A biocompatibility evaluation report can look finished the moment every box in the standard test matrix has a checkmark next to it. It isn’t actually finished until the report also explains why those were the right boxes to check for this device, in this material, against this specific pattern of patient contact.
What decides which endpoints apply
ISO 10993-1 sorts a device’s patient contact along two axes: the nature of contact — surface device, external communicating device, or implant — and the duration of contact, from limited (24 hours or less) through prolonged (up to 30 days) to permanent (beyond 30 days). Cross those two axes with the tissue or fluid actually contacted and the standard’s Table A.1 points to a specific set of endpoints: cytotoxicity and sensitization for nearly everything, and irritation, systemic toxicity, genotoxicity, implantation effects, or hemocompatibility depending on how far up the contact-and-duration scale the device sits. A device that mixes categories — surface contact with skin but external communicating through a lumen, say — gets evaluated against the more demanding of the two. None of this classification is supposed to be asserted; a report that states the category without showing the reasoning is asking a reviewer to take the hardest part of the analysis on faith.
Where chemical characterization changes the analysis
FDA’s guidance also recognizes a second path into the same endpoints: chemical characterization under ISO 10993-18, paired with a toxicological risk assessment under ISO 10993-17, can justify skipping a biological test when the extractable and leachable compounds are already identified, quantified, and shown to fall under an acceptable exposure threshold. The chemistry alone doesn’t get you there — a list of compounds and concentrations is data, not a conclusion. The toxicological risk assessment is the document that has to make the connection explicit: here is what’s present, here is the toxicological basis for why that level of exposure is acceptable for this contact type and duration. A report that stops at the chemistry, without that bridging assessment, has done half the analysis and labeled it complete.
Where this goes wrong
Treating the endpoint matrix as a checklist to complete
Running every test in Table A.1 without explaining why each one applies to this device looks thorough, but it isn’t the same as engaging with the reasoning a reviewer is actually checking.
Citing a raw-material certificate as if it covers the finished device
A resin’s existing biocompatibility data doesn’t account for what molding, adhesives, or sterilization add to or change about that material’s surface chemistry.
Skipping the toxicological risk assessment when leaning on chemistry
An extractables list isn’t a safety conclusion by itself; the toxicological risk assessment is the document that has to make that case, and a report that omits it has data but no argument.
None of this is unique to biocompatibility — it’s the same discipline of documented, device-specific reasoning that a risk management file runs on elsewhere in the same submission. What makes a biocompatibility file distinct is how much of the reasoning happens before a single test is run, in the classification decision that determines which tests are even worth running.
Sources & further reading
- FDA Guidance — Use of ISO 10993-1 in the biological evaluation of medical devices fda.gov
- FDA — CDRH Recognized Consensus Standards database (covers the ISO 10993 series) fda.gov
- Regulatory Academy — Building the 510(k) — eSTAR, Screening, and the Testing Burden regulatoryacademy.com
- Regulatory Academy — How to Read a Risk Management File regulatoryacademy.com
This essay is provided for general educational purposes and reflects the regulatory landscape as of its publication date. It is not legal, regulatory, or career advice.