What this guide covers
First, know what you're buying
PMS software is the external-signal layer of your surveillance obligations: it watches regulator publications, adverse-event databases and the open market, and turns findings into alerts and evidence. It is not a QMS — complaint handling, CAPA, PMCF and document control stay where they are; this feeds them. Vendors that blur that line are usually strong at one side and hand-waving the other.
Anchor your requirements in the obligation itself: under EU MDR Articles 83–92 your PMS system must actively and systematically collect exactly this external data and produce a documented PMS report or PSUR from it. Whatever you buy should demonstrably shorten the path from "signal exists somewhere" to "signal in my report, with evidence."
The seven evaluation criteria
1. Source coverage — regulators
The single biggest differentiator. Many tools are FDA-only, because the US data is the easiest to integrate. If you sell into the UK, EU, Canada or Switzerland, FDA-only monitoring leaves documented blind spots — MHRA field safety notices, Health Canada recalls, EU Safety Gate alerts and Swissmedic actions each publish things the FDA never will. Ask for the list of covered regulators, not the phrase "global coverage."
2. Source coverage — the open market
Grey-market and unauthorized listings are where recalled, diverted and investigational devices resurface — and no regulator watches it for you. Check which marketplaces are covered (general ones like eBay and Google Shopping, and medical-specific resale sites like DotMed and LabX), and how listings are verified: title matching alone drowns you in false positives; image-based verification with a confidence score is what makes the volume workable.
3. Evidence trail
In an audit, "we monitor continuously" is a claim; a timestamped log is a fact. Findings should be captured and preserved at detection time (listings vanish fast), hashed or otherwise tamper-evident, and every user action recorded — the standard your auditors will reference is FDA 21 CFR Part 11. If evidence is a screenshot folder, keep looking.
4. Workflow, not just alerts
A feed of findings without a workflow becomes a second inbox nobody owns. Look for a triage queue with assignment, notes and status; authorized-seller whitelisting so legitimate partners never get flagged; and practical portfolio management — bulk device import (e.g., from FDA GUDID by UDI) matters enormously once you're past a handful of products.
5. Alerts and integrations
Signals should reach people where they work: notification centre, email, and webhooks or an API for pushing events into your QMS, ticketing or data warehouse. An API also future-proofs you — the tool that can't export its data is the tool you can't leave.
6. Security and procurement readiness
Your infosec review will ask regardless, so ask first: tenant isolation model (shared database vs isolated environment per customer), SSO (OIDC/SAML) and SCIM provisioning, MFA, role-based access, audit logging, and machine-to-machine API credentials. For device manufacturers this isn't box-ticking — the data includes your portfolio and your problems.
7. Reporting outputs
The end product of PMS is a document: your PMSR or PSUR. A tool that generates report-ready annexes from its own data — rather than leaving you to export CSVs and reformat — pays for itself every reporting cycle. Ask to see an actual generated output during the demo, on data resembling yours.
Red flags
- "Global coverage" without a source list. If the regulators aren't named, assume FDA-only with aspirations.
- Live-scraping lookups. Tools that fetch regulator sites at query time are slow, brittle and rate-limited; continuously ingested data is the difference between a lookup and a wait.
- No evidence preservation. Alerts without capture means every disputed finding becomes your word against a deleted listing.
- Compliance badges that don't survive questions. If a vendor claims a certification or framework, ask for the evidence pack — and drop any vendor that can't produce it. (Hold us to that too.)
- Per-seat pricing on a monitoring tool. Surveillance value scales with devices and sources watched, not logins; pricing that punishes adding your quality team to the queue distorts how you'll use it.
Questions to ask every vendor
- Exactly which regulators and marketplaces do you ingest, and how often does each update?
- Show me a device lookup live — how fresh is this data, and is it served from your store or scraped on demand?
- How is a marketplace listing verified as my device rather than a keyword match?
- Walk me through one finding end to end: detection → triage → evidence → takedown/report.
- What exactly is preserved per finding, and how would I prove its integrity to an auditor two years later?
- What's your tenant isolation model? SSO/SCIM/MFA? Can I see the audit log?
- Generate a PSUR-ready annex in front of me. What manual work remains after this?
- How do I get my data out — full export, API, both?
The evaluation checklist
| Criterion | Minimum | Strong |
|---|---|---|
| Regulator coverage | FDA (MAUDE, recalls) | + MHRA, Health Canada, EU Safety Gate, Swissmedic, EUDAMED |
| Open market | eBay keyword search | + Google Shopping, DotMed, LabX; AI image verification; seller networks |
| Evidence | Findings stored | Captured at detection, hashed, PDF-preserved, full audit trail (Part 11-aligned) |
| Workflow | Alert list | Triage queue, assignment, whitelisting, GUDID/UDI bulk import |
| Integrations | Email alerts | + Notification centre, webhooks, API, data export |
| Security | Password login | Isolated environment per customer, OIDC SSO, SCIM, MFA, RBAC, audit log |
| Reporting | CSV export | On-demand PMS/PSUR-ready annexes |
Score honestly against the "strong" column, weight by your own footprint (jurisdictions, device count, resale exposure), and make every vendor — us included — demonstrate rather than describe. For grounding on the underlying data sources themselves, our guides to FDA MAUDE and the regulators beyond the FDA cover what each one publishes and where the manual workflows break down.
Evaluate us first — on your devices
The free MedFortis Gap Scan runs the checklist's hardest test for you: a live lookup across six regulators plus the resale market, on your actual device lines, in 30 minutes.
Request your free Gap Scan →Key takeaways
- PMS software is the external-signal layer — it feeds your QMS, it doesn't replace it.
- The seven criteria: regulator coverage, open-market coverage, evidence trail, workflow, integrations, security, reporting outputs.
- Biggest differentiators in practice: multi-regulator coverage (vs FDA-only) and evidence preservation (vs alert feeds).
- Red flags: unnamed "global coverage," live-scraped lookups, no capture-at-detection, unverifiable compliance badges.
- Make every vendor run their tool on your device lines before you commit — demonstration over description.