Join Essenvia at RAPS Convergence 2026 — Booth #918
· Charlotte, 15–17 September
Read more →

When does a device change require a new submission?
A decision framework for multi-market portfolios
By Soumya Mahapatra

When does a device change require a new submission? A decision framework for multi-market portfolios
Your change control board approved a change on Thursday. The device is registered in eleven countries. Someone now has to decide, market by market, whether that change goes iqnto the file, into a notification, or into a new submission — and whether the product can ship before those answers come back.
Most teams assess the change once, usually against FDA, then treat every other market as a stricter or looser version of that answer. That is the error. Markets do not sit on a single strictness scale. They ask different questions, and the same change can be trivial in the market you assumed was hardest and blocking in the one you assumed was easy.
The question is not "how big is this change"
Two different kinds of triggers govern change control, and they key on completely different things.
Most change-control systems carry one field for regulatory impact. Someone assesses the change, writes "no significant change — letter to file," and the record closes. That works until an inspector in a second market asks why the registration dossier names a supplier that stopped shipping two years ago.
The error is treating "significance" as a property of the change instead of the output of a question, that varies:
A risk-based trigger asks what the change does to the device. Could it significantly affect safety or effectiveness? The evidence that answers it is engineering and clinical: risk analysis, verification data, biocompatibility, human factors. The regulation gives you a decision framework and you reason your way through it.
A dossier-based trigger asks whether the change alters something you told the authority. The evidence that answers it is not engineering at all. It is the text of your own filing. If the attribute you changed appears as an approved matter on the certificate, the change is loud regardless of how small it is. If it does not appear, the change may be silent regardless of how large it is.
Dossier-based triggers are where multi-market teams get caught. A process change with no specification change and no measurable performance delta can be a non-event under a risk test and a mandatory notification under a dossier test — because you named the manufacturing site or the material supplier in the original application. Nothing about the device changed. Something about the file did.
That distinction is the whole framework. Assess the change once, technically. Then route it through each market's actual question separately.
What each regime is actually asking
[VERIFY: every row of this table against the numbered sources below — instrument, current revision, cited article or section number, and the wording of the trigger. This table is the spine of the piece and must be signed off line by line by a market-specific SME before publication. Confidence gradings in the source list say where to concentrate.]
Market | Governing instrument | The question it asks | Trigger type |
US (510(k) devices) | 21 CFR 807.81(a)(3); FDA, Deciding When to Submit a 510(k) for a Change to an Existing Device, final guidance, 25 October 2017 — sources [1], [2] | Could the change significantly affect safety or effectiveness? | Risk-based, with documented rationale retained if the answer is no |
US (PMA devices) | 21 CFR 814.39; FDA, Modifications to Devices Subject to Premarket Approval (PMA) — The PMA Supplement Decision-Making Process, December 2008 — source [5] | Which supplement type does the change require, or can it travel as a 30-day notice? | Tiered, with the tier set by change category |
EU (MDR- certified) | Regulation (EU) 2017/745, Art. 10(9) and Annex IX §4 — source [6] | Is this a change to the approved design or intended purpose, or to the quality system that the notified body must be told about? | Contractual and dossier-based, mediated by your notified body |
EU (legacy devices) | MDR Art. 120 as amended by Regulation (EU) 2023/607; MDCG 2020-3 Rev.1 — sources [7], [8] | Is this a "significant change in design or intended purpose"? If yes, the transitional relief ends. | Risk-based, but with a cliff-edge consequence rather than a filing |
Canada | Medical Devices Regulations, SOR/98-282, s.1 ("significant change") and s.34; Health Canada, Guidance for the Interpretation of Significant Change of a Medical Device — sources [9], [10] | Does the change meet the regulatory definition of a significant change? | Definitional — you test the change against enumerated categories |
Japan | PMD Act (Act No. 145 of 1960, as amended), Art. 23-2-5: partial change approval application vs minor change notification — source [11] | Does this fall outside what a minor change notification can cover? | Dossier-based, with an approval pathway for anything not minor |
Brazil | ANVISA RDC No. 751/2022 — source [12] | Does the change alter information in the registration? | Dossier-based |
Australia | Therapeutic Goods Act 1989, s.41FN; Therapeutic Goods (Medical Devices) Regulations 2002 — sources [13], [14] | Does the change affect the basis of the ARTG entry or the conformity assessment evidence? | Dossier-based, layered on top of the EU or other conformity assessment you relied on |
The second-order consequence is the part practitioners underuse. Dossier-based obligations are partly self-inflicted. Two manufacturers selling identical devices in the same country can carry different change-control burdens, because each chose to declare different things at original filing. A manufacturer who wrote "Ti-6Al-4V ELI per ASTM F136" into the approved specification is free to change mills. A manufacturer who wrote the mill's name into the same field is not. Neither regulation nor device differs. The filing does.
A note on the two-category model. Risk-based and dossier-based are the two families that carry most of the practical load, but they are a compression. In practice you will hit four: risk-based (reason from consequence), dossier-based (diff against the declaration), enumerated (the regulation lists change types that are significant by definition, no reasoning required), and contractual (your notified body's or distributor's agreement obliges you to notify on terms narrower than the law). Health Canada's significant change definition is largely enumerated. Distribution and authorised-representative agreements are contractual. Neither collapses cleanly into the two families. Use the two-family model to triage; check for the other two before you close the assessment.
Two changes that invert each other
The clearest way to see this is to run two changes: that a change control board would rank in one order, and a global regulatory assessment ranks in the opposite order.
Change A — supplier change on an implant. A titanium dental abutment. New bar stock mill in a different country. Same alloy, same material specification, same incoming acceptance criteria, no dimensional or design change. On an engineering scale this is a purchasing decision.
Change B - cybersecurity patch on an active implant. An implantable pulse generator firmware patch closes an authentication weakness in the telemetry link. No change to the therapy algorithm, no new function, no new indication. On an engineering scale this is a bigger deal than a mill change.
Here is how each lands.Read the two columns against each other. The change with no engineering content is the expensive one in the US. The change with real engineering content is close to free there and expensive in Asia. A change control process that escalates by engineering magnitude will be wrong in both directions, and it will be wrong quietly — nobody raises a flag when a filing obligation is missed, because the trigger sat in a document nobody opened.
A · Bar stock supplier change | B · Firmware security patch | |
FDA | Material change on a permanently implanted device routes into the materials decision logic and toward re-establishing biocompatibility. If you need new biological testing to show equivalence, that is usually the signal you are past a letter-to-file. | Routine security patches that restore or maintain safety, without changing intended use or introducing new risk, are generally treated as device enhancements rather than as changes requiring a new 510(k). |
EU MDR | Turns on whether the material is type-defining in the certified design and whether the mill is a critical subcontractor or critical supplier under the approved QMS. Both routes go through the notified body, but they are different processes with different clocks. | A security patch that does not change intended purpose or performance is commonly handled as a non-substantial change under the notified body's change-notification process — but the definition of substantial change for software is not applied uniformly across notified bodies. |
Health Canada | The significant change definition is enumerated and expressly reaches manufacturing process, material and quality control changes, which makes reasoning-from-low-risk a weaker defence here than at FDA. | Software change guidance applies; risk to safety and effectiveness governs. |
Japan | If the approved matters name only the material specification, the mill change is a minor change notification or nothing at all. If the manufacturing method section names the supplier or the manufacturing site, it is a partial change approval application with a review clock attached. | Where the software version is an approved matter, a version increment is a change to the certificate irrespective of what the patch does. |
China | The registration certificate and technical requirements describe structure, composition and specification. A mill change that leaves the declared composition and specification untouched typically does not reach a licensing-item change. | Where the software release version appears on the registration certificate or in the registered product technical requirements, incrementing it is a change to a registered item. |
The framework
Run this per change, per market. It is deliberately not a single global assessment.
/

Alt text:
Four things make this work in practice.
Step | What you are actually looking at | The common failure |
1 · Pull the filing before the regulation | The approved certificate, registered technical requirements, and the technical file as certified — for that specific market | Reading the regulation first. In a dossier market the regulation tells you the process; your own filing tells you whether the process applies. |
2 · Classify the trigger | Which of the four families governs this change type in this market | Classifying the market rather than the change. No market is purely one type. Japan applies risk logic to some change categories; FDA reaches for enumeration in others. |
3 · Diff, don't assess | For dossier triggers: a literal comparison of changed attribute against declared text | Assessing risk. A dossier trigger is indifferent to your risk conclusion, and a well-argued risk rationale is not a defence to an undeclared change to a declared attribute. |
4 · Sequence by clock, not by importance | Which market's review clock is longest, and whether that market gates manufacture or only its own supply | Cutting over globally on the date the largest market clears, and shipping non-conforming products into a market still holding the old certificate. |
Where this is genuinely unclear
Three areas where practice diverges and anyone telling you the answer is clean is not doing the work:
Process changes with no specification change. Nothing measurable moves. Some regimes care because the site or method was declared; some don't. There is no general rule, only your dossiers.
Aggregation windows. How far back you look is a judgment. Reasonable teams pick different baselines and both defend them.
Supplier changes at tier two and below. Whether a change at your supplier's supplier is your change at all depends on what you named and what you control. [VERIFY: whether any jurisdiction addresses sub-tier supplier changes explicitly.]
What to do Monday
Pull the last three changes your team implemented and closed as non-significant. For each one, retrieve the registration dossier for your two most document-heavy markets and check whether what you filed still describes what you make. You are looking for one thing: a change where the risk assessment was right and the dossier check was never done. If you find one, you have found a systematic gap, not an isolated miss — and the fix is a routing step, not a stricter risk threshold.
When does a device change require a new submission? A decision framework for multi-market portfolios
Your change control board approved a change on Thursday. The device is registered in eleven countries. Someone now has to decide, market by market, whether that change goes iqnto the file, into a notification, or into a new submission — and whether the product can ship before those answers come back.
Most teams assess the change once, usually against FDA, then treat every other market as a stricter or looser version of that answer. That is the error. Markets do not sit on a single strictness scale. They ask different questions, and the same change can be trivial in the market you assumed was hardest and blocking in the one you assumed was easy.
The question is not "how big is this change"
Two different kinds of triggers govern change control, and they key on completely different things.
Most change-control systems carry one field for regulatory impact. Someone assesses the change, writes "no significant change — letter to file," and the record closes. That works until an inspector in a second market asks why the registration dossier names a supplier that stopped shipping two years ago.
The error is treating "significance" as a property of the change instead of the output of a question, that varies:
A risk-based trigger asks what the change does to the device. Could it significantly affect safety or effectiveness? The evidence that answers it is engineering and clinical: risk analysis, verification data, biocompatibility, human factors. The regulation gives you a decision framework and you reason your way through it.
A dossier-based trigger asks whether the change alters something you told the authority. The evidence that answers it is not engineering at all. It is the text of your own filing. If the attribute you changed appears as an approved matter on the certificate, the change is loud regardless of how small it is. If it does not appear, the change may be silent regardless of how large it is.
Dossier-based triggers are where multi-market teams get caught. A process change with no specification change and no measurable performance delta can be a non-event under a risk test and a mandatory notification under a dossier test — because you named the manufacturing site or the material supplier in the original application. Nothing about the device changed. Something about the file did.
That distinction is the whole framework. Assess the change once, technically. Then route it through each market's actual question separately.
What each regime is actually asking
[VERIFY: every row of this table against the numbered sources below — instrument, current revision, cited article or section number, and the wording of the trigger. This table is the spine of the piece and must be signed off line by line by a market-specific SME before publication. Confidence gradings in the source list say where to concentrate.]
Market | Governing instrument | The question it asks | Trigger type |
US (510(k) devices) | 21 CFR 807.81(a)(3); FDA, Deciding When to Submit a 510(k) for a Change to an Existing Device, final guidance, 25 October 2017 — sources [1], [2] | Could the change significantly affect safety or effectiveness? | Risk-based, with documented rationale retained if the answer is no |
US (PMA devices) | 21 CFR 814.39; FDA, Modifications to Devices Subject to Premarket Approval (PMA) — The PMA Supplement Decision-Making Process, December 2008 — source [5] | Which supplement type does the change require, or can it travel as a 30-day notice? | Tiered, with the tier set by change category |
EU (MDR- certified) | Regulation (EU) 2017/745, Art. 10(9) and Annex IX §4 — source [6] | Is this a change to the approved design or intended purpose, or to the quality system that the notified body must be told about? | Contractual and dossier-based, mediated by your notified body |
EU (legacy devices) | MDR Art. 120 as amended by Regulation (EU) 2023/607; MDCG 2020-3 Rev.1 — sources [7], [8] | Is this a "significant change in design or intended purpose"? If yes, the transitional relief ends. | Risk-based, but with a cliff-edge consequence rather than a filing |
Canada | Medical Devices Regulations, SOR/98-282, s.1 ("significant change") and s.34; Health Canada, Guidance for the Interpretation of Significant Change of a Medical Device — sources [9], [10] | Does the change meet the regulatory definition of a significant change? | Definitional — you test the change against enumerated categories |
Japan | PMD Act (Act No. 145 of 1960, as amended), Art. 23-2-5: partial change approval application vs minor change notification — source [11] | Does this fall outside what a minor change notification can cover? | Dossier-based, with an approval pathway for anything not minor |
Brazil | ANVISA RDC No. 751/2022 — source [12] | Does the change alter information in the registration? | Dossier-based |
Australia | Therapeutic Goods Act 1989, s.41FN; Therapeutic Goods (Medical Devices) Regulations 2002 — sources [13], [14] | Does the change affect the basis of the ARTG entry or the conformity assessment evidence? | Dossier-based, layered on top of the EU or other conformity assessment you relied on |
The second-order consequence is the part practitioners underuse. Dossier-based obligations are partly self-inflicted. Two manufacturers selling identical devices in the same country can carry different change-control burdens, because each chose to declare different things at original filing. A manufacturer who wrote "Ti-6Al-4V ELI per ASTM F136" into the approved specification is free to change mills. A manufacturer who wrote the mill's name into the same field is not. Neither regulation nor device differs. The filing does.
A note on the two-category model. Risk-based and dossier-based are the two families that carry most of the practical load, but they are a compression. In practice you will hit four: risk-based (reason from consequence), dossier-based (diff against the declaration), enumerated (the regulation lists change types that are significant by definition, no reasoning required), and contractual (your notified body's or distributor's agreement obliges you to notify on terms narrower than the law). Health Canada's significant change definition is largely enumerated. Distribution and authorised-representative agreements are contractual. Neither collapses cleanly into the two families. Use the two-family model to triage; check for the other two before you close the assessment.
Two changes that invert each other
The clearest way to see this is to run two changes: that a change control board would rank in one order, and a global regulatory assessment ranks in the opposite order.
Change A — supplier change on an implant. A titanium dental abutment. New bar stock mill in a different country. Same alloy, same material specification, same incoming acceptance criteria, no dimensional or design change. On an engineering scale this is a purchasing decision.
Change B - cybersecurity patch on an active implant. An implantable pulse generator firmware patch closes an authentication weakness in the telemetry link. No change to the therapy algorithm, no new function, no new indication. On an engineering scale this is a bigger deal than a mill change.
Here is how each lands.Read the two columns against each other. The change with no engineering content is the expensive one in the US. The change with real engineering content is close to free there and expensive in Asia. A change control process that escalates by engineering magnitude will be wrong in both directions, and it will be wrong quietly — nobody raises a flag when a filing obligation is missed, because the trigger sat in a document nobody opened.
A · Bar stock supplier change | B · Firmware security patch | |
FDA | Material change on a permanently implanted device routes into the materials decision logic and toward re-establishing biocompatibility. If you need new biological testing to show equivalence, that is usually the signal you are past a letter-to-file. | Routine security patches that restore or maintain safety, without changing intended use or introducing new risk, are generally treated as device enhancements rather than as changes requiring a new 510(k). |
EU MDR | Turns on whether the material is type-defining in the certified design and whether the mill is a critical subcontractor or critical supplier under the approved QMS. Both routes go through the notified body, but they are different processes with different clocks. | A security patch that does not change intended purpose or performance is commonly handled as a non-substantial change under the notified body's change-notification process — but the definition of substantial change for software is not applied uniformly across notified bodies. |
Health Canada | The significant change definition is enumerated and expressly reaches manufacturing process, material and quality control changes, which makes reasoning-from-low-risk a weaker defence here than at FDA. | Software change guidance applies; risk to safety and effectiveness governs. |
Japan | If the approved matters name only the material specification, the mill change is a minor change notification or nothing at all. If the manufacturing method section names the supplier or the manufacturing site, it is a partial change approval application with a review clock attached. | Where the software version is an approved matter, a version increment is a change to the certificate irrespective of what the patch does. |
China | The registration certificate and technical requirements describe structure, composition and specification. A mill change that leaves the declared composition and specification untouched typically does not reach a licensing-item change. | Where the software release version appears on the registration certificate or in the registered product technical requirements, incrementing it is a change to a registered item. |
The framework
Run this per change, per market. It is deliberately not a single global assessment.
/

Alt text:
Four things make this work in practice.
Step | What you are actually looking at | The common failure |
1 · Pull the filing before the regulation | The approved certificate, registered technical requirements, and the technical file as certified — for that specific market | Reading the regulation first. In a dossier market the regulation tells you the process; your own filing tells you whether the process applies. |
2 · Classify the trigger | Which of the four families governs this change type in this market | Classifying the market rather than the change. No market is purely one type. Japan applies risk logic to some change categories; FDA reaches for enumeration in others. |
3 · Diff, don't assess | For dossier triggers: a literal comparison of changed attribute against declared text | Assessing risk. A dossier trigger is indifferent to your risk conclusion, and a well-argued risk rationale is not a defence to an undeclared change to a declared attribute. |
4 · Sequence by clock, not by importance | Which market's review clock is longest, and whether that market gates manufacture or only its own supply | Cutting over globally on the date the largest market clears, and shipping non-conforming products into a market still holding the old certificate. |
Where this is genuinely unclear
Three areas where practice diverges and anyone telling you the answer is clean is not doing the work:
Process changes with no specification change. Nothing measurable moves. Some regimes care because the site or method was declared; some don't. There is no general rule, only your dossiers.
Aggregation windows. How far back you look is a judgment. Reasonable teams pick different baselines and both defend them.
Supplier changes at tier two and below. Whether a change at your supplier's supplier is your change at all depends on what you named and what you control. [VERIFY: whether any jurisdiction addresses sub-tier supplier changes explicitly.]
What to do Monday
Pull the last three changes your team implemented and closed as non-significant. For each one, retrieve the registration dossier for your two most document-heavy markets and check whether what you filed still describes what you make. You are looking for one thing: a change where the risk assessment was right and the dossier check was never done. If you find one, you have found a systematic gap, not an isolated miss — and the fix is a routing step, not a stricter risk threshold.
See what your portfolio looks like when everything is sellable — and audit-ready.
A 30-minute demo, on your products and your markets. No sandbox, no trial to configure — a working conversation with people who know regulatory.
See what your portfolio looks like when everything is sellable — and audit-ready.
A 30-minute demo, on your products and your markets. No sandbox, no trial to configure — a working conversation with people who know regulatory.
See what your portfolio looks like when everything is sellable — and audit-ready.
A 30-minute demo, on your products and your markets. No sandbox, no trial to configure — a working conversation with people who know regulatory.


