Launch Is the Start of a New Regulatory Phase

Clearance is not the finish line. The moment a device reaches a user, a second set of obligations begins, and they run for as long as the product is on the market plus the retention period after it is withdrawn. Regulators treat post-market performance as part of the evidence that the device is safe, and a weak surveillance system is one of the most commonly cited findings in facility inspections.

For a small manufacturer the practical problem is that these obligations arrive at the exact moment the team is smallest and busiest. Build the system before launch, or it gets built during your first serious complaint.

Not Just Complaints: Proactive Data Collection

Many first-time manufacturers assume surveillance means answering the phone when something goes wrong. That is reactive data, and it undercounts real-world problems by a wide margin, since most users who find a device confusing or unreliable simply stop using it.

A defensible system pulls from both directions. Reactive sources include complaints, service and repair records, returns, warranty claims, and distributor reports. Proactive sources include structured user surveys at defined intervals, follow-up with a sample of accounts, literature and adverse-event database screening for similar devices, trend analysis on production nonconformances, and registry or clinical follow-up data where it exists.

The point of the proactive half is to detect a drift before it becomes a reportable event, and to feed real-world data back into the risk file, which is a living document rather than a pre-launch artifact, as explained in ISO 14971 risk management.

What You Build Before Launch

  • A complaint handling procedure with a single intake point, a defined record format, a decision on reportability, and an investigation requirement. Every complaint gets a record, including the ones you believe are user error.
  • A written surveillance plan naming the data sources, how often each is reviewed, the indicators you track, and the thresholds that trigger action.
  • Traceability from unit to lot. If a defect is found in one lot of a sealing component, you need to know which serial numbers contain it and where they went. Without that, a targeted correction becomes a full recall.
  • Distributor and service agreements obliging partners to forward complaints within a defined period, typically five to ten business days. Distributors sitting on complaints is a real and recurring failure.
  • Labeling and IFU under version control, since many corrective actions are labeling changes and you must know which version shipped with which unit; the requirements are in FDA labeling requirements.
  • A CAPA process that is actually used, with owners and due dates, as part of the quality system described in ISO 13485.

From Event to Decision

Every incoming report follows the same path: record, evaluate for reportability, investigate, decide on action, and close with documented rationale.

The reportability question has hard deadlines in the US. Under the medical device reporting regulation at 21 CFR 803, manufacturers file within 30 calendar days of becoming aware of information suggesting the device may have caused or contributed to a death or serious injury, or malfunctioned in a way that would likely cause one on recurrence. Events requiring remedial action to prevent an unreasonable risk of substantial harm are reported within 5 working days. Corrections and removals initiated to reduce a health risk are reported under 21 CFR 806, generally within 10 working days.

Two traps catch new manufacturers. The clock starts when any employee becomes aware, not when management is told, so a service technician's email counts. And "we could not reproduce it" is not a conclusion that closes a file; it is a documented investigation outcome that still requires a reportability decision.

Investigation quality matters as much as speed. Get the unit back where possible, examine it against the device history record for its lot, and check whether the same signal appears elsewhere in your data. Systemic findings feed CAPA and, where the root cause is in manufacturing, back into the process controls covered in FDA QSR requirements.

Periodic Reports and the European Layer

If you also sell in Europe, the obligations are more prescriptive. The manufacturer maintains a post-market surveillance plan and produces a periodic safety update report, annually for higher-risk classes and at least every two years for lower ones, summarizing complaint data, sales volumes, benefit-risk conclusions, and any preventive or corrective actions. Post-market clinical follow-up is a standing requirement rather than an exception, and serious incidents are reported to the competent authority on short deadlines. The structure is outlined in EU MDR explained, and the differences from the US route in FDA clearance vs CE marking.

Connected devices add a further layer: vulnerability monitoring, coordinated disclosure, and patch deployment are treated as ongoing safety obligations, not IT housekeeping, as described in FDA cybersecurity requirements for connected devices.

What This Means for a Small Company

Budget realistically. A minimal but genuine surveillance system for a single Class II device costs roughly $15,000 to $40,000 to set up and 0.2 to 0.5 of a full-time person to run, more once volumes reach the thousands. Complaint software is optional at low volume; a controlled spreadsheet with a defined procedure is acceptable if it is actually maintained.

Three habits separate manufacturers who survive their first inspection from those who do not. Log everything, including the trivial. Investigate and close records on a schedule rather than in batches before an audit. And review the aggregated data quarterly with someone empowered to stop shipments, because the value of surveillance is entirely in the trend nobody wanted to see.

Set Up Surveillance Before You Ship

Projects House helps device companies stand up the post-launch side of the quality system: complaint handling, surveillance plan, reporting decision trees, traceability, and periodic report templates sized for a small team. Send your device class and launch timing through our contact form.