304 and the issuance of cybersecurity guidance—typically necessitating gap analysis and corresponding verification records. We recommend that companies proactively monitor target countries' official standard journals rather than waiting until regulatory review to discover issues.

Content Review and Applicability

Content by: AIMEILI Regulatory Editorial Department. Professional review: AIMEILI International Medical Device Registration Project Team. Sources: Priority is given to official regulatory agencies, international organizations, standard bodies, and publicly available regulatory materials; industry media and project experience are used only as supplementary references. This article is intended for preliminary understanding, documentation preparation, and project planning, and does not replace the formal requirements of target country regulatory authorities, test conclusions, or legal advice.

Further reading: For related topics, see the previous article “What to Do When Quality System Evidence Inconsistencies Occur for Home Medical Device Overseas Registration?” and the next article “How to Localize Labels and Instructions for AI Medical Device Overseas Registration?”

Source and Language Notice

View Chinese original page

Related Reading

Need a registration pathway assessment?

Send product type, intended use, target countries and existing certificates. AIMEILI can help evaluate registration pathway, documentation gaps and compliance risks.

Contact AIMEILI