Zum Inhalt

EPPA Regulatory Roadmap — Phased Plan

Phases, not dates

This roadmap is phase-ordered, not calendar-ordered. Each phase has deliverables, a person-month effort estimate and a list of organisational milestones that must complete before the next phase starts. Firm dates are absent on purpose — they will be set per deployment by the Product and Regulatory leads.

1. Document identity

Field Value
Document title EPPA Regulatory Roadmap
Document ID EPPA-ROADMAP-001
Version 0.1 (draft)
Status Draft — not approved
Effective date n/a
Owner LABIS UCA — Regulatory lead (pending)
Linked documents every other compliance document, in particular 00-overview.md §5

2. Phase summary

   ┌───────────┐    ┌───────────┐    ┌───────────┐    ┌───────────┐    ┌───────────┐    ┌───────────┐
   │  Phase 0  │ ─→ │  Phase 1  │ ─→ │  Phase 2  │ ─→ │  Phase 3  │ ─→ │  Phase 4  │ ─→ │  Phase 5  │
   │   RUO     │    │  GDPR-    │    │  Clinical │    │  ISO 13485│    │  CE mark  │    │  FDA SaMD │
   │ research  │    │  compliant│    │ validation│    │  + IEC    │    │  Class IIa│    │  510(k) / │
   │           │    │  ops      │    │  study    │    │  62304    │    │           │    │  De Novo  │
   └───────────┘    └───────────┘    └───────────┘    └───────────┘    └───────────┘    └───────────┘
Phase Theme Person-months estimate Critical org milestone
0 Research-Use Only (current) ongoing n/a
1 GDPR-compliant ops, audit log, consent 8 to 12 Privacy lead hired (or external DPO contracted)
2 Single-site clinical validation study 18 to 30 Clinical lead hired; IRB approval secured
3 ISO 13485 QMS + IEC 62304 lifecycle artefacts 14 to 20 QMS certifier engaged; auditor selected
4 CE marking submission (Class IIa) 12 to 18 Notified body engaged; clinical evaluation closed
5 FDA SaMD pathway (510(k) likely) 10 to 16 US regulatory consultant engaged

3. Phase 0 — Research-Use Only (current state)

This phase characterises EPPA today: a research instrument carrying the non-device disclaimer in every surface, used by trained clinicians within approved research protocols.

3.1 Deliverables (already in place or in flight)

Deliverable File Status
Executive overview 00-overview.md DRAFT
Intended Use Statement 01-intended-use-statement.md DRAFT
Non-device disclaimer (4 locales) 91-non-device-disclaimer.md DRAFT
GDPR DPIA seed 30-gdpr-dpia.md DRAFT

3.2 Effort

n/a — this is the current state. Maintenance effort is ~1 person-month per year for documentation upkeep until Phase 1 starts.

3.3 Gate to leave Phase 0

  • Phase 1 backlog (§4.1) approved by Product and Regulatory leads.
  • Funding for Phase 1 secured.
  • Privacy lead identified (internal or external).

4. Phase 1 — GDPR-compliant operations

The goal of Phase 1 is to operationalise the privacy-compliance posture already drafted, and to introduce the persistence and audit-log infrastructure (Epic E3) without which downstream phases cannot begin.

4.1 Deliverables

Deliverable Owner Reference
Software persistence (Postgres, Patient, Marker, Analysis, Session, AuditLog, ConsentRecord, User entities) Software Epic E3
Authentication and authorisation (Argon2id, JWT RS256, RBAC) Software 50-secdev-checklist.md §4–§6
Encryption at rest (pgcrypto for sensitive columns; KMS-managed key) Software 50-secdev-checklist.md §9
AuditLog with immutable append-only semantics and 10-year retention Software 30-gdpr-dpia.md §7
Consent management (per-patient ConsentRecord, with withdrawal flow) Software + Privacy 30-gdpr-dpia.md §6
Operational privacy notices in es / en / de / pt-BR Privacy + Marketing 30-gdpr-dpia.md, 32-ar-lopdp.md, 33-br-lgpd.md, 34-de-gdpr-bdsg.md
Data Subject Access Request (DSAR) runbook Privacy 30-gdpr-dpia.md §6
Processor (AV-Vertrag) contracts with every operator (hosting, SMTP, backup) Legal 34-de-gdpr-bdsg.md §6
AAIP database registration in Argentina Privacy 32-ar-lopdp.md §4
Penetration test report (annual) Security 50-secdev-checklist.md §19
security.txt published Security 50-secdev-checklist.md §18
Coordinated vulnerability disclosure policy Security Same

4.2 Person-month estimate

Workstream PM
Software (Epic E3) 4 to 6
Privacy (DPIA finalisation, notices, AV contracts, registrations) 2 to 3
Security (controls, pen test, runbooks) 1 to 2
Documentation upkeep 1
Total 8 to 12

4.3 Required organisational milestones

  • Privacy lead hired or external DPO contracted.
  • Security lead identified.
  • Legal counsel engaged for AV-Verträge / DPAs / BAA template.
  • Bank account / billing relationship with hosting provider with executed DPA.

4.4 Gate to leave Phase 1

  • DPIA signed by DPO and controller.
  • AuditLog in production with 30 days of retention demonstrated.
  • DSAR runbook tested end-to-end.
  • AAIP registration confirmation received.
  • At least one external penetration test report with no Critical/High findings.

5. Phase 2 — Single-site clinical validation study

EPPA must accumulate clinical evidence before EU MDR Art. 61 / FDA substantial equivalence claims are credible. A single-site, IRB-approved, peer-reviewed validation study is the minimum viable evidence base.

5.1 Deliverables

Deliverable Owner Reference
Clinical investigation plan (CIP) under ISO 14155:2020 Clinical lead 00-overview.md §5 Phase 2
IRB / ethics-committee approval Clinical lead Per institutional procedure
Patient information sheet and consent form, per locale Clinical lead Compliant with locale's medical research law
Investigator brochure Clinical lead ISO 14155 Annex B
Case report forms (CRF) Clinical lead + Data ISO 14155 §6.5
Statistical analysis plan (SAP) Clinical lead + Data ISO 14155 §6.4
Data management plan (DMP) Data Aligned with the DPIA
Study report and submission for peer review Clinical lead Targets a kinesiology / physiotherapy journal
Update to risk file with field data Quality 12-iso-14971-risk.md §10

5.2 Person-month estimate

Workstream PM
Clinical lead 6 to 10
Software (study-only features: structured data export, audit detail) 2 to 3
Data management 3 to 5
Statistics 2 to 3
Regulatory + documentation 2 to 3
Writing and submission 3 to 6
Total 18 to 30

5.3 Required organisational milestones

  • Clinical lead hired (PhD-level kinesiologist or postural-medicine physician with prior clinical-study experience).
  • Statistical consultant engaged (or in-house biostatistician).
  • IRB / ethics-committee partnership in place.
  • Funding for the study secured (likely grant-funded; estimated EUR 80–150 K for a 60-patient single-site study with 12-month follow-up).

5.4 Gate to leave Phase 2

  • Peer-reviewed publication accepted (or under revision after favourable reviewer comments).
  • Study report available as input to the EU MDR clinical evaluation report.
  • Risk file updated with field-observed failure modes.

6. Phase 3 — ISO 13485 QMS + IEC 62304 SDLC artefacts

For EU MDR and FDA QMSR purposes, the QMS and the software lifecycle file must be formalised under the relevant standards. Without this layer, no notified body or FDA reviewer will accept the technical documentation.

6.1 Deliverables

Deliverable Owner Reference
QMS Manual (ISO 13485:2016) Quality n/a
Document control procedure Quality ISO 13485 §4.2
Records control procedure Quality ISO 13485 §4.2
Management review process Quality + Exec ISO 13485 §5
CAPA (Corrective and Preventive Action) procedure Quality ISO 13485 §8.5.2, §8.5.3
Internal-audit programme Quality ISO 13485 §8.2.4
Software Development Plan Software 11-iec-62304-lifecycle.md §6
Software Architecture Description Software 11-iec-62304-lifecycle.md §7
Software Requirements Specification Software + Clinical n/a
V&V plan and reports Software + QA 11-iec-62304-lifecycle.md §8
SOUP register (authoritative) Software 11-iec-62304-lifecycle.md §5
Configuration management plan Software 11-iec-62304-lifecycle.md §4
Problem-resolution procedure Software + Quality Same
Risk file closed (ISO 14971) Quality 12-iso-14971-risk.md
Cybersecurity assessment per MDCG 2019-16 / IEC 81001-5-1 Security + Quality 50-secdev-checklist.md §17
QMS audit by certifier (Stage 1 + Stage 2) External auditor n/a
ISO 13485 certificate issued External auditor n/a

6.2 Person-month estimate

Workstream PM
Quality (QMS build-up) 6 to 9
Software (lifecycle artefacts) 4 to 6
Security (cybersecurity file) 1 to 2
External audit prep + audit response 3
Total 14 to 20

6.3 Required organisational milestones

  • Head of Quality hired or contracted (often a regulated-industry QA with prior ISO 13485 build-out experience).
  • ISO 13485 certifier engaged (BSI, DEKRA, TÜV SÜD, DNV typical for Argentina/EU).
  • Internal-audit cadence operational (minimum quarterly during Phase 3).

6.4 Gate to leave Phase 3

  • ISO 13485 certificate issued with no Major nonconformities.
  • IEC 62304 file (SDP, SAD, SRS, V&V, SOUP, CM) under change control.
  • Risk file closed for the marketed configuration.
  • Cybersecurity file aligned with MDCG 2019-16 Rev.1 and IEC 81001-5-1.

7. Phase 4 — CE marking (EU MDR Class IIa)

With Phase 3 complete, EPPA has the QMS, lifecycle and clinical-evidence substrate to submit for CE marking under EU MDR.

7.1 Deliverables

Deliverable Owner Reference
EU MDR technical documentation (Annex II + Annex III) Regulatory 10-eu-mdr-saMD-classification.md §5.1
Classification dossier (Rule 11) Regulatory 10-eu-mdr-saMD-classification.md §4
Clinical evaluation report (Art. 61, Annex XIV Part A) Clinical + Regulatory Uses Phase 2 study report as core input
Post-market surveillance plan (Art. 83, Annex III) Regulatory n/a
Periodic Safety Update Report template (Art. 86) Regulatory n/a
Vigilance procedures (Art. 87–92) Regulatory + Quality n/a
Declaration of Conformity (Annex IV) Regulatory n/a
UDI assignment (Basic UDI-DI + per-version UDI-DI) Regulatory 10-eu-mdr-saMD-classification.md §6
Labelling and IFU per Annex I §23 Regulatory + Product 01-intended-use-statement.md is the seed
EUDAMED Actor + UDI + Device registration Regulatory 10-eu-mdr-saMD-classification.md §6
Notified-body conformity assessment (Annex IX Ch I + Ch III §4) Notified body n/a
EC certificate issued Notified body n/a

7.2 Person-month estimate

Workstream PM
Regulatory (technical file) 6 to 8
Clinical (CER drafting) 2 to 3
Quality (audit response) 1 to 2
Software (any required hardening from audit findings) 1 to 2
Localisation (IFU in EU languages of marketing) 2 to 3
Total 12 to 18

7.3 Required organisational milestones

  • Notified body engaged (designation verified per 10-eu-mdr-saMD-classification.md §5.2).
  • Person Responsible for Regulatory Compliance (PRRC, Art. 15) appointed.
  • Authorised Representative in the EU (Art. 11) appointed if manufacturer is outside the EU.
  • Vigilance email and process operational.

7.4 Gate to leave Phase 4

  • EC certificate issued and registered in EUDAMED.
  • Non-device disclaimer removed in EU locales (per the conditions in 91-non-device-disclaimer.md §4).
  • First commercial deployment under post-market surveillance.

8. Phase 5 — FDA SaMD pathway (510(k) likely)

In parallel with Phase 4 or immediately after, file with the FDA. Order of EU vs US is a strategic choice; EU-first is the default because EU MDR allows broader market expansion immediately.

8.1 Deliverables

Deliverable Owner Reference
Pre-submission Q-Sub to FDA Regulatory + US consultant 20-fda-samd-path.md §4.4
Predicate identification and substantial-equivalence analysis US consultant 20-fda-samd-path.md §5
510(k) content per 21 CFR 807.87 Regulatory + US consultant 20-fda-samd-path.md §6.1
Software documentation per FDA June 2023 guidance (Enhanced level likely) Software + Regulatory 20-fda-samd-path.md §6.1
Cybersecurity submission per FDA September 2023 guidance Security + Regulatory 20-fda-samd-path.md §12
Establishment registration and device listing Regulatory 21 CFR Part 807
US labelling per 21 CFR Part 801 Regulatory + Product n/a
MDR procedures per 21 CFR Part 803 Regulatory + Quality 20-fda-samd-path.md §10
BAA template execution with first US customers Legal 31-hipaa-readiness.md §7
HIPAA Security Rule readiness Privacy + Security 31-hipaa-readiness.md §10
510(k) clearance (or De Novo grant) FDA n/a

8.2 Person-month estimate

Workstream PM
US Regulatory consultant 4 to 6
Internal Regulatory 2 to 3
Software (FDA-specific documentation packaging) 1 to 2
Security (cybersecurity submission packaging) 1 to 2
Privacy (HIPAA readiness completion) 1 to 2
Legal (BAA template + first contracts) 1
Total 10 to 16

8.3 Required organisational milestones

  • US Regulatory consultant engaged.
  • US Agent (per 21 CFR 807.40) appointed if manufacturer is outside the US.
  • US deployment hosting provider with executed BAA.
  • Quality system updated to QMSR-compatible state (after 2 February 2026 QMSR transition).

8.4 Gate to leave Phase 5

  • 510(k) clearance (or De Novo grant) received.
  • Non-device disclaimer removed in US locale.
  • First US deployment under post-market MDR vigilance (21 CFR Part 803).

9. Cross-cutting concerns

Concern Comment
Localisation Each phase that introduces a new market locale (es-AR, en, de, pt-BR) adds translation effort; budget ~10–15 % of the documentation effort for each additional locale.
Multi-site clinical research If Phase 2 expands to multi-site, GDPR joint-controller agreements (34-de-gdpr-bdsg.md §7) become load-bearing.
Brazil (ANVISA) Phase 4 + 5 do not cover Brazil. A separate ANVISA RDC 751/2022 submission will be needed; effort ≈ Phase 5 / 2.
Argentina (ANMAT) ANMAT registration runs in parallel with Phase 1 (privacy registration) and Phase 4 (device registration). Effort ≈ 2 PM.
Insurance Product liability insurance must be in place before any commercial deployment — typically Phase 4 closure.
Pricing and reimbursement Out of scope of regulatory roadmap; relevant for Product.

10. Risk register for the roadmap itself

# Risk Mitigation
RR1 Notified-body slot unavailable when Phase 4 is ready Engage notified body early in Phase 3; book a slot at Stage 1 audit
RR2 Phase 2 study fails to meet inter-rater agreement threshold Pilot study before main protocol; pre-register the threshold
RR3 Funding gap between Phase 2 and Phase 3 Apply for grants alongside Phase 1; consider commercial partnership
RR4 Regulatory landscape shift (e.g. EU MDR amendment, ANPD adequacy decision changes) Annual regulatory horizon scan
RR5 Cybersecurity incident in Phase 1 derails programme trust Annual pen test from Phase 1; security incident runbook tested quarterly
RR6 Key-person dependency (single regulatory lead) Document everything in this compliance/ set; cross-train at least two people on each domain

11. Open questions

  1. Phase ordering: confirm EU-first vs US-first vs simultaneous.
  2. Single-site vs multi-site Phase 2: cost-benefit on broader clinical evidence vs faster gate.
  3. Notified-body shortlist: lock in Phase 3.
  4. In-house vs contracted DPO: Phase 1 decision.
  5. Effort estimates: validate against industry benchmarks for SaMD programmes of comparable size.

References