Industries · Medical technology

ERP Success Factors for the Medical Technology Industry

For medical technology manufacturers, four things decide: UDI data under the MDR as master data, traceability by batch and serial number through to the customer, a system that can be validated within ISO 13485 quality management, and production records that stand up to audit and post-market surveillance. Whatever the standard cannot carry becomes custom development – and every piece of custom development has to be validated too.

(EU) 2017/745
Medical Device Regulation (MDR)
Since 1992
Vendor-neutral, independent
DACH
Germany, Austria, Switzerland

What is different in medical technology

The product is only finished once it is documented. The ERP writes that documentation as it goes.

In general manufacturing, the order ends with delivery. In medical technology, delivery is where responsibility for the product on the market begins: for every product, the manufacturer must be able to show which material batches it was made from, how it was tested and sterilised and to whom it was delivered – over the whole lifetime of the product, not just until the invoice.

The Medical Device Regulation (EU) 2017/745 has made this obligation stricter. The unique device identifier UDI must appear on the label and packaging, and on reusable instruments on the product itself, and the data belongs in the European database EUDAMED. An ERP that keeps the UDI as a free-text field on the item turns every product variant into manual work – and every audit into a search.

A reliable selection therefore does not start with a vendor comparison, but with the question of which evidence your risk classes and your quality management require and which processes create it. How we build this in vendor-neutral ERP consulting, and why process analysis comes before the system question, follows from this order.

Walk through your MDR requirements with us
Where it goes wrong in this industry

Four failure patterns we see again and again in medical technology projects.

UDI sits in free text

The UDI is kept on the item as a text field, and the production identifier from batch, serial number and manufacturing date is added by hand. Article 27 of Regulation (EU) 2017/745 requires the UDI system for every device, and the data goes to EUDAMED. What the standard has to deliver: UDI-DI as master data per variant and packaging level, UDI-PI generated automatically from production.

Direct marking is not planned in

Reusable devices such as surgical instruments carry the UDI on the product itself – for Class I devices from 26 May 2027. If this is missing from the process, it is missing from the routing, the laser marking and the label at the same time. What the standard has to deliver: marking as an operation with an inspection step, driven by the same UDI master data.

Validation comes after go-live

ISO 13485 requires software used in quality management to be validated before use, proportionate to the risk. If the ERP is first selected and customised and only then validated, every customisation becomes part of the validation scope. What the standard has to deliver: quality-relevant functions that are configured rather than programmed, with a traceable change history.

The recall starts with an Excel list

In a field safety corrective action, the manufacturer must know which serial numbers or batches are affected and which customers have them. If the ERP records deliveries only at document level, the search starts in delivery notes. What the standard has to deliver: delivery history by batch and serial number at line level, with customer contacts straight from the system.

Which systems the industry uses

Three system classes, three prices – no winner.

Each class solves the four requirements in a different place. The table describes where – and what you accept in return.

System classes for medical technology manufacturers compared
System class Where the industry logic sits What speaks for it The price
Industry ERP for medical technologyIn the core of the system. UDI, batch and serial number tracking, production records and release are standard functions.Shortest route to audit-ready operation. Complaints, CAPA and device history are often built in.Smaller vendor, smaller market for partners and staff. Finance and group functions often weaker. High switching costs because industry logic and validation are not portable.
Standard ERP with industry add-onIn a partner's add-on on a broad base system.Broad ecosystem, strong finance, staff available. Medical technology depth where the add-on brings it.Two release cycles that can drift apart – and both affect validation. Dependence on the add-on partner. UDI depth varies widely and must be tested against your own variants.
Generalist ERP without industry focusIn custom development or customisation on the customer's side.Greatest freedom of design. Fits group standards. Lowest entry barrier for a few product families in a low risk class.UDI, serial number history and production records are built, validated and maintained in-house. Every release of the base system tests this custom development again.

What the table cannot decide: which risk classes you carry, how many product variants need their own UDI-DI, whether you manufacture by batch or serial number and how much you outsource to sterilisers and contract manufacturers. These four points decide the selection – and none of them is in a data sheet. For the assessment in the project we draw on our database of around 500 software vendors – vendor-neutral, without commission.

From our projects · Medical technology, manufacturer

MedTec & Science GmbH: a regulated ERP selection for parent company and subsidiary.

MedTec & Science GmbH has been developing and producing solutions for medical technology for 40 years. A subsidiary handles sales for one of its product areas.

The problemThe decision to invest in new ERP software had been made, but the subsidiary ran its own ERP system. Documents were exchanged between the two companies by hand – and both had to meet the regulatory requirements for ERP software in medical technology.
What we didIn workshops, Dreher worked out where the two companies overlap and defined the requirements with both project teams – adding regulatory requirements such as UDI creation, audit trail and validation of computerised systems to GAMP 5. The requirements specification was followed by the tender, vendor presentations, a two-day detail workshop and the contract negotiation with the chosen vendor.
Read the medical technology reference
One system
For parent and subsidiary
Across companies, document exchange can be automated
per reference
Met
Regulatory requirements
UDI creation, audit trail, validation to GAMP 5
per reference
Independence

No licences sold, no vendor commission. Our fee is the same whichever system is chosen in the end – including in a regulated environment. 

Frequently asked questions

Frequently asked questions about ERP in medical technology.

Ten questions managing directors, quality management representatives and IT leads in medical technology ask us before an ERP decision – on MDR, UDI, ISO 13485, traceability, duration and cost.

Your contact

Dr. Harald Dreher

Managing Director & Owner · Dreher Consulting

Since 1992, Harald Dreher has supported companies in the DACH Mittelstand with ERP decisions – vendor-neutral, without selling licences. In a 30-minute conversation he assesses which system class fits your risk classes, your product variants and your quality management, and where a selection is not needed at all.

1. Which ERP system is right for medical technology manufacturers?

The ERP system that keeps UDI data as master data, tracks batches and serial numbers from material to customer, creates production records and can be validated within ISO 13485 quality management – in the standard, not as customisation. Three system classes do this in different ways. An industry ERP brings these functions with it; the price is a smaller vendor and partner market. A standard ERP with an industry add-on combines a broad base system with a partner's industry logic; the price is two release cycles that both affect validation. A generalist ERP gives the greatest freedom, but requires UDI and traceability to be built and validated in-house. Which class fits is decided by risk classes, number of variants, batch or serial number and the share of outsourced production steps.

2. What does the MDR require from the ERP system?
The Medical Device Regulation (EU) 2017/745 does not prescribe an ERP, but it requires data that is hard to keep without a suitable system. This includes the unique device identifier UDI for every device and its submission to the European database EUDAMED, traceability of devices in the supply chain, technical documentation and post-market surveillance with vigilance and field safety corrective actions. For the ERP this means: UDI data per variant and packaging level, batch or serial number in production and delivery, production records clearly assigned to a device, and a delivery history from which affected customers can be identified quickly. For in vitro diagnostics, the corresponding Regulation (EU) 2017/746 applies with comparable requirements.
3. How does an ERP handle the UDI?
The UDI has two parts. The device identifier UDI-DI is fixed to a product variant and packaging level and therefore belongs on the item as master data. The production identifier UDI-PI is made up of data such as batch, serial number, manufacturing or expiry date and is created in production. An ERP has to bring both together: the UDI-DI from the item master, the UDI-PI from the production order, and from these the data for the label, direct marking and shipping documents. Then there is the data for EUDAMED, submitted through an interface or a service provider. The most common weak point is variants: every size, version and packaging unit can need its own UDI-DI. In the selection, test how the system handles your actual number of variants.
4. When must reusable instruments be directly marked?
Reusable devices that are reprocessed before each use – such as surgical instruments – must carry the UDI on the product itself. The MDR deadlines are staggered by risk class; for Class I devices the transition period for direct marking ends on 26 May 2027, and for higher classes it has already expired. For the ERP this means: marking becomes its own operation with an inspection step, driven by the same UDI data as the label, and the result must be documented in the production order. Anyone who organises direct marking outside the ERP keeps two data sets for the same identifier – and that is exactly where the discrepancies arise that show up in an audit.
5. What does ISO 13485 mean for the ERP implementation?
ISO 13485 is the standard for quality management systems of medical device manufacturers. Among other things, it requires software used in quality management to be validated before first use and after changes – proportionate to the risk associated with its use. An ERP that holds batches, releases, test results or delivery history is such software. For the implementation this means: the quality-relevant functions must be defined, their risk assessed and their validation planned before the system goes live. The more of these functions are configured rather than programmed, the smaller the validation scope – and the less has to be retested with every release. That is why the validation question belongs in the selection, not in the project.
6. Batch or serial number – what does the ERP need to handle?
Both, and differently for each product. Single-use products and consumables are usually manufactured and tracked by batch, active devices and implants often by serial number. Many manufacturers run both side by side, sometimes in the same product: the device with a serial number, the accessories by batch. The ERP must therefore define for each item how it is tracked and keep tracking continuous – from goods receipt of the material through production, testing and sterilisation to delivery at line level. For serial numbers, device history comes on top: service, repair and replacement at the customer must stay assigned to the serial number. In the proof of concept, test a real case such as a complaint and have the vendor show you the complete chain.
7. How does the ERP support complaints, vigilance and recalls?
With data, not with decisions. In the event of a complaint or an incident, the manufacturer must quickly establish which batches or serial numbers may be affected, which material batches they come from and which customers received them. That requires traceability in both directions and a delivery history at line level. A field safety corrective action also needs customer contacts straight from the system and a record of which customers were informed and when. Many manufacturers run complaints and CAPA in a separate quality management system; then the interface to the ERP is decisive. What the system does not have to do: assess the incident and report it to the authority. Those decisions stay with the responsible person.
8. What needs attention with sterilisation and contract manufacturing?
Many medical technology manufacturers outsource steps such as sterilisation, coating or assembly to external service providers. For the ERP, the goods are then on the move but not available: they must be held as "at service provider", with batch or serial number, and after return they must be booked back in and released with the service provider's certificate. In sterilisation, the sterilisation batch belongs in the device's production record. Without this link, traceability breaks at exactly the point where an auditor asks. Check how the system maps subcontracted work – as its own operation with stock at the service provider, not as a purchase order with no link to the batch.
9. How long does an ERP selection take in medical technology?
The time does not go into comparing systems, but into process analysis, the assessment of quality-relevant functions and the requirements specification: variants and UDI, batch or serial number, test and release steps, subcontracted work. Only once these cases are described can a vendor show in a proof of concept how its system works with your data. We plan each stage separately – process analysis, requirements specification, market analysis, selection with proof of concept – and fix its scope before it starts.
10. What does independent ERP consulting cost a medical technology manufacturer?
The effort depends on the number of processes, sites, product variants and risk classes, not on company size alone. A manufacturer of Class I instruments with one site has different requirements from a device manufacturer with serial numbers, service at the customer and deliveries to several markets. We therefore price each stage separately – process analysis, requirements specification, market analysis, selection with proof of concept – and fix its scope before it starts. You can stop, continue or adjust the scope after each stage. Our fee is independent of the system you choose in the end: we do not sell licences and receive no vendor commission.
Start the conversation

Test your MDR and validation requirements against the system classes – before a vendor presents.

High commitment

45-minute independent strategy call

The full first conversation, with Dr. Harald Dreher or the senior consultant who leads the engagement. The aim is to clarify the decision — not to recommend a system.

Book the call
Medium commitment

15-minute orientation call

To check whether an engagement makes sense. If we're not the right people for the job, we'll say so.

Book a short call
Low commitment

Prefer to email?

Tell us where you stand. We'll reply with a clear next step — not a sales pitch.

Email us