The Workbench · Craft
A common specification binds; a standard doesn't have to
A harmonized standard and an MDR common specification look, from the outside, like the same kind of thing: both let a manufacturer meet a General Safety and Performance Requirement by pointing to a document the Commission has blessed, instead of building the case from scratch. Article 9 of Regulation (EU) 2017/745 draws a sharper line between them than that similarity suggests. A harmonized standard is a route a manufacturer can choose or set aside, so long as the GSPR still gets met some other defensible way. A common specification, once one exists for a device, is a route a manufacturer has to take — unless it can justify, in writing, why an alternative reaches an equivalent result.
Common specifications exist to cover ground standards don't
Article 9(1) authorizes the Commission to adopt common specifications for a device or device group where no harmonized standard exists, where an existing standard isn't sufficient, or where a public health concern needs addressing regardless of what the standards landscape looks like. That's a gap-filling power, not a general substitute for the standards system — it's built for the specific cases where the ordinary route to a presumption of conformity has nothing to offer, or offers something the Commission has judged inadequate to a given risk.
Article 9(4) is where the real difference sits
A harmonized standard gives a manufacturer a presumption of conformity if it's used, and leaves the manufacturer free not to use it, provided the GSPR gets satisfied another way the manufacturer can defend. Article 9(4) sets a different rule for common specifications: manufacturers have to comply with a common specification that applies to their device, unless they can duly justify having adopted a solution that ensures a level of safety and performance at least equivalent to it. The presumption-of-conformity language in Article 9(3) reads almost like a standard's own effect — but Article 9(4) is the paragraph that turns “you may rely on this” into “you must rely on this, or prove your alternative is just as good.” A technical file that treats a common specification as one optional reference among several has missed the paragraph that actually governs it.
Annex XVI is where the mechanism is already operating
Common specifications aren't a hypothetical power sitting unused in the Regulation's text. Commission Implementing Regulation (EU) 2022/2346 lays down common specifications for the product groups listed in Annex XVI — devices without an intended medical purpose, like certain aesthetic and cosmetic products, that MDR brought inside its scope precisely because no medical purpose meant no existing device-specific standard covered them adequately. Its own annexes work the same way Article 9 describes in general: one set of requirements applying across every Annex XVI product, and product-specific annexes layered on top for each named group, covering risk management and, where necessary, clinical evaluation for safety. A manufacturer of an Annex XVI device that builds its risk file around a generic standard instead of the common specification that actually names its product group has picked the wrong governing document for a gap the Regulation built this exact mechanism to close.
A technical file has to name which kind of reference it's citing
FDA runs a comparable but distinct system on its own side: a recognized consensus standard a submitter can cite in full, in part, or with named deviations, all still voluntary in the sense that a sponsor can generate the underlying data itself instead. MDR's common specifications don't offer that same default optionality once one applies to a device — and a technical documentation file that cites “the applicable standard” without distinguishing a harmonized standard from a common specification has obscured exactly the question Article 9(4) makes load-bearing: whether departing from the cited document requires a routine justification, or the specific, documented equivalence case Article 9(4) demands.
Where this meets the file
A GSPR trace that cites a common specification the same way it cites a harmonized standard — interchangeably, as one input among several — has flattened a distinction the Regulation built on purpose. A GSPR checklist built to trace each requirement to its actual governing document needs a field for which kind of reference it's citing, because only one of the two comes with a duty to justify departing from it. A reference-tracking worksheet that separates harmonized standards from common specifications, and flags Article 9(4)'s justification duty wherever a common specification applies, is previewed in the launch catalog. If your program tracks these references differently, the shelf takes that correction directly.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.