CE marking medical wearables — MDR + CRA overlap
How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.
By Vladimír Vician
Medical wearables are one of the few product categories where the overlap question is explicitly settled in law rather than left to interpretation. Article 2(2) of the Cyber Resilience Act states that the CRA does not apply to products with digital elements covered by Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR). This is not a future exemption — it is a direct exclusion in the CRA text itself, reflecting that medical-device cybersecurity is already addressed by MDR Annex I §17 and the MDCG 2019-16 cybersecurity guidance.
What does still apply, alongside MDR, is the Radio Equipment Directive 2014/53/EU — because RED catches the wireless radio inside the wearable, and RED Article 3(3)(d), (e), and (f) were activated by Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444, applicable from 1 August 2025) with wearables explicitly named in the scope of 3(3)(e).
The three-regulation reality (and why CRA is missing)
A connected medical wearable typically interacts with three EU regulatory frameworks. Only two of them actually bind:
| Regulation | Applies? | Why |
|---|---|---|
| MDR (EU) 2017/745 | Yes — binding | Medical purpose triggers MDR Article 1 scope |
| RED 2014/53/EU | Yes — binding | Contains radio (BLE, NFC, cellular, Wi-Fi) |
| CRA (EU) 2024/2847 | No — carved out | Excluded by CRA Article 2(2)(a) |
| GPSR (EU) 2023/988 | Not for medical devices | Excluded by GPSR Article 2(2) for products covered by sector-specific legislation |
The carve-out works the same way for IVDR-regulated diagnostic devices (Article 2(2)(b)) and for type-approved motor vehicles under Regulation (EU) 2019/2144 (Article 2(2)(c)). The legislator's logic: where mature sector-specific cybersecurity provisions already exist, layering CRA on top would create conflicting obligations.
"This Regulation does not apply to products with digital elements to which the following Union legal acts apply: (a) Regulation (EU) 2017/745; (b) Regulation (EU) 2017/746"
— Cyber Resilience Act, Article 2(2)
MDR classification — the gatekeeping decision
Under MDR Annex VIII, devices are sorted into classes I, IIa, IIb, and III in line with their risk profile. The four-class structure is confirmed in recital 58: "it is necessary…to maintain the division of devices into four product classes in line with international practice."
For wearables, the classification rule that usually applies is Rule 10 for active devices intended for diagnosis or monitoring of vital physiological processes. Practical examples:
| Device | Typical MDR class | Notified body? |
|---|---|---|
| ECG patch (diagnostic) | IIa | Yes |
| Continuous glucose monitor (CGM) | IIb (or IVDR depending on intended purpose) | Yes |
| Smart hearing aid | IIa | Yes |
| Pulse oximeter (clinical) | IIa | Yes |
| Implanted cardiac monitor | III | Yes |
| Wellness step counter (no medical claim) | Not a medical device | No (consumer route, plus CRA may apply) |
The critical line is MDR Article 52 on conformity assessment procedures. As MDR recital 60 states: "For class IIa, class IIb and class III devices, an appropriate level of involvement of a notified body should be compulsory."
That single sentence drives most of the cost and timeline of a wearable CE submission.
The notified body route under MDR Article 52
For class IIa, manufacturers typically pick one of:
- Annex IX — Quality Management System (QMS) plus technical documentation assessment of a representative sample.
- Annex XI Part A — Production quality assurance (the lighter Annex IX-alternative for some IIa devices).
For class IIb and III, the route adds Annex X type examination or full QMS plus design dossier review. Implantables and class III almost always require Annex IX + Annex X combined.
Plan for 9 to 18 months between submitting a complete technical file and receiving the EC certificate, given continuing MDR notified body capacity bottlenecks in 2026. Selecting a designated MDR notified body — check NANDO — is non-negotiable.
One email at launch · cancel any time
The wireless side: RED still applies in full
CRA being carved out does not exempt the radio. Any wearable that emits or receives radio waves falls under Directive 2014/53/EU (RED). The relevant essential requirements:
- Article 3(1)(a) — health and safety (overlaps with MDR but RED requirement remains).
- Article 3(1)(b) — electromagnetic compatibility.
- Article 3(2) — efficient use of the radio spectrum.
- Article 3(3)(d) — "radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service".
- Article 3(3)(e) — "radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected".
These last two (and (f) for monetary-value transfer) were activated by Commission Delegated Regulation (EU) 2022/30. The application date was postponed to 1 August 2025 by Commission Delegated Regulation (EU) 2023/2444, which replaced Article 3 second paragraph of 2022/30 with "It shall apply from 1 August 2025."
Wearables are explicitly named in 2022/30 Article 1 as falling within Article 3(3)(e) scope where they process personal data — and a wearable that uploads heart rhythm, blood glucose, or audiogram data is unambiguously processing personal data of the user.
The presumption-of-conformity standards are the EN 18031 series. See our EN 18031 parts 1/2/3 comparison and the RED delegated act walkthrough.
EUDAMED registration is mandatory from 28 May 2026
Per the European Commission's EUDAMED page, four EUDAMED modules became mandatory on 28 May 2026:
- Actor registration — manufacturer, authorised representative, importer obtain a Single Registration Number (SRN).
- UDI / Devices registration — every device registered with its UDI-DI per MDR Article 27.
- Notified Bodies and Certificates — NB-issued certificates published.
- Vigilance and PMS — serious-incident reporting and trend analysis.
This is sector-specific equivalent to what CRA Article 14 reporting does for non-medical products — but routed through EUDAMED to the relevant Member State authorities, not to ENISA. The 24-hour reporting clock that catches CRA products (see CRA ENISA 24-hour reporting) does not apply here.
The DoC: one document, two regulations
Per the Blue Guide single-DoC principle, manufacturers issue one EU Declaration of Conformity that lists every piece of Union legislation the product complies with. For a connected medical wearable, that is MDR + RED — not CRA.
A skeleton DoC for a class IIa connected ECG wearable lists:
- Regulation (EU) 2017/745 (MDR) — conformity route Annex IX with NB 0123
- Directive 2014/53/EU (RED) — essential requirements 3(1)(a), 3(1)(b), 3(2), 3(3)(d), 3(3)(e)
- Harmonised standards applied — EN ISO 14971, EN 60601-1, EN 60601-1-2, EN 18031-1, EN 18031-2
Listing CRA on this DoC is wrong. See Declaration of Conformity 101 and Sample DoC walkthrough for full DoC structure.
Common mistakes
- Listing CRA "to be safe". CRA does not apply to MDR-regulated devices. A DoC listing CRA is factually incorrect and surfaces during NB surveillance and Member State market surveillance audits.
- Assuming RED is also carved out. RED has its own scope rules. Medical devices are not excluded from RED — they are subject to it in addition to MDR. The Blue Guide explicitly addresses this stack.
- Treating CGM as automatically MDR. Continuous glucose monitors with diagnostic intended purpose fall under IVDR Regulation (EU) 2017/746, not MDR. The CRA carve-out works the same way (Article 2(2)(b)), but the notified body, classification rules, and EUDAMED modules differ.
- Underestimating the notified body queue. Class IIa MDR submissions in 2026 still face multi-month waiting lists. Budget timeline accordingly.
- Treating the wellness-vs-medical line as soft. A step counter without a medical claim is a CRA-in-scope consumer product (no MDR). The same hardware with a medical claim is MDR-only. The intended purpose statement decides the entire regulatory stack.
- Skipping 3(3)(e) because "MDR already covers it". MDR Annex I §17 cybersecurity and RED 3(3)(e) personal-data safeguards are evaluated against different standards. EN 18031-2 must be applied for the RED 3(3)(e) claim.
How Cenitia helps
Cenitia's compliance platform classifies a connected medical wearable automatically against MDR Annex VIII, IVDR Annex VIII, RED, and CRA scope rules — and explicitly flags the CRA Article 2(2) carve-out so customers do not waste effort drafting CRA Annex I documentation that does not apply. The platform generates a single EU DoC listing only the regulations that bind: MDR plus RED, with the right notified body number, the EN 18031 harmonised standards, and the MDR Annex II technical documentation index.
When EUR-Lex publishes an amendment to MDR, RED Delegated Regulation 2022/30, or the EUDAMED module timeline, the Cenitia regulation watcher flags every affected DoC and technical file in your library — so a delegated act change on 1 August 2027 does not silently invalidate a CE submission you signed off in 2026.
One email at launch · cancel any time
Frequently asked questions
Does the Cyber Resilience Act apply to my ECG wearable?
No. Article 2(2) of Regulation (EU) 2024/2847 states the CRA does not apply to products with digital elements to which Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR) applies. An ECG wearable is a medical device under MDR, so the CRA carve-out applies — the cybersecurity baseline is MDR Annex I §17, not CRA Annex I.
Does RED still apply if MDR already covers cybersecurity?
Yes. RED 2014/53/EU is independent of MDR. Any radio equipment placed on the EU market must satisfy RED Article 3. From 1 August 2025, Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444) activates Article 3(3)(d) network protection and 3(3)(e) personal-data safeguards for wearables that process personal data — which most connected medical wearables do.
What MDR class is a typical connected wearable?
Most active monitoring wearables (ECG patches, glucose monitors, pulse oximeters with diagnostic claims) classify as IIa under MDR Annex VIII rule 10 (active devices for diagnosis). Some implanted or therapeutic devices reach IIb or III. Notified body involvement is mandatory from IIa upward per MDR Article 52.
Do I need to register in EUDAMED?
Yes. As of 28 May 2026 the first four EUDAMED modules — Actor, UDI/Devices, Notified Bodies and Certificates, and Vigilance — became mandatory per the Commission's EUDAMED page. Manufacturers obtain an SRN through the Actor module before placing devices on the market and register each device with its UDI-DI per MDR Article 27.
Can I put CRA on the Declaration of Conformity 'just in case'?
No. The DoC must list the Union legislation the product actually complies with, per the Blue Guide. If MDR is binding and CRA is excluded by Article 2(2), listing CRA is factually incorrect and creates audit risk during NB surveillance. List MDR and RED only.
What about the IVDR — does that overlap with CRA too?
Same carve-out. CRA Article 2(2) excludes products covered by Regulation (EU) 2017/746 (IVDR) on identical terms to MDR. A connected continuous glucose monitor that is regulated under IVDR (depending on its intended purpose) sits under IVDR + RED, not CRA.
Related from the Library
- CRA for existing products on market — how the CRA Article 2 carve-outs and the date-of-placing rule interact
- RED + CRA overlap for connected radio — when both apply and when (as here) only one does
- RED delegated act and EN 18031 walkthrough — Delegated Regulation 2022/30 detailed
- EN 18031 parts 1, 2, 3 comparison — the RED 3(3)(d)(e)(f) harmonised standards
- Declaration of Conformity 101 — the single-DoC principle and what to list
Further reading
- Regulation (EU) 2017/745 (MDR) — EUR-Lex
- Regulation (EU) 2024/2847 (CRA) — EUR-Lex
- Directive 2014/53/EU (RED) — EUR-Lex
- Commission Delegated Regulation (EU) 2022/30 — RED cybersecurity activation
- Commission Delegated Regulation (EU) 2023/2444 — postponement to 1 August 2025
- European Commission — EUDAMED
- MDCG 2019-16 — Guidance on cybersecurity for medical devices
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
Does the Cyber Resilience Act apply to my ECG wearable?
No. Article 2(2) of Regulation (EU) 2024/2847 states the CRA does not apply to products with digital elements to which Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR) applies. An ECG wearable is a medical device under MDR, so the CRA carve-out applies — the cybersecurity baseline is MDR Annex I §17, not CRA Annex I.
Does RED still apply if MDR already covers cybersecurity?
Yes. RED 2014/53/EU is independent of MDR. Any radio equipment placed on the EU market must satisfy RED Article 3. From 1 August 2025, Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444) activates Article 3(3)(d) network protection and 3(3)(e) personal-data safeguards for wearables that process personal data — which most connected medical wearables do.
What MDR class is a typical connected wearable?
Most active monitoring wearables (ECG patches, glucose monitors, pulse oximeters with diagnostic claims) classify as IIa under MDR Annex VIII rule 10 (active devices for diagnosis). Some implanted or therapeutic devices reach IIb or III. Notified body involvement is mandatory from IIa upward per MDR Article 52.
Do I need to register in EUDAMED?
Yes. As of 28 May 2026 the first four EUDAMED modules — Actor, UDI/Devices, Notified Bodies and Certificates, and Vigilance — became mandatory per the Commission's EUDAMED page. Manufacturers obtain an SRN through the Actor module before placing devices on the market and register each device with its UDI-DI per MDR Article 27.
Can I put CRA on the Declaration of Conformity 'just in case'?
No. The DoC must list the Union legislation the product actually complies with, per the Blue Guide. If MDR is binding and CRA is excluded by Article 2(2), listing CRA is factually incorrect and creates audit risk during NB surveillance. List MDR and RED only.
What about the IVDR — does that overlap with CRA too?
Same carve-out. CRA Article 2(2) excludes products covered by Regulation (EU) 2017/746 (IVDR) on identical terms to MDR. A connected continuous glucose monitor that is regulated under IVDR (depending on its intended purpose) sits under IVDR + RED, not CRA.
Continue reading
Related guides
guide
CE marking for industrial sensors and gateways
EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.
9 min read
guide
CE marking for IoT consumer products — end-to-end
End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.
9 min read
reference
EN 62368-1 — safety for audio/video and ICT equipment
EN IEC 62368-1 (3rd ed., 2018) is the hazard-based safety standard replacing EN 60950-1 and EN 60065 — energy classes, safeguards, LVD presumption of conformity.
8 min read
reference
IEC 62443 family overview for product manufacturers
Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.
10 min read
Put this into practice
Free tools & references
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
- Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.