Skip to main content
Category: Compliance & Audit

Common Specifications

Also known as: CS, Common Specifications (CS)
Simply put

Common Specifications are detailed technical and/or clinical requirements adopted by the European Commission that describe how certain products should meet regulatory requirements when no harmonized standard covers the same ground. In the European Union medical device context, they set out practical rules for demonstrating that particular types of devices comply with the applicable Regulation. The evidence provided here describes their role in EU medical device and in vitro diagnostic regulation; the same term is also used in other EU frameworks, though the source material supplied does not detail those uses.

Formal definition

As described in the evidence, a Common Specification is 'a set of technical and/or clinical requirements for which no harmonized standard is available,' functioning as detailed practical rules for how specified device types comply with certain requirements of a Regulation (the sources cite Regulation (EU) 2017/745, the Medical Devices Regulation, and reference the IVDR). Under the EU MDR/IVDR regime the sources indicate CS provide a basis for the conformity assessment procedure, including for Annex XVI devices that have no intended medical purpose. Note on legal status: the supplied evidence characterizes CS as detailed practical rules and as a concept introduced alongside harmonized standards, but it does not contain the text establishing whether or when compliance is mandatory or the specific implementing acts adopting them; practitioners should consult the underlying legal texts and any adopting Commission acts to confirm binding status, the 'comply-or-justify-an-alternative' mechanism, and scope. The term is not limited to medical devices and appears in other EU instruments, but this entry is scoped only to what the provided sources support (EU MDR/IVDR); any application to AI governance frameworks is out of scope of this evidence packet and is not addressed here.

Why it matters

Common Specifications (CS) fill a specific gap in EU conformity assessment: where no harmonized standard exists to describe how a product meets regulatory requirements, the European Commission can adopt CS to provide that missing technical and/or clinical detail. In the medical device context described by the supplied sources, this matters because manufacturers rely on a predictable route to demonstrate compliance, and CS give them concrete rules to work against for device types that harmonized standards do not yet cover. The sources specifically note that CS establish a basis for the conformity assessment procedure of Annex XVI devices—products that have no intended medical purpose—where the usual evidentiary path may otherwise be unclear.

The practical significance is heightened by the legal status of CS. Where the Commission adopts them, CS are given effect through binding Commission implementing acts rather than functioning as merely optional guidance, and the EU MDR framework operates on a comply-or-justify basis: manufacturers are generally expected to meet an applicable CS unless they can duly justify that an alternative approach achieves an equivalent level of safety and performance. Practitioners should confirm the precise scope, the specific implementing act, and the justification mechanism against the underlying legal texts (for example, the relevant articles of Regulation (EU) 2017/745 and any adopting Commission implementing regulation), because the supplied evidence describes the concept but does not reproduce the clause-level text.

Beyond medical devices, the term Common Specifications is used in other EU instruments; the same drafting device—Commission-adopted specifications standing in for absent harmonized standards—appears in other EU product and technology regulation. The evidence packet supplied for this entry, however, is scoped to EU MDR/IVDR, so readers extending the concept to other frameworks should consult the specific regulation governing that domain rather than assuming the medical device treatment transfers unchanged.

Who it's relevant to

Medical device and IVD regulatory affairs professionals
Those preparing conformity assessment documentation under the EU MDR (Regulation (EU) 2017/745) or IVDR need to know which Common Specifications apply to their device type, since CS provide the practical rules for demonstrating compliance where no harmonized standard exists. They should confirm the applicable CS and its adopting act, and be prepared to either meet it or duly justify an alternative approach.
Manufacturers of Annex XVI devices
The supplied sources indicate that CS establish a basis for the conformity assessment procedure of Annex XVI devices—products with no intended medical purpose. Manufacturers of such products are directly affected because CS may be the primary detailed reference available for demonstrating compliance.
Notified bodies and conformity assessment reviewers
Bodies evaluating whether a device meets regulatory requirements use applicable Common Specifications as a benchmark during assessment, and must evaluate any manufacturer justification for departing from a CS where the comply-or-justify mechanism applies. They should reference the specific implementing act rather than general summaries.
Legal and compliance specialists tracking EU regulation
Because CS are given effect through binding Commission implementing acts and the term also appears in EU instruments beyond medical devices, legal and compliance teams need to distinguish the medical device treatment (the scope of this entry) from CS provisions in other frameworks, and to verify binding status and scope against the underlying legal texts.

Inside CS

Legal basis in the EU AI Act
Under the EU AI Act, common specifications are provided for as a mechanism relating to high-risk AI systems (addressed in Article 41). They give the European Commission a route to specify technical detail for the essential requirements applicable to high-risk AI systems, particularly where harmonised standards are absent, insufficient, or where the Commission needs to address specific safety or fundamental-rights concerns.
Instrument type
Where adopted, common specifications typically take the form of Commission implementing acts. This makes them binding EU legal instruments rather than voluntary technical standards or mere guidance. This distinguishes them from harmonised standards produced by European standardisation organisations, which remain voluntary even though compliance with them confers a presumption of conformity.
Relationship to harmonised standards
Common specifications generally function as a fallback or complement to harmonised standards. In many EU product-safety and conformity frameworks, they are used when harmonised standards do not exist, do not adequately cover the relevant requirements, or are unduly delayed. Where harmonised standards later cover the same ground, the role of the common specification is typically reassessed.
Presumption of conformity effect
Conformity with applicable common specifications typically gives rise to a presumption of conformity with the corresponding essential requirements they cover, similar to the effect associated with harmonised standards. This links technical compliance work to the legal conformity assessment for high-risk AI systems.
Comply-or-justify obligation
Where common specifications have been adopted, providers/manufacturers are generally required to comply with them unless they adopt technical solutions that meet the relevant requirements at least to an equivalent level and can duly justify that alternative approach. This comply-or-justify structure appears both in the AI Act (Article 41) and in analogous EU frameworks such as the Medical Device Regulation (Article 9).
Cross-sector precedent
The common specifications mechanism is not unique to the AI Act. It is used in other EU regulatory regimes, including the Medical Device Regulation, where common specifications have been adopted through implementing regulations. These precedents help interpret how the AI Act's common specifications are likely to operate in practice, though each regime is scoped to its own subject matter.

Common questions

Answers to the questions practitioners most commonly ask about CS.

Do Common Specifications have any application to AI governance, or are they only a general EU concept?
They have a specific, established application to AI governance. Under the EU AI Act, Article 41 provides for the Commission to adopt Common Specifications for high-risk AI systems, typically where harmonised standards are absent, insufficient, or where the Commission needs to address specific safety or fundamental-rights concerns. This mirrors the mechanism already used in other EU product-safety regimes. So the term is not confined to a generic or non-AI context; it is expressly part of the EU AI Act's conformity framework for high-risk systems.
Are Common Specifications optional practical guidance that organisations can take or leave?
No. Where the Commission adopts Common Specifications, they take the form of implementing acts and carry binding effect. Under the EU AI Act (Art. 41), a provider that follows adopted Common Specifications benefits from a presumption of conformity with the corresponding requirements. A provider that does not follow them must be able to duly justify that it has adopted technical solutions meeting the requirements at a level at least equivalent. This is comparable to the approach under the EU Medical Device Regulation (Art. 9(4)). Treating Common Specifications as mere optional guidance mischaracterises their legal status.
How do Common Specifications relate to harmonised standards under the EU AI Act?
In the EU AI Act framework, harmonised standards are the primary route to demonstrating conformity, and compliance with them confers a presumption of conformity. Common Specifications operate as a fallback or complement: the Commission may adopt them where harmonised standards do not exist, are judged insufficient, or where a standardisation request has not been met adequately. For implementation, this means providers should first track relevant harmonised standards and treat Common Specifications as the alternative pathway that applies where the Commission has acted.
What should a high-risk AI system provider do if it wants to depart from an adopted Common Specification?
Under the EU AI Act (Art. 41), a provider that does not apply adopted Common Specifications must duly justify that its chosen technical solutions meet the relevant requirements at a level at least equivalent to that provided by the Common Specifications. In practice this means documenting the alternative approach, the requirements it addresses, and the reasoning supporting equivalence, so that this justification can be presented as part of the conformity assessment and technical documentation. Organisations should confirm the exact documentary expectations against the current legal text and any implementing acts.
Where would a compliance team look to confirm whether a Common Specification has been adopted for its use case?
Common Specifications, where adopted under the EU AI Act, take the form of Commission implementing acts. Compliance teams should monitor official EU publications for such implementing acts and check whether they cover the specific high-risk AI category and requirements relevant to their system. Because adoption depends on Commission action and the state of harmonised standards, the presence or absence of a Common Specification for a given use case can change over time; verification against the current published legal texts is essential rather than relying on secondary summaries.
How should Common Specifications be integrated into an existing model risk or AI governance program?
Common Specifications relate primarily to demonstrating conformity of high-risk AI systems under EU law, so they intersect with governance (through documentation, accountability, and oversight processes) and with model risk management (through the technical controls and validation evidence that support equivalence claims). Practically, a program can map applicable Common Specifications and harmonised standards to internal control requirements, assign ownership for tracking Commission implementing acts, and ensure that where an alternative approach is used, the equivalence justification is captured within the same documentation and review workflows. This scope is specific to the EU AI Act context and does not automatically extend to other jurisdictions or non-high-risk systems.

Common misconceptions

Common specifications are voluntary technical guidance that manufacturers can choose to ignore.
Where adopted as Commission implementing acts, common specifications are binding EU legal instruments. Providers of high-risk AI systems must generally comply with them, and may only depart from them where they adopt solutions of at least equivalent effect and can duly justify that alternative approach.
Common specifications and harmonised standards are the same thing or interchangeable.
They differ in origin and legal character. Harmonised standards are developed by European standardisation organisations and remain voluntary, while common specifications are adopted by the European Commission as implementing acts. Common specifications typically operate as a fallback where harmonised standards are absent, insufficient, or delayed, though both can confer a presumption of conformity.
Common specifications have no relevance to AI governance.
The EU AI Act expressly provides for common specifications for high-risk AI systems (Article 41). They are a substantive compliance mechanism within the AI Act's conformity framework, so they are directly relevant to organisations governing high-risk AI systems placed on the EU market.

Best practices

Monitor for the adoption of Commission implementing acts establishing common specifications relevant to your high-risk AI systems, and treat any adopted common specification as a binding compliance obligation rather than optional guidance.
Where you intend to rely on an alternative technical approach instead of an adopted common specification, document a justification demonstrating that your solution meets the relevant requirements at least to an equivalent level, consistent with the comply-or-justify structure in Article 41.
Distinguish in your conformity documentation between reliance on harmonised standards and reliance on common specifications, since they have different legal origins and statuses even where both confer a presumption of conformity.
Track the interaction between harmonised standards and common specifications over time, as the relevance of a common specification may change if harmonised standards subsequently cover the same requirements.
Consult analogous EU regimes, such as the common specifications adopted under the Medical Device Regulation, as interpretive precedent for how the AI Act mechanism may operate, while confirming applicability to your specific sector and product.
Base compliance decisions on the actual legal texts of the applicable implementing acts and the AI Act itself rather than on summaries, and seek qualified legal advice where the scope or status of a specific common specification is uncertain.