Cenitia launchesLaunching September 2026 — first 250 founders get the launch price locked for life.

Reserve your spot →
Cenitia
How it worksLibraryGlossaryRegulationsToolsAbout
Reserve your spot
How it worksLibraryGlossaryRegulationsToolsAbout

On this page

  • The three-regulation reality (and why CRA is missing)
  • MDR classification — the gatekeeping decision
  • The notified body route under MDR Article 52
  • The wireless side: RED still applies in full
  • EUDAMED registration is mandatory from 28 May 2026
  • The DoC: one document, two regulations
  • Common mistakes
  • How Cenitia helps
  • Frequently asked questions
  • Related from the Library
  • Further reading
← Library
guide·MDR, CRA, RED·9 min read

CE marking medical wearables — MDR + CRA overlap

How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.

By Vladimír Vician · 23 July 2026

TL;DR

A connected medical wearable — ECG patch, continuous glucose monitor, smart hearing aid — is CE-marked under MDR (Regulation (EU) 2017/745) plus RED (Directive 2014/53/EU). The Cyber Resilience Act is carved out for medical devices by Article 2(2) of Regulation (EU) 2024/2847. Cybersecurity flows through MDR Annex I §17 and RED 3(3)(d)(e) — not CRA Annex I.

This guide walks the practical CE path: MDR classification, notified body engagement for class IIa and above, EUDAMED registration, RED radio + cybersecurity clearance, and the single DoC that names both regulations.

Medical wearables are one of the few product categories where the overlap question is explicitly settled in law rather than left to interpretation. Article 2(2) of the Cyber Resilience Act states that the CRA does not apply to products with digital elements covered by Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR). This is not a future exemption — it is a direct exclusion in the CRA text itself, reflecting that medical-device cybersecurity is already addressed by MDR Annex I §17 and the MDCG 2019-16 cybersecurity guidance.

What does still apply, alongside MDR, is the Radio Equipment Directive 2014/53/EU — because RED catches the wireless radio inside the wearable, and RED Article 3(3)(d), (e), and (f) were activated by Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444, applicable from 1 August 2025) with wearables explicitly named in the scope of 3(3)(e).

Who this is for

Engineering, regulatory, and compliance leaders at companies building wireless medical wearables — ECG monitors, continuous glucose monitors, connected hearing aids, smart inhalers, sleep apnea sensors — who need to know which EU regulations bind their next CE submission. This article is not legal advice — for binding interpretation, consult your notified body and a qualified EU medical-device regulatory consultant.

The three-regulation reality (and why CRA is missing)

A connected medical wearable typically interacts with three EU regulatory frameworks. Only two of them actually bind:

RegulationApplies?Why
MDR (EU) 2017/745Yes — bindingMedical purpose triggers MDR Article 1 scope
RED 2014/53/EUYes — bindingContains radio (BLE, NFC, cellular, Wi-Fi)
CRA (EU) 2024/2847No — carved outExcluded by CRA Article 2(2)(a)
GPSR (EU) 2023/988Not for medical devicesExcluded by GPSR Article 2(2) for products covered by sector-specific legislation

The carve-out works the same way for IVDR-regulated diagnostic devices (Article 2(2)(b)) and for type-approved motor vehicles under Regulation (EU) 2019/2144 (Article 2(2)(c)). The legislator's logic: where mature sector-specific cybersecurity provisions already exist, layering CRA on top would create conflicting obligations.

"This Regulation does not apply to products with digital elements to which the following Union legal acts apply: (a) Regulation (EU) 2017/745; (b) Regulation (EU) 2017/746"

— Cyber Resilience Act, Article 2(2)

MDR classification — the gatekeeping decision

Under MDR Annex VIII, devices are sorted into classes I, IIa, IIb, and III in line with their risk profile. The four-class structure is confirmed in recital 58: "it is necessary…to maintain the division of devices into four product classes in line with international practice."

For wearables, the classification rule that usually applies is Rule 10 for active devices intended for diagnosis or monitoring of vital physiological processes. Practical examples:

DeviceTypical MDR classNotified body?
ECG patch (diagnostic)IIaYes
Continuous glucose monitor (CGM)IIb (or IVDR depending on intended purpose)Yes
Smart hearing aidIIaYes
Pulse oximeter (clinical)IIaYes
Implanted cardiac monitorIIIYes
Wellness step counter (no medical claim)Not a medical deviceNo (consumer route, plus CRA may apply)

The critical line is MDR Article 52 on conformity assessment procedures. As MDR recital 60 states: "For class IIa, class IIb and class III devices, an appropriate level of involvement of a notified body should be compulsory."

That single sentence drives most of the cost and timeline of a wearable CE submission.

The notified body route under MDR Article 52

For class IIa, manufacturers typically pick one of:

  • Annex IX — Quality Management System (QMS) plus technical documentation assessment of a representative sample.
  • Annex XI Part A — Production quality assurance (the lighter Annex IX-alternative for some IIa devices).

For class IIb and III, the route adds Annex X type examination or full QMS plus design dossier review. Implantables and class III almost always require Annex IX + Annex X combined.

Plan for 9 to 18 months between submitting a complete technical file and receiving the EC certificate, given continuing MDR notified body capacity bottlenecks in 2026. Selecting a designated MDR notified body — check NANDO — is non-negotiable.

Reserve your spot — Cenitia launches September 2026

One email at launch · cancel any time

The wireless side: RED still applies in full

CRA being carved out does not exempt the radio. Any wearable that emits or receives radio waves falls under Directive 2014/53/EU (RED). The relevant essential requirements:

  • Article 3(1)(a) — health and safety (overlaps with MDR but RED requirement remains).
  • Article 3(1)(b) — electromagnetic compatibility.
  • Article 3(2) — efficient use of the radio spectrum.
  • Article 3(3)(d) — "radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service".
  • Article 3(3)(e) — "radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected".

These last two (and (f) for monetary-value transfer) were activated by Commission Delegated Regulation (EU) 2022/30. The application date was postponed to 1 August 2025 by Commission Delegated Regulation (EU) 2023/2444, which replaced Article 3 second paragraph of 2022/30 with "It shall apply from 1 August 2025."

Wearables are explicitly named in 2022/30 Article 1 as falling within Article 3(3)(e) scope where they process personal data — and a wearable that uploads heart rhythm, blood glucose, or audiogram data is unambiguously processing personal data of the user.

The presumption-of-conformity standards are the EN 18031 series. See our EN 18031 parts 1/2/3 comparison and the RED delegated act walkthrough.

EUDAMED registration is mandatory from 28 May 2026

Per the European Commission's EUDAMED page, four EUDAMED modules became mandatory on 28 May 2026:

  1. Actor registration — manufacturer, authorised representative, importer obtain a Single Registration Number (SRN).
  2. UDI / Devices registration — every device registered with its UDI-DI per MDR Article 27.
  3. Notified Bodies and Certificates — NB-issued certificates published.
  4. Vigilance and PMS — serious-incident reporting and trend analysis.

This is sector-specific equivalent to what CRA Article 14 reporting does for non-medical products — but routed through EUDAMED to the relevant Member State authorities, not to ENISA. The 24-hour reporting clock that catches CRA products (see CRA ENISA 24-hour reporting) does not apply here.

The DoC: one document, two regulations

Per the Blue Guide single-DoC principle, manufacturers issue one EU Declaration of Conformity that lists every piece of Union legislation the product complies with. For a connected medical wearable, that is MDR + RED — not CRA.

A skeleton DoC for a class IIa connected ECG wearable lists:

  • Regulation (EU) 2017/745 (MDR) — conformity route Annex IX with NB 0123
  • Directive 2014/53/EU (RED) — essential requirements 3(1)(a), 3(1)(b), 3(2), 3(3)(d), 3(3)(e)
  • Harmonised standards applied — EN ISO 14971, EN 60601-1, EN 60601-1-2, EN 18031-1, EN 18031-2

Listing CRA on this DoC is wrong. See Declaration of Conformity 101 and Sample DoC walkthrough for full DoC structure.

Common mistakes

  • Listing CRA "to be safe". CRA does not apply to MDR-regulated devices. A DoC listing CRA is factually incorrect and surfaces during NB surveillance and Member State market surveillance audits.
  • Assuming RED is also carved out. RED has its own scope rules. Medical devices are not excluded from RED — they are subject to it in addition to MDR. The Blue Guide explicitly addresses this stack.
  • Treating CGM as automatically MDR. Continuous glucose monitors with diagnostic intended purpose fall under IVDR Regulation (EU) 2017/746, not MDR. The CRA carve-out works the same way (Article 2(2)(b)), but the notified body, classification rules, and EUDAMED modules differ.
  • Underestimating the notified body queue. Class IIa MDR submissions in 2026 still face multi-month waiting lists. Budget timeline accordingly.
  • Treating the wellness-vs-medical line as soft. A step counter without a medical claim is a CRA-in-scope consumer product (no MDR). The same hardware with a medical claim is MDR-only. The intended purpose statement decides the entire regulatory stack.
  • Skipping 3(3)(e) because "MDR already covers it". MDR Annex I §17 cybersecurity and RED 3(3)(e) personal-data safeguards are evaluated against different standards. EN 18031-2 must be applied for the RED 3(3)(e) claim.

How Cenitia helps

Cenitia's compliance platform classifies a connected medical wearable automatically against MDR Annex VIII, IVDR Annex VIII, RED, and CRA scope rules — and explicitly flags the CRA Article 2(2) carve-out so customers do not waste effort drafting CRA Annex I documentation that does not apply. The platform generates a single EU DoC listing only the regulations that bind: MDR plus RED, with the right notified body number, the EN 18031 harmonised standards, and the MDR Annex II technical documentation index.

When EUR-Lex publishes an amendment to MDR, RED Delegated Regulation 2022/30, or the EUDAMED module timeline, the Cenitia regulation watcher flags every affected DoC and technical file in your library — so a delegated act change on 1 August 2027 does not silently invalidate a CE submission you signed off in 2026.

Reserve your spot — Cenitia launches September 2026

One email at launch · cancel any time

Frequently asked questions

Does the Cyber Resilience Act apply to my ECG wearable?

No. Article 2(2) of Regulation (EU) 2024/2847 states the CRA does not apply to products with digital elements to which Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR) applies. An ECG wearable is a medical device under MDR, so the CRA carve-out applies — the cybersecurity baseline is MDR Annex I §17, not CRA Annex I.

Does RED still apply if MDR already covers cybersecurity?

Yes. RED 2014/53/EU is independent of MDR. Any radio equipment placed on the EU market must satisfy RED Article 3. From 1 August 2025, Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444) activates Article 3(3)(d) network protection and 3(3)(e) personal-data safeguards for wearables that process personal data — which most connected medical wearables do.

What MDR class is a typical connected wearable?

Most active monitoring wearables (ECG patches, glucose monitors, pulse oximeters with diagnostic claims) classify as IIa under MDR Annex VIII rule 10 (active devices for diagnosis). Some implanted or therapeutic devices reach IIb or III. Notified body involvement is mandatory from IIa upward per MDR Article 52.

Do I need to register in EUDAMED?

Yes. As of 28 May 2026 the first four EUDAMED modules — Actor, UDI/Devices, Notified Bodies and Certificates, and Vigilance — became mandatory per the Commission's EUDAMED page. Manufacturers obtain an SRN through the Actor module before placing devices on the market and register each device with its UDI-DI per MDR Article 27.

Can I put CRA on the Declaration of Conformity 'just in case'?

No. The DoC must list the Union legislation the product actually complies with, per the Blue Guide. If MDR is binding and CRA is excluded by Article 2(2), listing CRA is factually incorrect and creates audit risk during NB surveillance. List MDR and RED only.

What about the IVDR — does that overlap with CRA too?

Same carve-out. CRA Article 2(2) excludes products covered by Regulation (EU) 2017/746 (IVDR) on identical terms to MDR. A connected continuous glucose monitor that is regulated under IVDR (depending on its intended purpose) sits under IVDR + RED, not CRA.

Related from the Library

  • CRA for existing products on market — how the CRA Article 2 carve-outs and the date-of-placing rule interact
  • RED + CRA overlap for connected radio — when both apply and when (as here) only one does
  • RED delegated act and EN 18031 walkthrough — Delegated Regulation 2022/30 detailed
  • EN 18031 parts 1, 2, 3 comparison — the RED 3(3)(d)(e)(f) harmonised standards
  • Declaration of Conformity 101 — the single-DoC principle and what to list

Further reading

  • Regulation (EU) 2017/745 (MDR) — EUR-Lex
  • Regulation (EU) 2024/2847 (CRA) — EUR-Lex
  • Directive 2014/53/EU (RED) — EUR-Lex
  • Commission Delegated Regulation (EU) 2022/30 — RED cybersecurity activation
  • Commission Delegated Regulation (EU) 2023/2444 — postponement to 1 August 2025
  • European Commission — EUDAMED
  • MDCG 2019-16 — Guidance on cybersecurity for medical devices

Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.

FAQ

Frequently asked questions

  • Does the Cyber Resilience Act apply to my ECG wearable?+

    No. Article 2(2) of Regulation (EU) 2024/2847 states the CRA does not apply to products with digital elements to which Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR) applies. An ECG wearable is a medical device under MDR, so the CRA carve-out applies — the cybersecurity baseline is MDR Annex I §17, not CRA Annex I.

  • Does RED still apply if MDR already covers cybersecurity?+

    Yes. RED 2014/53/EU is independent of MDR. Any radio equipment placed on the EU market must satisfy RED Article 3. From 1 August 2025, Commission Delegated Regulation (EU) 2022/30 (as amended by 2023/2444) activates Article 3(3)(d) network protection and 3(3)(e) personal-data safeguards for wearables that process personal data — which most connected medical wearables do.

  • What MDR class is a typical connected wearable?+

    Most active monitoring wearables (ECG patches, glucose monitors, pulse oximeters with diagnostic claims) classify as IIa under MDR Annex VIII rule 10 (active devices for diagnosis). Some implanted or therapeutic devices reach IIb or III. Notified body involvement is mandatory from IIa upward per MDR Article 52.

  • Do I need to register in EUDAMED?+

    Yes. As of 28 May 2026 the first four EUDAMED modules — Actor, UDI/Devices, Notified Bodies and Certificates, and Vigilance — became mandatory per the Commission's EUDAMED page. Manufacturers obtain an SRN through the Actor module before placing devices on the market and register each device with its UDI-DI per MDR Article 27.

  • Can I put CRA on the Declaration of Conformity 'just in case'?+

    No. The DoC must list the Union legislation the product actually complies with, per the Blue Guide. If MDR is binding and CRA is excluded by Article 2(2), listing CRA is factually incorrect and creates audit risk during NB surveillance. List MDR and RED only.

  • What about the IVDR — does that overlap with CRA too?+

    Same carve-out. CRA Article 2(2) excludes products covered by Regulation (EU) 2017/746 (IVDR) on identical terms to MDR. A connected continuous glucose monitor that is regulated under IVDR (depending on its intended purpose) sits under IVDR + RED, not CRA.

Portrait of Vladimír Vician

Written by

Vladimír Vician

Founder, Cenitia · Founder & Managing Director, Inovasense s.r.o.

Founded Inovasense in Bratislava in 2016. Specialises in EU-sovereign hardware — FPGA and embedded systems design, embedded security, and regulatory compliance under the CRA, RED (EN 18031), and the harmonised standards each cites. Named signatory on every Declaration of Conformity Inovasense ships.

Best reached on LinkedIn. For longer enquiries, the Inovasense contact form.

Inovasense profile · More about Cenitia

Continue reading

Related guides

  • guide

    CE marking for industrial sensors and gateways

    EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.

    9 min read

  • guide

    CE marking for IoT consumer products — end-to-end

    End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.

    9 min read

  • reference

    EN 62368-1 — safety for audio/video and ICT equipment

    EN IEC 62368-1 (3rd ed., 2018) is the hazard-based safety standard replacing EN 60950-1 and EN 60065 — energy classes, safeguards, LVD presumption of conformity.

    8 min read

  • reference

    IEC 62443 family overview for product manufacturers

    Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.

    10 min read

Put this into practice

Free tools & references

  • EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
  • Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →

New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.

Reserve your spot — launching September 2026

One email at launch · cancel any time

← Back to Library

Cenitia

The EU compliance engine for hardware manufacturers. Cited drafts, electronic signing, regulation watching — all in one place.

A product of Inovasense s.r.o., Bratislava, Slovakia · Data hosted in Stockholm, EU

Site

  • How it works
  • Library
  • Glossary
  • Regulations
  • By product type
  • Tools
  • About

Legal

  • Imprint
  • Privacy
  • Terms

© 2026 Inovasense s.r.o. · cenitia.com

EU sovereign · EU data residency by design · Customer data never trains models