UdiWatch

Notes · 30 September 2026

How to monitor EUDAMED for changes

Monitor an EUDAMED UDI-DI or manufacturer SRN by storing a public snapshot and comparing the next read. The first read is a baseline, not an alert.

Monitoring EUDAMED means noticing when a public UDI-DI or manufacturer SRN is no longer the record you last relied on. The official register is a publication system. It does not email your purchasing team when a manufacturer sets a device to no longer placed on the EU market. Someone, or something, has to read it twice and compare.

A watch is a stored comparison

The reliable version is boring:

  1. Identify the subject. A UDI-DI for a device. An SRN for the manufacturer.
  2. Read the public record and store the fields you are willing to act on.
  3. Read it again later. Write an event only where a new value differs and the new value is not empty.

For a UDI-DI those fields are market status, status date, trade name, risk class, catalogue reference, manufacturer status, version, and the published certificate number, expiry, and status. For an SRN they are the actor name, the actor status, and the count of registered devices. Country is displayed and not part of the comparison. Lot numbers and serial numbers are not in the public device record we read, so they are not on the watch.

Empty-to-filled can be a change. Filled-to-empty is ignored, because a thin response after a timeout or a partial payload would otherwise look like “trade name deleted”. A read that fails does not update certificates at all. The previous snapshot remains the baseline.

What you should expect the first day

The first successful read creates no alert. If a product emails you “12 changes” the moment you paste a spreadsheet, it is treating the current register as news. It is not news. It is the starting point. Real events start at the second read.

After that, the audit trail is the product: subject, time, field, old value, new value. A webhook can carry the same JSON, signed with HMAC-SHA256 over the raw body, so a receiving system can reject anything that did not come from the key you stored. Mail is only useful once the server actually has SMTP. Do not design a process that assumes an inbox is already live. The webhook section has the verification snippet.

What this will not catch

  • A change that exists only inside a non-public EUDAMED workspace.
  • A certificate that was never linked to the basic UDI-DI in the public certificate search.
  • Vigilance, FSNs, or clinical-investigation updates. Different modules, not this feed.
  • The entire register. A watchlist is the devices and manufacturers you named, up to the cap on the account. A sitemap of every UDI-DI in Europe is not a product, and it is not what the public API is for.

You can start from a known code. Open 10887714028257 or AT-MF-000000252, then add it in the app. The trial is seven days and 25 watches. When Stripe is connected, a card starts that trial and is not charged until it ends. Cancel anytime and keep the days left. A second subscription does not include another free trial. Until Stripe is connected, nothing is charged.

UdiWatch is independent of the European Commission. If the public API and the Commission’s own screen disagree, the screen is the authority and the API response is what we were able to read.

More notes

Not an official European Commission page. Public device and actor pages on this site repeat fields the register already publishes.