The Workbench · Craft

What a biological evaluation plan has to select, not just run

A biological evaluation report is easy to build backwards: run the full ISO 10993 test panel a lab is equipped to offer, then write the report around whatever came back. ISO 10993-1:2018 asks for the opposite sequence — place the device in a grid defined by the nature of its body contact and the duration of that contact, read off the endpoints the grid proposes as candidates, and then apply a documented risk evaluation before deciding which of those candidates actually need testing and which don't. Running every endpoint the grid could plausibly cover isn't the same as making that determination, and a report that never shows the grid or the reasoning applied on top of it hasn't demonstrated the standard's actual requirement — only that a lab stayed busy.

Contact and duration set the starting grid, not device type

Annex A of ISO 10993-1:2018, Table A.1, sorts a device along two axes: the nature of body contact — surface device, external communicating device, or implant device, each with its own sub-categories — and the duration of that contact, split into limited (24 hours or less), prolonged (more than 24 hours up to 30 days), and long-term (beyond 30 days). A device's placement in that grid, not its device-type name or its predicate's classification, is what proposes the starting set of candidate endpoints: cytotoxicity, sensitization, irritation or intracutaneous reactivity, systemic toxicity, genotoxicity, implantation effects, hemocompatibility, chronic toxicity, and carcinogenicity, marked as relevant or not for each cell in the table.

The table proposes; the risk evaluation decides

ISO 10993-1 is explicit that Table A.1's markings are a starting proposal for a risk-based evaluation, not a final answer — an endpoint the table doesn't flag for a given category can still be necessary if the device's specific materials, manufacturing process, or intended use raise a risk the generic grid cell doesn't capture, and an endpoint the table does flag can sometimes be excluded with documented justification, such as existing data on an unchanged material already in equivalent clinical use. A biological evaluation plan that stops at “ran everything the table marked” has followed the grid without doing the evaluation the standard actually requires on top of it.

FDA's own endpoint matrix isn't identical to the standard's

FDA maintains its own reference, Biocompatibility Evaluation Endpoints for Device Categories, alongside its 2020 guidance on the use of ISO 10993-1, and the two matrices don't always agree endpoint for endpoint — FDA's expectations for certain categories call for endpoints beyond what Table A.1 alone would flag. A plan built and checked only against the international standard's own table, without a separate pass against FDA's device-category page, can be complete by ISO 10993-1's own logic and still short of what a US reviewer expects to see addressed.

A material change reopens the grid on a different clock than a 510(k) change does

A supplier substitution, a new sterilant, or a reformulated adhesive can trigger a fresh biological evaluation even when the same change fails the 807.81(a)(3) test for a new 510(k) — the two questions run on separate logic entirely. The 510(k) change test asks whether the modification could significantly affect safety or effectiveness as a regulatory matter; the biological evaluation reopens because the risk management process underneath it, per ISO 14971, treats a materials or process change as a hazard-analysis trigger on its own terms. A change log that clears the 510(k) test and stops there hasn't checked whether the biological evaluation needed to reopen at all.

Where the determination has to end up on paper

The record a biological evaluation actually owes isn't the raw test data alone — it's the grid placement, the candidate endpoints the table proposed, whatever was added or excluded against both ISO 10993-1's own table and FDA's supplementary matrix, and the rationale for each of those calls, feeding into the risk management file's own per-hazard chain as one specific hazard category among the others it has to trace. A biocompatibility file that hands over lab reports with no visible path back to a documented category-and-duration determination is asking a reviewer to reconstruct the risk evaluation the standard requires the sponsor to have already made.

A biological evaluation plan built around this structure — the Table A.1 grid placement, the documented add/exclude reasoning against both matrices, and the trace into the risk management file — is previewed in the launch catalog. If your program's endpoint determination works differently, the shelf takes that correction directly.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes