ISO 20417: The Complete Guide to the 2026 Edition

Introduction

ISO 20417 is the horizontal standard that decides what has to be on a medical device label, in its instructions for use and in its packaging — and on 17 March 2026 the version most technical files still cite was withdrawn. ISO 20417:2026, the second edition, replaced it with six changes that turn what used to be flexible or informative into fixed, normative, auditable requirements.

None of this is cosmetic. A labelling procedure that still leans on the 2021 edition's normative-reference flexibility is not outdated paperwork, it is a direct nonconformity the moment a Notified Body opens the file. An IFU that declares itself "readily understood" without evidence behind it no longer meets the bar at all, because that phrase does not exist in the current text.

This guide works through what ISO 20417 covers and why it replaced EN 1041, the six substantive changes the 2026 edition introduced, how to demonstrate the new lay-user readability requirement, the new normative label durability and sterile barrier obligations, the eIFU access-control duty, the new jurisdiction-neutral authorised representative symbol, and how all of it maps into the MDR and IVDR GSPR checklist now that the standard's own cross-reference annexes have been deleted.

Table of Contents

What ISO 20417 covers, and why it replaced EN 1041

ISO 20417 sets the generally applicable requirements for the identification, labels, packaging, marking and accompanying information a manufacturer supplies with a medical device or accessory. It does not prescribe the medium — paper, on-device marking or electronic delivery are all in scope — and it explicitly steps aside wherever a device-specific product or group standard sets a stricter or different requirement. As a horizontal standard, it functions as the baseline every other labelling-adjacent standard assumes rather than repeats.

The standard was written to replace EN 1041, the older European standard that served the same purpose under the Medical Device Directive. EN 1041 was built for a regulatory landscape the MDR and IVDR have since superseded, and ISO 20417 was drafted to be a single, internationally applicable reference aligned with MDR (EU) 2017/745, IVDR (EU) 2017/746 and IMDRF guidance simultaneously, rather than a European-only document that regional standards would each reinterpret separately.

In practice the standard's scope splits into seven information categories that recur throughout its clauses: device identification and markings, labels and packaging, instructions for use, accompanying documentation more broadly, electronic information and software interfaces, accessories supplied separately from the device, and the standard's own interaction with device-specific product standards that take precedence over it where one exists. A gap analysis against ISO 20417 works best when it is run category by category rather than clause by clause, because a single category such as "accompanying documentation" often draws on requirements scattered across several clauses of the standard.

ISO 20417:2021 is withdrawn: what actually changed in 2026

ISO 20417:2021 was cancelled and replaced on 17 March 2026 by ISO 20417:2026, the second edition. Neither edition has been formally harmonised under the MDR or IVDR through publication in the Official Journal — an ongoing dispute between ISO/IEC and the European Commission over copyright and free access to standards has paused most EN ISO harmonisation since late 2024 — but that changes nothing about which edition to apply. Notified Bodies were already referencing ISO 20417:2026 in technical file reviews within weeks of publication, treating it as the current state of the art regardless of its Official Journal status. The current edition can be purchased directly from the ISO Store.

ISO 20417:2021 versus ISO 20417:2026The 2021 edition was withdrawn on 17 March 2026. Six changes turn what used to be flexible orinformative into fixed, normative and auditable requirements.AreaISO 20417:2021ISO 20417:2026NormativereferenceflexibilityPermitted — could substitute a newerreferenced standard on a risk-basedjustificationDeleted — Clause 2 editions arefixed unless the AuthorityHaving Jurisdiction saysotherwiseIFU readability,lay users“Readily understood” — unenforceablein practiceDemonstrable lower secondaryeducation level, evidenced bytestingLabel durabilityInformative annex — guidance only,not an audit findingNormative — mandatory test planand acceptance criteriaSterile barrierconfigurationNot required on the labelMust be identified on the label,e.g. single/double barriersymboleIFU accesscontrolNot addressedManufacturer must evaluaterestricting access by user groupJurisdiction-specificclausesAd hoc notes on “authority havingjurisdiction”~20 clauses formalised under thedefined term “applicable policy”ISO 20417:2021 was never harmonised under the MDR before it was withdrawn, so the practical status of the 2026edition is unchanged: apply it as state of the art in the GSPR checklist, not as a formal presumption of conformity.
Figure 2 — the six substantive changes between the withdrawn 2021 edition and the current 2026 edition

The substance of what belongs on a label, in an IFU and in packaging information has not moved. What changed is enforceability: several requirements that were optional, flexible or merely informative under the 2021 text became fixed and normative, and two changes explicitly close off practices the 2021 edition had permitted. The sections that follow work through each one.

Applicable policy: the concept that now runs through ~20 clauses

The 2026 edition introduces "applicable policy" as a defined term: the set of requirements relating to a product established by the authority having jurisdiction in a given market. Roughly twenty clauses across the standard now anchor jurisdiction-specific obligations — language, UDI presentation, importer identification, date formats — to this single term, replacing the looser 2021 phrasing that flagged such points with informal notes about what "can be required by the authority having jurisdiction."

Where ISO 20417 sits in the documentation stackISO 20417 electrical safety has nothing to do with this standard — it is the horizontalframework for manufacturer information, cross-referenced to the symbol and reprocessingstandards that fill in device-specific detail.1 · CENTRAL FRAMEWORKISO 20417:2026Labels, packaging, marking andaccompanying information2 · SYMBOLSISO 15223-1Graphical symbols used on labels, incl.the new AR symbol 5.1.123 · REPROCESSINGISO 17664-1/2Information for devices that arereprocessed before reuse4 · IVD-SPECIFICISO 18113 seriesLabelling for IVD reagents andinstruments5 · GSPR CHECKLISTMDR/IVDR Annex I, Ch. IIIWhere every ISO 20417 clause has to betracedISO 20417 is the central framework, not the whole answer. Full MDR/IVDR labelling compliance still needs the symbol,reprocessing and IVD-specific standards cross-referenced wherever they apply to the device.
Figure 1 — how ISO 20417 sits alongside the symbol, reprocessing and IVD-specific standards

The practical consequence is documentation, not new substantive obligations. A manufacturer selling into several markets can no longer rely on one market-neutral labelling procedure and a general awareness of local rules. Clause 8.7.4 and the surrounding "applicable policy" clauses ask instead for a market-by-market matrix — typically EU MDR/IVDR, US 21 CFR 801, and any other jurisdiction served — mapping exactly how each applicable-policy clause is satisfied for that market, in a form a reviewer can follow without cross-referencing separate national procedures.

From "readily understood" to a lay-user readability you can prove

ISO 20417:2021 required instructions for use intended for lay users to be "readily understood." The phrase was well intentioned and effectively unenforceable: a manufacturer could assert clarity without demonstrating it, and a reviewer had no defined bar to check the assertion against.

ISO 20417:2026 replaces it with a specific, testable requirement: lay-user IFUs must be written at a lower secondary education level, and the manufacturer must be able to demonstrate this rather than simply state it. That single change moves IFU readability from a design intention to a verification activity with its own evidence trail, much like the essential performance verification a device's clinical claims already require.

Three activities together build a defensible readability file, and none of them are new tools — they simply now have to be documented against this specific requirement rather than left as background good practice.

Demonstrating lay-user IFU readabilityISO 20417:2026 replaced the unenforceable “readily understood” test with a defined bar — anda defined bar has to be evidenced, not just asserted.1Plain-language reviewA reader without a medicalbackground checks whetherevery instruction and warningis actionable without furtherexplanation.2Validated readability scoringFlesch-Kincaid or SMOGscoring against a lowersecondary education levelbenchmark, typically grade7–8 equivalent as a startingpoint.3Lay-user usability testingRepresentative lay users,tested under IEC 62366-1,must find, understand andcorrectly follow the keyinstructions and warnings.4Documented in the technical fileMethodology, results and anyIFU iterations go in theTechnical Documentation — aNotified Body expectsevidence, not a declarationof clarity.
Figure 3 — the four steps that build evidence for the ISO 20417 lay-user readability requirement

The connection to IEC 62366-1 usability engineering is direct rather than incidental. A manufacturer that already runs formative and summative usability evaluations for a lay-use device has the natural home for lay-user comprehension testing already built; the readability requirement asks that IFU comprehension be one of the tasks evaluated, with the methodology, results and any IFU iterations documented in the technical file where a Notified Body reviewer will look for them.

✦ EU MDR Technical Documentation Kit · Annex II/III

Every ISO 20417 clause has to trace back to a GSPR entry a reviewer can find.

With the standard's own MDR/IVDR cross-reference annexes deleted in 2026, that mapping now has to live in your own technical documentation. The kit gives you the Annex I, Chapter III structure to hold it.

✓ GSPR checklist template mapping harmonised and non-harmonised standards

✓ Labelling and IFU section structured for Annex I, Chapter III

✓ Built on Notified Body audit experience

Get the Technical Documentation Kit → from €429

Label durability and sterile barrier configuration go normative

Under the 2021 edition, label durability guidance sat in an informative annex — advisory reading a manufacturer could follow or not, and an auditor could not cite as a nonconformity on its own. ISO 20417:2026 makes it normative: a mandatory requirement expected to hold for the device's full intended lifetime, covering sterilization, handling, cleaning-agent exposure and abrasion as applicable to the device.

Sterile devices pick up a second new obligation at the same time. Where the 2021 edition only required a label to state that a device was sterile, the 2026 edition requires the sterile barrier configuration itself to be identified — in practice, the appropriate single- or double-barrier symbol from ISO 15223-1 added to the packaging label. For a manufacturer with several sterile product families or market-specific packaging variants, this is usually a label and design-history update rather than a full redesign, but it touches every affected template and needs tracking across all of them consistently.

A Notified Body reviewer working through the durability requirement in a technical file will look for four things in sequence: a test plan covering the conditions relevant to the specific device, whichever combination of sterilization method, handling, cleaning-agent exposure or fluid contact applies; test results measured against defined acceptance criteria rather than a pass/fail note with no threshold; evidence that the label still satisfies every other ISO 20417 labelling requirement once the durability testing has been applied to it, since a label that survives sterilization but becomes illegible is not durable in any useful sense; and a statement connecting the tested conditions back to the device's stated shelf life or intended lifetime, so the durability claim and the device's own claims agree with each other.

eIFU: the new access-control obligation and the 2025 amendment

ISO 20417:2026 introduces a new obligation for manufacturers who deliver instructions for use electronically: evaluate whether access to that electronic accompanying information should be restricted to defined user groups, and document that evaluation. This sits alongside, not instead of, the EU's own electronic-IFU framework.

For EU MDR devices, electronic instructions for use are governed by Implementing Regulation (EU) 2021/2226, which limited eIFU to professional users under listed device categories and required a documented risk assessment covering access, availability, versioning and the persistent URL a user reaches. Implementing Regulation (EU) 2025/1234 widened that scope in July 2025, removing the fixed device-category list so eIFU became available for any professional-use device meeting the conditions, and explicitly tied the persistent-URL requirement to EUDAMED registration. Devices reasonably foreseeable to also reach lay users still need a paper IFU for those users regardless of the eIFU option taken for professional users.

The ISO 20417:2026 access-control duty is a design and documentation obligation layered on top of that regulatory framework, not a replacement for it: a manufacturer operating an eIFU portal has to show it assessed who should see what, not only that the portal exists and the URL resolves. A defensible assessment typically distinguishes at minimum between the general public, professional users authorised to see full technical detail, and any regulator or Notified Body that needs unrestricted access for review purposes, with the reasoning for each access level recorded rather than implied by the portal's default configuration.

The authorised representative symbol becomes jurisdiction-neutral

Of everything in the 2026 edition, this is the change most likely to touch artwork directly. The 2021 edition drew its authorised representative symbol from ISO 15223-1 symbol 5.1.2, which carried "EC" baked into its design. Clause 6.1.2 d) 1) of the 2021 text allowed manufacturers serving non-EU jurisdictions — a UK Responsible Person, a Swiss representative — to substitute the relevant two- or three-letter country code from ISO 3166-1, producing label variants such as "UK REP" or "CH REP."

That substitution clause is deleted in the 2026 edition. The normative reference moves to ISO 15223-1:2021/Amd 1:2025, which introduces a new symbol, 5.1.12, designed to be jurisdiction-neutral from the outset — no country code, no "EC," usable for any authorised representative in any market without a variant. There is no hard deadline forcing an immediate label change, but the update belongs on the next revision a label goes through for any other reason, and manufacturers running a single label across several markets should find the change simplifies rather than complicates their artwork going forward.

✦ EU MDR Technical Documentation Kit · Annex II/III

The durability evidence and readability testing this guide describes need a home.

Label durability test plans, readability documentation and the applicable-policy matrix all belong inside a structured technical documentation file a Notified Body can navigate, not scattered across separate working documents.

✓ Full Annex II/III document structure and templates

✓ Designed to hold evolving evidence as standards are updated

Get the Technical Documentation Kit → from €429

SaMD and AI-based tools: the interface is the label

A common misconception among software manufacturers is that labelling requirements do not apply because there is no physical device to put a label on. ISO 20417 applies to Software as a Medical Device and AI-based tools exactly as it applies to hardware, and it is explicit that the requirement does not disappear simply because the delivery mechanism changes — it relocates. For SaMD, the user interface is the regulated label, typically delivered through an in-app IFU, a Help section or an About screen rather than a printed insert.

Three consequences follow directly from treating the UI as the label. First, the UDI and build or version identifier need to be immediately accessible within the clinical workflow itself, not buried in a separately hosted document a clinician has to leave the application to find. Second, algorithmic limitations, confidence boundaries and the dataset constraints a model was validated against need to be traceable from the interface back to the risk management file, the same way a hardware device's warnings trace back to its risk analysis. Third, in-app IFU content is a live post-market obligation: it has to stay current as the software changes, which means the labelling change-control process has to be wired into the same release pipeline as the software itself, not treated as a separate documentation task that happens to lag behind the code.

Teams building a SaMD product benefit from involving ISO 20417 in UI design from the outset rather than retrofitting labelling compliance once the interface is finished, for the same reason usability engineering under IEC 62366-1 works better integrated into development than bolted on afterward.

Mapping ISO 20417 into the MDR and IVDR GSPR checklist

ISO 20417 addresses Annex I, Chapter III of both the MDR and the IVDR — the general safety and performance requirements covering information supplied with the device. Under the 2021 edition, four informative annexes did much of this cross-referencing work directly: Annex D mapped every clause to IMDRF N47:2018, IMDRF N52:2019, MDR Annex I, IVDR Annex I and the legacy Directives; Annex E gave the IMDRF correspondence tables separately; Annexes F, G and H mapped to the now-withdrawn ISO 16142 essential principles series and to the MDR and IVDR GSPRs respectively.

All five are gone in the 2026 edition, replaced by a single leaner annex covering only the current IMDRF documents, N47:2024 and N52:2024. A technical file that relied on the deleted MDR or IVDR annexes as its labelling traceability bridge has lost that shortcut and now needs to build and maintain the ISO 20417-to-GSPR mapping itself — a properly built traceability matrix was already doing this work internally in most well-structured files, but a file that pointed to the annex instead now has a visible gap.

The removal is defensible rather than arbitrary. The legacy Directive references in the deleted annexes point to instruments that are no longer in force, so carrying them forward would have been dead weight. The MDR and IVDR annex mappings are a different case: five years into MDR application, the expectation embedded in removing them is that manufacturers already hold their own GSPR conformity documentation rather than depending on a standard's appendix to supply it, which is a reasonable bar for any file still being actively maintained.

ISO 20417 is also not a standalone answer to labelling GSPR compliance on its own. Full conformity typically layers in ISO 14971-driven risk management informing what a label or IFU must warn against, EN ISO 15223-1 for the graphical symbols referenced throughout, EN ISO 17664-1/2 for devices that are reprocessed before reuse, and the EN ISO 18113 series for IVD reagent and instrument labelling where applicable.

Six findings Notified Bodies are already raising

Every recurring ISO 20417:2026 finding traces back to the same root cause: a technical file, SOP or label that still reflects the withdrawn 2021 text rather than the current normative one.

Six ISO 20417:2026 findings Notified Bodies are already raisingEvery one traces back to a technical file that still reflects the withdrawn 2021 editioninstead of the current normative textCRITICALNo applicable policy matrixRoughly 20 clauses defer to the“applicable policy” of each targetmarket. Fix: build a market-by-marketclause mapping for EU, US, UK and anyother market served.CRITICALDeleted flexibility stillcited in the QMSA labelling SOP still justifies anewer referenced standard by internalrisk assessment alone. Fix: remove the2021 Clause 4 b) citation; route thejustification through risk managementand change control instead.HIGHIFU readability asserted, notevidencedThe technical file states the IFU isclear with no test behind it. Fix: runa plain-language review, a readabilityscore and lay-user usability testing.HIGHNo label durability test planDurability is now normative, notadvisory. Fix: test for the device'sfull lifetime against sterilization,handling, cleaning-agent exposure andabrasion.MODERATESterile barrier configurationmissing from the labelThe label states “sterile” but notwhich barrier system. Fix: add thecorrect ISO 15223-1 single- ordouble-barrier symbol to the packaginglabel.MODERATEOld AR symbol or country-codevariant still in useA “UK REP” or “CH REP” variant of theold EC-based symbol is still on thelabel. Fix: move to symbol 5.1.12 ofISO 15223-1:2021/Amd 1:2025 at thenext revision.
Figure 4 — six recurring findings in ISO 20417:2026 technical file reviews, with the fix for each

Frequently asked questions

Is ISO 20417:2021 still valid?

No. ISO 20417:2021 was officially withdrawn on 17 March 2026 when ISO 20417:2026 was published. The second edition is now the current version and should be used for all new and updated technical documentation, labels and Declarations of Conformity.

What is "applicable policy" under ISO 20417:2026?

Applicable policy is a defined term introduced in Clause 3.3 of ISO 20417:2026, meaning the set of requirements relating to a product established by the authority having jurisdiction in a given market. Roughly twenty clauses across the standard now anchor jurisdiction-specific obligations to this term, replacing the informal "authority having jurisdiction" notes used in the 2021 edition.

Does ISO 20417 apply to software medical devices and AI-based tools?

Yes. ISO 20417 applies to all medical devices, including Software as a Medical Device and AI-based tools, regardless of the absence of a physical device. For these products the user interface functions as the regulated label, typically delivered through an in-app IFU, Help or About section, with the UDI and build version accessible within the clinical workflow.

Is ISO 20417:2026 harmonised under the EU MDR or IVDR?

Not formally. As with the withdrawn 2021 edition, ISO 20417:2026 has not been published as a harmonised standard in the Official Journal of the European Union, a process currently affected by an ongoing dispute between ISO/IEC and the European Commission over standards access. In practice this changes little: neither edition has ever carried formal presumption of conformity, and ISO 20417:2026 is applied as the current state of the art in the GSPR checklist regardless.

What is a sterile barrier configuration, and why does it now need to be on the label?

The sterile barrier configuration describes whether a device uses a single or double sterile barrier system. ISO 20417:2026 requires this to be explicitly identified on the label using the appropriate ISO 15223-1 symbol, where the 2021 edition only required the label to state that the device was sterile without specifying the barrier system.

How do I demonstrate IFU readability for lay users under the new requirement?

Three activities together build the evidence: a plain-language review by a reader without a medical background, a validated readability score such as Flesch-Kincaid or SMOG benchmarked against a lower secondary education level, and lay-user usability testing under IEC 62366-1 confirming representative users can find, understand and correctly follow key instructions and warnings. All three, along with any resulting IFU iterations, belong in the technical documentation.

Conclusions

ISO 20417:2026 did not change what belongs on a medical device label or in its instructions for use — it changed what a manufacturer has to prove about that content, and removed several places technical files had been quietly leaning on the standard's own cross-referencing to do work the file itself should have been doing. The applicable-policy matrix, the readability evidence and the durability test plan are the three gaps most likely to surface first in a Notified Body review, precisely because they ask for documentation that a compliant label may already reflect in substance but has never had to demonstrate on paper.

The single item worth checking on every open technical file this week is the citation itself: a Declaration of Conformity or GSPR checklist still referencing ISO 20417:2021 is citing a cancelled standard, independent of every other change discussed here. It costs nothing to fix and it is the first thing a reviewer's eye lands on.

The second item worth a deliberate decision rather than an accident is scope: whether the applicable-policy matrix, the readability evidence and the durability test plan get built once, centrally, and referenced from every affected product's technical file, or get rebuilt piecemeal product by product as each one comes up for review. For a manufacturer with more than a handful of active product families, the centralised route is very much the cheaper one over a two- or three-year cycle, and it is also the version a Notified Body reviewer finds easiest to audit, since a single consolidated matrix invites far fewer follow-up questions than six slightly different product-specific versions of the same underlying policy analysis.

The EU MDR Technical Documentation Kit on MD Regulatory gives the Annex II/III structure that labelling evidence, readability testing and the applicable-policy matrix all need to sit inside, alongside the GSPR mapping that ties each ISO 20417 clause back to a specific Annex I requirement.

Related articles