MMedFortis Free Gap Scan™
Buyer's guide

How to Choose Post-Market Surveillance Software

By Kieran Redington, Founder of MedFortis Updated 21 July 2026 ~9 min read

Post-market surveillance software promises the same thing everywhere: stop monitoring regulators and marketplaces by hand, stay current by default, and walk into audits with evidence instead of anecdotes. Under the promise, products differ enormously — in what they watch, how they prove it, and whether they'll pass your own procurement review. This guide gives you seven evaluation criteria, the red flags, and the questions that separate marketing from capability. (Full disclosure: we make MedFortis, a product in this category — the criteria below are the ones we think any serious tool, ours included, should be held to.)

First, know what you're buying

PMS software is the external-signal layer of your surveillance obligations: it watches regulator publications, adverse-event databases and the open market, and turns findings into alerts and evidence. It is not a QMS — complaint handling, CAPA, PMCF and document control stay where they are; this feeds them. Vendors that blur that line are usually strong at one side and hand-waving the other.

Anchor your requirements in the obligation itself: under EU MDR Articles 83–92 your PMS system must actively and systematically collect exactly this external data and produce a documented PMS report or PSUR from it. Whatever you buy should demonstrably shorten the path from "signal exists somewhere" to "signal in my report, with evidence."

The seven evaluation criteria

1. Source coverage — regulators

The single biggest differentiator. Many tools are FDA-only, because the US data is the easiest to integrate. If you sell into the UK, EU, Canada or Switzerland, FDA-only monitoring leaves documented blind spots — MHRA field safety notices, Health Canada recalls, EU Safety Gate alerts and Swissmedic actions each publish things the FDA never will. Ask for the list of covered regulators, not the phrase "global coverage."

2. Source coverage — the open market

Grey-market and unauthorized listings are where recalled, diverted and investigational devices resurface — and no regulator watches it for you. Check which marketplaces are covered (general ones like eBay and Google Shopping, and medical-specific resale sites like DotMed and LabX), and how listings are verified: title matching alone drowns you in false positives; image-based verification with a confidence score is what makes the volume workable.

3. Evidence trail

In an audit, "we monitor continuously" is a claim; a timestamped log is a fact. Findings should be captured and preserved at detection time (listings vanish fast), hashed or otherwise tamper-evident, and every user action recorded — the standard your auditors will reference is FDA 21 CFR Part 11. If evidence is a screenshot folder, keep looking.

4. Workflow, not just alerts

A feed of findings without a workflow becomes a second inbox nobody owns. Look for a triage queue with assignment, notes and status; authorized-seller whitelisting so legitimate partners never get flagged; and practical portfolio management — bulk device import (e.g., from FDA GUDID by UDI) matters enormously once you're past a handful of products.

5. Alerts and integrations

Signals should reach people where they work: notification centre, email, and webhooks or an API for pushing events into your QMS, ticketing or data warehouse. An API also future-proofs you — the tool that can't export its data is the tool you can't leave.

6. Security and procurement readiness

Your infosec review will ask regardless, so ask first: tenant isolation model (shared database vs isolated environment per customer), SSO (OIDC/SAML) and SCIM provisioning, MFA, role-based access, audit logging, and machine-to-machine API credentials. For device manufacturers this isn't box-ticking — the data includes your portfolio and your problems.

7. Reporting outputs

The end product of PMS is a document: your PMSR or PSUR. A tool that generates report-ready annexes from its own data — rather than leaving you to export CSVs and reformat — pays for itself every reporting cycle. Ask to see an actual generated output during the demo, on data resembling yours.

Red flags

Questions to ask every vendor

  1. Exactly which regulators and marketplaces do you ingest, and how often does each update?
  2. Show me a device lookup live — how fresh is this data, and is it served from your store or scraped on demand?
  3. How is a marketplace listing verified as my device rather than a keyword match?
  4. Walk me through one finding end to end: detection → triage → evidence → takedown/report.
  5. What exactly is preserved per finding, and how would I prove its integrity to an auditor two years later?
  6. What's your tenant isolation model? SSO/SCIM/MFA? Can I see the audit log?
  7. Generate a PSUR-ready annex in front of me. What manual work remains after this?
  8. How do I get my data out — full export, API, both?
The strongest demo request: ask the vendor to run the tool on your actual device lines before you commit to anything. A vendor confident in coverage will show you your own data; one who insists on canned demo data is telling you something. (This is what our free Gap Scan is — and any competent competitor should offer the equivalent.)

The evaluation checklist

CriterionMinimumStrong
Regulator coverageFDA (MAUDE, recalls)+ MHRA, Health Canada, EU Safety Gate, Swissmedic, EUDAMED
Open marketeBay keyword search+ Google Shopping, DotMed, LabX; AI image verification; seller networks
EvidenceFindings storedCaptured at detection, hashed, PDF-preserved, full audit trail (Part 11-aligned)
WorkflowAlert listTriage queue, assignment, whitelisting, GUDID/UDI bulk import
IntegrationsEmail alerts+ Notification centre, webhooks, API, data export
SecurityPassword loginIsolated environment per customer, OIDC SSO, SCIM, MFA, RBAC, audit log
ReportingCSV exportOn-demand PMS/PSUR-ready annexes

Score honestly against the "strong" column, weight by your own footprint (jurisdictions, device count, resale exposure), and make every vendor — us included — demonstrate rather than describe. For grounding on the underlying data sources themselves, our guides to FDA MAUDE and the regulators beyond the FDA cover what each one publishes and where the manual workflows break down.

Evaluate us first — on your devices

The free MedFortis Gap Scan runs the checklist's hardest test for you: a live lookup across six regulators plus the resale market, on your actual device lines, in 30 minutes.

Request your free Gap Scan →

Key takeaways

  • PMS software is the external-signal layer — it feeds your QMS, it doesn't replace it.
  • The seven criteria: regulator coverage, open-market coverage, evidence trail, workflow, integrations, security, reporting outputs.
  • Biggest differentiators in practice: multi-regulator coverage (vs FDA-only) and evidence preservation (vs alert feeds).
  • Red flags: unnamed "global coverage," live-scraped lookups, no capture-at-detection, unverifiable compliance badges.
  • Make every vendor run their tool on your device lines before you commit — demonstration over description.
This article is provided for general information only and is not legal, regulatory or procurement advice. MedFortis is a product in the category discussed; we've disclosed that throughout and encourage you to apply every criterion in this guide to our product as strictly as to any other.