EPPA Regulatory Roadmap — Phased Plan
Phases, not dates
This roadmap is phase-ordered, not calendar-ordered. Each phase has
deliverables, a person-month effort estimate and a list of organisational
milestones that must complete before the next phase starts. Firm dates
are absent on purpose — they will be set per deployment by the Product
and Regulatory leads.
1. Document identity
| Field |
Value |
| Document title |
EPPA Regulatory Roadmap |
| Document ID |
EPPA-ROADMAP-001 |
| Version |
0.1 (draft) |
| Status |
Draft — not approved |
| Effective date |
n/a |
| Owner |
LABIS UCA — Regulatory lead (pending) |
| Linked documents |
every other compliance document, in particular 00-overview.md §5 |
2. Phase summary
┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐
│ Phase 0 │ ─→ │ Phase 1 │ ─→ │ Phase 2 │ ─→ │ Phase 3 │ ─→ │ Phase 4 │ ─→ │ Phase 5 │
│ RUO │ │ GDPR- │ │ Clinical │ │ ISO 13485│ │ CE mark │ │ FDA SaMD │
│ research │ │ compliant│ │ validation│ │ + IEC │ │ Class IIa│ │ 510(k) / │
│ │ │ ops │ │ study │ │ 62304 │ │ │ │ De Novo │
└───────────┘ └───────────┘ └───────────┘ └───────────┘ └───────────┘ └───────────┘
| Phase |
Theme |
Person-months estimate |
Critical org milestone |
| 0 |
Research-Use Only (current) |
ongoing |
n/a |
| 1 |
GDPR-compliant ops, audit log, consent |
8 to 12 |
Privacy lead hired (or external DPO contracted) |
| 2 |
Single-site clinical validation study |
18 to 30 |
Clinical lead hired; IRB approval secured |
| 3 |
ISO 13485 QMS + IEC 62304 lifecycle artefacts |
14 to 20 |
QMS certifier engaged; auditor selected |
| 4 |
CE marking submission (Class IIa) |
12 to 18 |
Notified body engaged; clinical evaluation closed |
| 5 |
FDA SaMD pathway (510(k) likely) |
10 to 16 |
US regulatory consultant engaged |
3. Phase 0 — Research-Use Only (current state)
This phase characterises EPPA today: a research instrument carrying the
non-device disclaimer in every surface, used by trained clinicians within
approved research protocols.
3.1 Deliverables (already in place or in flight)
3.2 Effort
n/a — this is the current state. Maintenance effort is ~1 person-month
per year for documentation upkeep until Phase 1 starts.
3.3 Gate to leave Phase 0
- Phase 1 backlog (§4.1) approved by Product and Regulatory leads.
- Funding for Phase 1 secured.
- Privacy lead identified (internal or external).
4. Phase 1 — GDPR-compliant operations
The goal of Phase 1 is to operationalise the privacy-compliance posture
already drafted, and to introduce the persistence and audit-log
infrastructure (Epic E3) without which downstream phases cannot begin.
4.1 Deliverables
| Deliverable |
Owner |
Reference |
| Software persistence (Postgres, Patient, Marker, Analysis, Session, AuditLog, ConsentRecord, User entities) |
Software |
Epic E3 |
| Authentication and authorisation (Argon2id, JWT RS256, RBAC) |
Software |
50-secdev-checklist.md §4–§6 |
Encryption at rest (pgcrypto for sensitive columns; KMS-managed key) |
Software |
50-secdev-checklist.md §9 |
| AuditLog with immutable append-only semantics and 10-year retention |
Software |
30-gdpr-dpia.md §7 |
| Consent management (per-patient ConsentRecord, with withdrawal flow) |
Software + Privacy |
30-gdpr-dpia.md §6 |
| Operational privacy notices in es / en / de / pt-BR |
Privacy + Marketing |
30-gdpr-dpia.md, 32-ar-lopdp.md, 33-br-lgpd.md, 34-de-gdpr-bdsg.md |
| Data Subject Access Request (DSAR) runbook |
Privacy |
30-gdpr-dpia.md §6 |
| Processor (AV-Vertrag) contracts with every operator (hosting, SMTP, backup) |
Legal |
34-de-gdpr-bdsg.md §6 |
| AAIP database registration in Argentina |
Privacy |
32-ar-lopdp.md §4 |
| Penetration test report (annual) |
Security |
50-secdev-checklist.md §19 |
security.txt published |
Security |
50-secdev-checklist.md §18 |
| Coordinated vulnerability disclosure policy |
Security |
Same |
4.2 Person-month estimate
| Workstream |
PM |
| Software (Epic E3) |
4 to 6 |
| Privacy (DPIA finalisation, notices, AV contracts, registrations) |
2 to 3 |
| Security (controls, pen test, runbooks) |
1 to 2 |
| Documentation upkeep |
1 |
| Total |
8 to 12 |
4.3 Required organisational milestones
- Privacy lead hired or external DPO contracted.
- Security lead identified.
- Legal counsel engaged for AV-Verträge / DPAs / BAA template.
- Bank account / billing relationship with hosting provider with executed DPA.
4.4 Gate to leave Phase 1
- DPIA signed by DPO and controller.
- AuditLog in production with 30 days of retention demonstrated.
- DSAR runbook tested end-to-end.
- AAIP registration confirmation received.
- At least one external penetration test report with no Critical/High
findings.
5. Phase 2 — Single-site clinical validation study
EPPA must accumulate clinical evidence before EU MDR Art. 61 / FDA
substantial equivalence claims are credible. A single-site, IRB-approved,
peer-reviewed validation study is the minimum viable evidence base.
5.1 Deliverables
| Deliverable |
Owner |
Reference |
| Clinical investigation plan (CIP) under ISO 14155:2020 |
Clinical lead |
00-overview.md §5 Phase 2 |
| IRB / ethics-committee approval |
Clinical lead |
Per institutional procedure |
| Patient information sheet and consent form, per locale |
Clinical lead |
Compliant with locale's medical research law |
| Investigator brochure |
Clinical lead |
ISO 14155 Annex B |
| Case report forms (CRF) |
Clinical lead + Data |
ISO 14155 §6.5 |
| Statistical analysis plan (SAP) |
Clinical lead + Data |
ISO 14155 §6.4 |
| Data management plan (DMP) |
Data |
Aligned with the DPIA |
| Study report and submission for peer review |
Clinical lead |
Targets a kinesiology / physiotherapy journal |
| Update to risk file with field data |
Quality |
12-iso-14971-risk.md §10 |
5.2 Person-month estimate
| Workstream |
PM |
| Clinical lead |
6 to 10 |
| Software (study-only features: structured data export, audit detail) |
2 to 3 |
| Data management |
3 to 5 |
| Statistics |
2 to 3 |
| Regulatory + documentation |
2 to 3 |
| Writing and submission |
3 to 6 |
| Total |
18 to 30 |
5.3 Required organisational milestones
- Clinical lead hired (PhD-level kinesiologist or postural-medicine
physician with prior clinical-study experience).
- Statistical consultant engaged (or in-house biostatistician).
- IRB / ethics-committee partnership in place.
- Funding for the study secured (likely grant-funded; estimated EUR 80–150 K
for a 60-patient single-site study with 12-month follow-up).
5.4 Gate to leave Phase 2
- Peer-reviewed publication accepted (or under revision after favourable
reviewer comments).
- Study report available as input to the EU MDR clinical evaluation report.
- Risk file updated with field-observed failure modes.
6. Phase 3 — ISO 13485 QMS + IEC 62304 SDLC artefacts
For EU MDR and FDA QMSR purposes, the QMS and the software lifecycle file
must be formalised under the relevant standards. Without this layer, no
notified body or FDA reviewer will accept the technical documentation.
6.1 Deliverables
| Deliverable |
Owner |
Reference |
| QMS Manual (ISO 13485:2016) |
Quality |
n/a |
| Document control procedure |
Quality |
ISO 13485 §4.2 |
| Records control procedure |
Quality |
ISO 13485 §4.2 |
| Management review process |
Quality + Exec |
ISO 13485 §5 |
| CAPA (Corrective and Preventive Action) procedure |
Quality |
ISO 13485 §8.5.2, §8.5.3 |
| Internal-audit programme |
Quality |
ISO 13485 §8.2.4 |
| Software Development Plan |
Software |
11-iec-62304-lifecycle.md §6 |
| Software Architecture Description |
Software |
11-iec-62304-lifecycle.md §7 |
| Software Requirements Specification |
Software + Clinical |
n/a |
| V&V plan and reports |
Software + QA |
11-iec-62304-lifecycle.md §8 |
| SOUP register (authoritative) |
Software |
11-iec-62304-lifecycle.md §5 |
| Configuration management plan |
Software |
11-iec-62304-lifecycle.md §4 |
| Problem-resolution procedure |
Software + Quality |
Same |
| Risk file closed (ISO 14971) |
Quality |
12-iso-14971-risk.md |
| Cybersecurity assessment per MDCG 2019-16 / IEC 81001-5-1 |
Security + Quality |
50-secdev-checklist.md §17 |
| QMS audit by certifier (Stage 1 + Stage 2) |
External auditor |
n/a |
| ISO 13485 certificate issued |
External auditor |
n/a |
6.2 Person-month estimate
| Workstream |
PM |
| Quality (QMS build-up) |
6 to 9 |
| Software (lifecycle artefacts) |
4 to 6 |
| Security (cybersecurity file) |
1 to 2 |
| External audit prep + audit response |
3 |
| Total |
14 to 20 |
6.3 Required organisational milestones
- Head of Quality hired or contracted (often a regulated-industry QA with
prior ISO 13485 build-out experience).
- ISO 13485 certifier engaged (BSI, DEKRA, TÜV SÜD, DNV typical for
Argentina/EU).
- Internal-audit cadence operational (minimum quarterly during Phase 3).
6.4 Gate to leave Phase 3
- ISO 13485 certificate issued with no Major nonconformities.
- IEC 62304 file (SDP, SAD, SRS, V&V, SOUP, CM) under change control.
- Risk file closed for the marketed configuration.
- Cybersecurity file aligned with MDCG 2019-16 Rev.1 and IEC 81001-5-1.
7. Phase 4 — CE marking (EU MDR Class IIa)
With Phase 3 complete, EPPA has the QMS, lifecycle and clinical-evidence
substrate to submit for CE marking under EU MDR.
7.1 Deliverables
| Deliverable |
Owner |
Reference |
| EU MDR technical documentation (Annex II + Annex III) |
Regulatory |
10-eu-mdr-saMD-classification.md §5.1 |
| Classification dossier (Rule 11) |
Regulatory |
10-eu-mdr-saMD-classification.md §4 |
| Clinical evaluation report (Art. 61, Annex XIV Part A) |
Clinical + Regulatory |
Uses Phase 2 study report as core input |
| Post-market surveillance plan (Art. 83, Annex III) |
Regulatory |
n/a |
| Periodic Safety Update Report template (Art. 86) |
Regulatory |
n/a |
| Vigilance procedures (Art. 87–92) |
Regulatory + Quality |
n/a |
| Declaration of Conformity (Annex IV) |
Regulatory |
n/a |
| UDI assignment (Basic UDI-DI + per-version UDI-DI) |
Regulatory |
10-eu-mdr-saMD-classification.md §6 |
| Labelling and IFU per Annex I §23 |
Regulatory + Product |
01-intended-use-statement.md is the seed |
| EUDAMED Actor + UDI + Device registration |
Regulatory |
10-eu-mdr-saMD-classification.md §6 |
| Notified-body conformity assessment (Annex IX Ch I + Ch III §4) |
Notified body |
n/a |
| EC certificate issued |
Notified body |
n/a |
7.2 Person-month estimate
| Workstream |
PM |
| Regulatory (technical file) |
6 to 8 |
| Clinical (CER drafting) |
2 to 3 |
| Quality (audit response) |
1 to 2 |
| Software (any required hardening from audit findings) |
1 to 2 |
| Localisation (IFU in EU languages of marketing) |
2 to 3 |
| Total |
12 to 18 |
7.3 Required organisational milestones
- Notified body engaged (designation verified per
10-eu-mdr-saMD-classification.md §5.2).
- Person Responsible for Regulatory Compliance (PRRC, Art. 15) appointed.
- Authorised Representative in the EU (Art. 11) appointed if manufacturer
is outside the EU.
- Vigilance email and process operational.
7.4 Gate to leave Phase 4
- EC certificate issued and registered in EUDAMED.
- Non-device disclaimer removed in EU locales (per the conditions in
91-non-device-disclaimer.md §4).
- First commercial deployment under post-market surveillance.
8. Phase 5 — FDA SaMD pathway (510(k) likely)
In parallel with Phase 4 or immediately after, file with the FDA. Order of
EU vs US is a strategic choice; EU-first is the default because EU MDR
allows broader market expansion immediately.
8.1 Deliverables
| Deliverable |
Owner |
Reference |
| Pre-submission Q-Sub to FDA |
Regulatory + US consultant |
20-fda-samd-path.md §4.4 |
| Predicate identification and substantial-equivalence analysis |
US consultant |
20-fda-samd-path.md §5 |
| 510(k) content per 21 CFR 807.87 |
Regulatory + US consultant |
20-fda-samd-path.md §6.1 |
| Software documentation per FDA June 2023 guidance (Enhanced level likely) |
Software + Regulatory |
20-fda-samd-path.md §6.1 |
| Cybersecurity submission per FDA September 2023 guidance |
Security + Regulatory |
20-fda-samd-path.md §12 |
| Establishment registration and device listing |
Regulatory |
21 CFR Part 807 |
| US labelling per 21 CFR Part 801 |
Regulatory + Product |
n/a |
| MDR procedures per 21 CFR Part 803 |
Regulatory + Quality |
20-fda-samd-path.md §10 |
| BAA template execution with first US customers |
Legal |
31-hipaa-readiness.md §7 |
| HIPAA Security Rule readiness |
Privacy + Security |
31-hipaa-readiness.md §10 |
| 510(k) clearance (or De Novo grant) |
FDA |
n/a |
8.2 Person-month estimate
| Workstream |
PM |
| US Regulatory consultant |
4 to 6 |
| Internal Regulatory |
2 to 3 |
| Software (FDA-specific documentation packaging) |
1 to 2 |
| Security (cybersecurity submission packaging) |
1 to 2 |
| Privacy (HIPAA readiness completion) |
1 to 2 |
| Legal (BAA template + first contracts) |
1 |
| Total |
10 to 16 |
8.3 Required organisational milestones
- US Regulatory consultant engaged.
- US Agent (per 21 CFR 807.40) appointed if manufacturer is outside the US.
- US deployment hosting provider with executed BAA.
- Quality system updated to QMSR-compatible state (after 2 February 2026
QMSR transition).
8.4 Gate to leave Phase 5
- 510(k) clearance (or De Novo grant) received.
- Non-device disclaimer removed in US locale.
- First US deployment under post-market MDR vigilance (21 CFR Part 803).
9. Cross-cutting concerns
| Concern |
Comment |
| Localisation |
Each phase that introduces a new market locale (es-AR, en, de, pt-BR) adds translation effort; budget ~10–15 % of the documentation effort for each additional locale. |
| Multi-site clinical research |
If Phase 2 expands to multi-site, GDPR joint-controller agreements (34-de-gdpr-bdsg.md §7) become load-bearing. |
| Brazil (ANVISA) |
Phase 4 + 5 do not cover Brazil. A separate ANVISA RDC 751/2022 submission will be needed; effort ≈ Phase 5 / 2. |
| Argentina (ANMAT) |
ANMAT registration runs in parallel with Phase 1 (privacy registration) and Phase 4 (device registration). Effort ≈ 2 PM. |
| Insurance |
Product liability insurance must be in place before any commercial deployment — typically Phase 4 closure. |
| Pricing and reimbursement |
Out of scope of regulatory roadmap; relevant for Product. |
10. Risk register for the roadmap itself
| # |
Risk |
Mitigation |
| RR1 |
Notified-body slot unavailable when Phase 4 is ready |
Engage notified body early in Phase 3; book a slot at Stage 1 audit |
| RR2 |
Phase 2 study fails to meet inter-rater agreement threshold |
Pilot study before main protocol; pre-register the threshold |
| RR3 |
Funding gap between Phase 2 and Phase 3 |
Apply for grants alongside Phase 1; consider commercial partnership |
| RR4 |
Regulatory landscape shift (e.g. EU MDR amendment, ANPD adequacy decision changes) |
Annual regulatory horizon scan |
| RR5 |
Cybersecurity incident in Phase 1 derails programme trust |
Annual pen test from Phase 1; security incident runbook tested quarterly |
| RR6 |
Key-person dependency (single regulatory lead) |
Document everything in this compliance/ set; cross-train at least two people on each domain |
11. Open questions
- Phase ordering: confirm EU-first vs US-first vs simultaneous.
- Single-site vs multi-site Phase 2: cost-benefit on broader clinical
evidence vs faster gate.
- Notified-body shortlist: lock in Phase 3.
- In-house vs contracted DPO: Phase 1 decision.
- Effort estimates: validate against industry benchmarks for SaMD
programmes of comparable size.
References