Qualysec
Blog

UKCA Marking Requirements vs. CE Mark: Dual Compliance Guide for Medical Devices

Learn UKCA marking requirements for medical devices, compare UKCA vs CE marking, and understand conformity assessment and Great Britain market access.

Published on August 26, 2026
Read Time: 12 min
CONNECT WITH US

Selling a medical device across Europe and Great Britain now comes with a regulatory choice that did not exist before Brexit. Manufacturers need to consider two conformity systems, different market access routes, and separate regulatory responsibilities depending on where the device will be sold.

For many companies, the decision is not simply UKCA versus CE. Around 90% of medical devices currently used in Great Britain carry the CE mark, according to the MHRA. CE marked devices also remain accepted in Great Britain under transitional arrangements, even as the UK develops its future regulatory framework.

Understanding UKCA marking requirements alongside CE obligations can therefore help you avoid unnecessary testing and documentation work.

This guide explains where the two routes differ, where they overlap, and how you can plan dual compliance more efficiently.

The Core Differences: UKCA vs. CE Mark for MedTech

CE and UKCA are separate legal conformity routes. CE supports access to the EU and EEA and is still accepted for eligible medical devices in Great Britain under current transitional rules. UKCA is the domestic route for Great Britain under the UK MDR 2002.

UKCA alone does not give you access to the EU or Northern Ireland. Northern Ireland generally requires CE marking. If a UK body performs the required assessment, the device uses CE with UKNI. That combination cannot be used for EU market access.

Area UKCA CE
Primary market Great Britain EU and EEA, plus eligible devices accepted in Great Britain
Main legislation UK MDR 2002, as amended EU MDR 2017/745 or IVDR 2017/746
Safety terminology Essential Requirements General Safety and Performance Requirements
Assessment body UK Approved Body EU Notified Body
Declaration UK Declaration of Conformity EU Declaration of Conformity
Standards UK designated standards EU harmonised standards
Overseas representative UK Responsible Person EU Authorised Representative
Registration MHRA registration Applicable EUDAMED obligations
Northern Ireland UKCA alone not accepted CE or CE plus UKNI, where applicable

A UK Approved Body assesses devices requiring third-party review for UKCA. An EU Notified Body performs the same role for CE. Some lower-risk devices may qualify for self-declaration, while higher-risk devices generally need external assessment.

You can maintain CE and UKCA together, but each route must be met independently. One approval does not grant the other mark.

Standards may overlap technically, but their legal status is separate. Check editions, amendments, designation or harmonisation status, and cessation dates for each market.

Dual compliance is a market access decision for both markets efficiently.

The MHRA Transitional Timeline: 2028 & 2030

In 2026, qualifying CE marked medical devices can still be placed on the Great Britain market. The deadline is not the same for every device. So the claim that all CE marked devices can remain on the market until 2030 is incorrect. The relevant date depends on the EU legislation used for conformity.

Current CE Recognition Timeline for Great Britain

Existing CE compliance route Current GB acceptance
MDD or AIMDD compliant general medical devices Earlier of certificate expiry or 30 June 2028
IVDD compliant IVDs Earlier of certificate expiry or 30 June 2030
MDR compliant general medical devices 30 June 2030
IVDR compliant IVDs 30 June 2030

These dates remain the current MHRA position while the government considers future recognition arrangements for CE marked devices.

The table covers the main routes, but some devices need closer review before you rely on a date. These include:

  • Certain Class I devices that were self declared under the MDD
  • Reusable surgical instruments
  • Devices that moved to a higher classification under the MDR or IVDR
  • Devices relying on EU provisions that extend the validity of existing certificates

For example, some Class I devices that did not need Notified Body involvement under the MDD but require it under the MDR can continue to qualify for GB recognition until 30 June 2028. Devices relying on an expired certificate generally need that certificate to remain valid under applicable EU transitional rules.

From a UKCA marking requirements perspective, this gives manufacturers an important choice. If your device qualifies under the CE transition route, you can currently access Great Britain without completing a separate UKCA conformity assessment.

Important 2026 Update: Indefinite CE Recognition Is Proposed, Not Yet the Current Rule

In February 2026, the MHRA proposed indefinite recognition of qualifying CE marked devices in Great Britain. At the time, it said around 90% of medical devices used in Great Britain carried CE marking. The consultation closed on 10 April 2026.

The proposal has not replaced the current rules. Manufacturers should continue planning against the existing statutory transition periods until the government changes the legislation.

If indefinite recognition of MDR and IVDR compliant devices goes ahead, separate UKCA compliance may have less commercial value for some manufacturers. Therefore, you should not assume every device must move to UKCA after 2030. Monitor MHRA updates before committing to costly certification programmes.

Last Updated: August 2026 

Regulatory & Legal Disclaimer: This guide is for informational purposes only and does not constitute formal legal or regulatory counsel. Medical device manufacturers must verify compliance against official regulations from the UK Medicines and Healthcare products Regulatory Agency (MHRA) and the European Commission (EUR-Lex).

Get CREST-Accredited Penetration Testing Services

Qualysec delivers CREST-accredited VAPT services with real-world attack simulations, validated findings, and actionable remediation reports.

Request a Quote



CREST Member

Dual compliance does not require you to build two technical evidence packages from the beginning. A better approach is one controlled evidence library, with separate EU and Great Britain compliance mappings.

Testing, risk data and technical documentation may support both routes where requirements overlap. However, classification, standards mapping, declarations, conformity conclusions and other regulatory outputs must still be managed separately.

Build a Shared Technical Evidence Backbone

You can organise the technical evidence needed for both CE and UKCA around one controlled documentation set, then map each item to the requirements of the relevant market. Typical evidence may include:

  • Device description, intended purpose and available variants
  • Design and manufacturing information
  • Quality management system records
  • Risk management documentation, including ISO 14971 based processes where used
  • Verification and validation results
  • Electrical safety and EMC evidence, where applicable
  • Biological evaluation and biocompatibility evidence
  • Usability and human factors documentation
  • Sterilisation and packaging validation
  • Software lifecycle records for software-containing devices
  • Clinical evaluation or IVD performance evidence
  • Cybersecurity risk analysis and security verification for connected or software-based devices
  • Labelling and instructions for use
  • Postmarket surveillance procedures and supporting records

The exact evidence depends on the device, its classification, intended purpose and applicable regulatory requirements. A shared evidence base can reduce unnecessary duplication, but it still needs separate CE and UKCA compliance mapping.

Create Separate UK and EU Regulatory Mappings

Once the shared evidence library is in place, map it separately against the legal requirements for each market.

For CE, check:

  • MDR or IVDR classification
  • Applicable General Safety and Performance Requirements
  • Relevant EU harmonised standards
  • EU Declaration of Conformity
  • Notified Body involvement, where required
  • Obligations for applicable EU economic operators
  • Current EUDAMED requirements

Under the MDR and IVDR, manufacturers must follow the conformity route that applies to the device and its classification. As of 28 May 2026, four EUDAMED modules are mandatory, including Actor Registration, UDI and Device Registration, Notified Bodies and Certificates, and Market Surveillance.

For UKCA, check:

  • Classification and conformity route under the UK MDR 2002
  • Applicable Essential Requirements
  • Relevant UK designated standards
  • UK Declaration of Conformity
  • UK Approved Body involvement, where required
  • UK Responsible Person requirements
  • MHRA registration

UK designated standards can support a presumption of conformity with corresponding Essential Requirements, but manufacturers remain responsible for meeting the applicable UK legislation.

Cybersecurity Evidence for Software and Connected Medical Devices

Software and connected medical devices need security evidence that matches how the product actually works. A cloud platform, API, mobile app or connected device can introduce risks that affect safety, performance and ongoing operation. EU guidance treats cybersecurity as part of risk management and verification across the device lifecycle.

Depending on the product, the evidence covers:

  • Threat modelling
  • Attack surface analysis
  • Authentication and authorisation testing
  • API and network security
  • Encryption checks
  • Secure update mechanisms
  • Vulnerability management
  • Software component and dependency risks
  • Penetration testing, where the architecture and risk justify it
  • Remediation and retesting records

Practical Insight: In dual-market auditing, mapping Software Bill of Materials (SBOM) vulnerabilities directly to both the EU MDR GSPR 17.2 and the UK Essential Requirement 13 within a single testing protocol prevents duplicative penetration testing cycles. 

UKCA Marking: Mandatory Operational Steps for the UK

Using CE recognition for Great Britain does not remove the UK obligations that apply after conformity has been established. Manufacturers still need to deal with matters such as representation, MHRA registration and applicable labelling before placing a device on the GB market.

Appoint a UK Responsible Person if the Manufacturer Is Based Outside the UK

A manufacturer established outside the UK must appoint a single UK Responsible Person covering the medical devices it places on the Great Britain market. The UKRP acts on the manufacturer’s behalf for specified regulatory tasks, including device registration with the MHRA.

If you also sell in the EU, an EU Authorised Representative may be required separately. The UKRP and EU Authorised Representative are different roles under different regulatory systems.

Labelling depends on the marking used:

  • UKCA device: UKRP name and address must appear on the labelling, outer packaging or instructions for use, as applicable.
  • CE only device recognised in GB: appointing a UKRP does not by itself require UKRP details to appear on the label.
  • CE and UKCA device: the UKRP labelling requirement applies because the UKCA mark is present.

Register the Device With the MHRA

Every medical device placed on the Great Britain market must be registered with the MHRA before it is sold there. This includes CE marked devices that qualify for the current GB recognition route.

A CE certificate or registration in the EU does not complete this step for Great Britain. MHRA registration is separate and remains part of GB market access, regardless of whether the device uses CE or UKCA conformity.

Account for the 2026 MHRA Registration Fee

From 1 April 2026, MHRA device registration moved to a new annual fee structure. The statutory charge for the 2026 to 2027 period is £300 per Level 2 GMDN category, or per Level 1 category where no Level 2 category exists.

Do not treat £300 as the total cost of UKCA compliance. Approved Body assessment, laboratory work, clinical evidence, cybersecurity testing, remediation, UK Responsible Person services and regulatory support can add separate costs. Those amounts vary too much by device and project to give one reliable UKCA total.

Maintain Great Britain Post Market Surveillance

Since 16 June 2025, updated GB post-market surveillance rules have applied to relevant devices placed on the market or put into service from that date. They apply to both CE and UKCA-marked devices.

Manufacturers must maintain a PMS system covering safety and performance data, incident reporting, trend analysis and corrective actions.

Reporting depends on device category and risk. Applicable devices require either a Post Market Surveillance Report or a Periodic Safety Update Report, with higher risk devices generally subject to PSUR requirements.

Keep EU Registration Separate

Selling in the EU brings a separate registration track. From 28 May 2026, four EUDAMED modules became mandatory: Actor Registration, UDI and Device Registration, Notified Bodies and Certificates, and Market Surveillance.

For manufacturers serving both markets, EUDAMED and MHRA registration must be managed independently. Work completed in one system does not replace the required submissions in the other.

Futureproof Your Product Launch With Qualysec

Cybersecurity findings are easier to fix before regulatory submission than after your documentation is already under review. Qualysec helps MedTech teams with medical device penetration testing for connected devices and supporting systems early, then turns the findings into clear technical evidence.

Testing can cover medical device software, mobile apps, APIs, cloud environments, external networks, and IoT systems. We combine automated checks with manual penetration testing to find exploitable weaknesses and attack paths that scanners may miss.

Your team receives:

  • Severity-rated findings
  • Reproduction steps and technical proof
  • Remediation guidance
  • Executive reporting
  • Retesting after fixes

For manufacturers managing UKCA testing alongside CE preparation, the same assessment may support both evidence sets where the product and risks overlap. Qualysec does not issue CE or UKCA approval. It provides the security testing and evidence that can strengthen your wider submission.

Talk to Qualysec about penetration testing before your MedTech product enters regulatory review.

Conclusion

There is no advantage in pursuing two certification routes simply because both exist. Start with your actual market plan, then decide whether CE, UKCA, or both give you the access your business needs.

A well-planned compliance programme can still reuse much of the same technical, quality, risk, cybersecurity, and UKCA marking requirements evidence. The legal conclusions and market obligations remain separate.

For now, qualifying CE marked devices continue to have a route into Great Britain under the current transition arrangements.

The bigger point is to avoid making long-term decisions on assumptions. The MHRA is still considering indefinite CE recognition, so future market access may look different from today. Build for the markets you need now, but keep enough flexibility to adapt when the rules change.

Speak Directly With Qualysec’s Certified Security Experts

Discover vulnerabilities before attackers exploit them

Schedule Free Consultation

Security Expert

FAQs

1. Can I use my existing EU CE mark to sell medical devices in the UK?

Yes, qualifying CE marked devices can currently enter Great Britain under transitional recognition rules. The applicable period depends on whether compliance is under MDD, AIMDD, IVDD, MDR or IVDR. MHRA registration, UK Responsible Person and GB surveillance duties still apply. Northern Ireland follows CE or CE plus UKNI rules.

2. What is required to transition from CE compliance to a full UKCA mark?

UKCA requires its own conformity route. You must confirm UK classification, assess the applicable Essential Requirements, map existing evidence, close UK specific gaps, involve a UK Approved Body where required, prepare the UK Declaration of Conformity, meet labelling rules and complete MHRA registration. Existing CE evidence may still be reusable.

3. Do UKCA marking requirements mandate independent software testing?

No universal rule requires every software medical device to undergo independent third-party penetration testing for UKCA. Manufacturers still need suitable cybersecurity and verification evidence for the device’s risks. For connected products, Qualysec can provide independent penetration testing, remediation evidence and retesting without acting as the UKCA approval body.

Chandan Sahoo

About Chandan Sahoo

Chandan Kumar Sahoo is the Co-Founder and Chief Executive Officer (CEO) at Qualysec. With over 8 years of experience in security testing and software quality assurance, he leads corporate strategy and expansion, helping organizations globally secure their web, mobile, and cloud environments.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.