The Control Plane Is Part of the Trust
A companion reading from the device-management vendor seat — what the control plane must evidence, and when constraining a device is someone else’s regulatory problem
The console is inside the trust boundary: the sponsor cannot rely on the locked-down state without evidence from it — yet locking a device down does not make you a manufacturer.
MDR Art. 16(1)(b)–(c) presupposes a device and follows the party that specifies the configuration and its purpose — usually the sponsor, acting on your platform. Harden and evidence console access, document the lock-down profile, run every push as a logged change event, and record per study whether Art. 16 is engaged.
Four perimeters land on the console, and each has an evidence artifact
| Perimeter | What it means for you | Vendor action / evidence |
|---|---|---|
| Security (QPP-05) | The control plane is part of the attack surface; its compromise is the fleet's compromise. | Harden console access; evidence MFA, least-privilege and audit logging. |
| Configuration (QPP-00) | Lock-down must be documented against the study's intended use. | Record the lock-down profile against the intended use stated by the sponsor. |
| Economic operator (QPP-03) | Whether Art. 16(1)(b)–(c) is engaged, and by whom, turns on intended purpose. | Record, per study, whether the configuration engages Art. 16 for the sponsor or for you. |
| Change control (QPP-07) | Policy and OS pushes are change events across the fleet. | Notify, schedule and log pushes as change events — and say which are reversible. |
Four facts about the control plane a sponsor will ask you to evidence
Compromise of the control plane is compromise of the fleet; the fleet is only as secure as its management plane. Shared or weak console credentials are the first failure mode.
Whether it changes the device's regulatory position depends on intended purpose, not on the push. Neither MDCG 2019-11 Rev. 1 nor MDCG 2023-4 treats a managed handset as a controlled platform.
MDR Art. 16(1)(b)–(c) attaches to the party that supplies the device under its own name or changes its purpose — normally the sponsor, not the vendor that applies the configuration.
An unmanaged mid-study push can alter the state the sponsor validated, and the audit trail is the only record it happened. "We just manage devices" is itself a trusted, in-scope function.
Five moves, in order of what breaks first
- 1Harden and evidence console access — MFA, named accounts, least privilege, session logging, no shared or default credentials.
- 2Document the lock-down profile so the configuration act is recorded against the intended use, not assumed.
- 3Run every push under change control: a notified, logged event, not a silent alteration of the validated state.
- 4Assess operator duties up front so constraining a device to medical use does not draw an unowned obligation for you or the sponsor.
- 5Retain the audit trail of console actions — who changed what, when — and make it available to the sponsor.
MDR Art. 16(1)(b)–(c) · ICH E6(R3) s.3.6 · EMA/INS/GCP/112288/2023 Annexes 2, 3 and 4 · 21 CFR 11.10(d) and 11.10(e) · ISO/IEC 27001:2022 · MDCG 2019-11 Rev. 1 (June 2025) · MDCG 2023-4 (October 2023)
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call