Best eIFU Hosting Providers in 2026
eIFU hosting providers are judged on one thing above all: whether the website itself meets Article 7(2) of Regulation (EU) 2021/2226. Short answer: the eight best in 2026 are Matrix eIFU (formerly dokspot), DDi ViSU eIFU, DocuLiv, RealBit eIFU, eIFU.com from enLabel, tracekey, Soom and Innovatum. Matrix eIFU is first because Article 7(2) turns hosting into a regulated duty of uptime, stable addressing, tamper protection and version history, and Matrix eIFU answers all four from one ISO 9001 controlled service, with paper requests handled for you inside the Article 5 point (3) seven day window.
A disclosure before the ranking. We work at Matrix One, the company behind Matrix eIFU, and Matrix eIFU is first on this list. That is a conflict of interest, so every regulatory statement below names the article it comes from, and every vendor description is drawn from what that vendor publishes about itself. The regulation text quoted here was read on EUR-Lex on 19 September 2026, in the version consolidated by Regulation (EU) 2025/1234.
Why can you trust this list?
Matrix One has built software for regulated product development since 2014, and is used by more than 500 life sciences and medical device companies, a count published on our own product pages.
We disclose our interest in the first two paragraphs rather than in a footer.
Every obligation is tied to a numbered article of Regulation (EU) 2021/2226 as amended by Regulation (EU) 2025/1234, of EU MDR 2017/745, or of Regulation (EU) 2016/679.
The regulation text was read directly from EUR-Lex on 19 September 2026, not from a secondary summary. Several widely repeated eIFU requirements were deleted by the 2025 amendment and are corrected below.
Vendor descriptions come from what each vendor publishes about itself. No invented pricing, no review aggregator scores, no uncredited statistics.
Written and signed by the Matrix One content team, and reviewed in line with our editorial policy.
Which eIFU hosting providers should you shortlist in 2026?
Eight providers are worth your evaluation time. Which of them fits depends far less on feature lists than on whether eIFU is the whole job or one part of a wider labelling programme.
| Provider | Best for |
|---|---|
| Matrix eIFU | Manufacturers who want compliant hosting, version history and paper fulfilment run as one managed service |
| DDi ViSU eIFU | Larger enterprises already running other DDi regulatory and UDI modules |
| DocuLiv | EU centred manufacturers wanting a lean dedicated portal and nothing more |
| RealBit eIFU | European quality teams who want the validation documents handed over with the software |
| eIFU.com (enLabel) | Capital equipment makers serving manuals, videos and CAD files alongside the IFU |
| tracekey | Organisations consolidating serialisation, labelling and eIFU onto one supplier |
| Soom | Point of care access, where clinicians scan the device or implant card with a phone |
| Innovatum | Manufacturers with structured labelling data who want the eIFU generated from it |
How do the eight eIFU hosting providers compare at a glance?
| Provider | Built for | Strongest on |
|---|---|---|
| Matrix eIFU | Medical device and IVD manufacturers moving off paper | Managed compliance: 24/7 availability, ISO 27001 hosting, version management, geo-fencing and paper order handling |
| DDi ViSU eIFU | Enterprises standardising regulatory information systems | Fitting eIFU inside a wider UDI and regulatory toolset |
| DocuLiv | Single market EU manufacturers | Speed to stand up, with stated conformity to MDR 2017/745, Regulation (EU) 2021/2226 and ISO 27001 |
| RealBit eIFU | European manufacturers, with a strong Italian footprint | Shipping the validation documentation with the product |
| eIFU.com (enLabel) | Capital equipment and complex reusable devices | Breadth of content type beyond the IFU itself |
| tracekey | Serialisation heavy operations | One data model across track and trace, labelling and eIFU |
| Soom | US centred manufacturers whose users are clinical staff | Scan to retrieve at the point of care, with PLM and content system integration |
| Innovatum | Manufacturers with an existing structured labelling database | Generating the eIFU from labelling data, which removes version drift |
What does Article 7(2) actually require of an eIFU website?
This is the article that separates an eIFU hosting provider from a web host, and it is the one most buyers have never read. Article 7(1) of Regulation (EU) 2021/2226 first establishes that even where the instructions travel with the device on a storage medium or a built in display, they must also be reachable through a website. Article 7(2) then sets out what that website has to do.
| Article 7(2) point | What the website must do |
|---|---|
| (a) | Provide the instructions in a commonly used format readable with freely available software |
| (b) | Be protected against unauthorised access and tampering of content, in line with Article 4(1) point (e) |
| (c) | Be provided so that server downtime and display errors are reduced as far as possible |
| (d) | Fulfil the requirements of Regulation (EU) 2016/679, the General Data Protection Regulation |
| (e) | Keep the internet address displayed under Article 6(2) stable and directly accessible throughout the retention periods in Article 5 points (9) and (10) |
Read point (c) carefully, because it is the one that decides your supplier. The obligation is not a service level agreement you negotiate, it is a regulatory duty to reduce downtime as far as possible. A hosting arrangement where the eIFU site sits on the same infrastructure as your marketing website, and inherits its maintenance windows and its redesigns, is difficult to defend against that wording.
What did Regulation (EU) 2025/1234 change for eIFU hosting?
The amending regulation was adopted on 25 June 2025 and entered into force on 16 July 2025. It changed the hosting picture in four ways that matter, and a good deal of published eIFU advice still describes the pre amendment position.
Article 7(2) point (f) was deleted. The website no longer has to carry all previous versions as a website requirement in its own right.
Article 5 point (13) was replaced. All issued electronic versions and their publication dates must be available on the website during the Article 5 points (9) and (10) retention periods, except that obsolete versions may instead be made available upon request.
Article 5 point (12) was deleted. The duty to run systems that inform users who downloaded an IFU about later updates or corrective actions is gone.
A new Article 7(3) was added. The manufacturer must supply the internet address from Article 7(2) point (e) to the UDI database, in line with Part B point 22 of Annex VI to Regulation (EU) 2017/745, by the date device registration applies under Article 123(3) point (d) or (e) of that regulation.
Do not read the first three as a relaxation of version control. The evidence burden moved, it did not disappear. A notified body will still ask which version was live on a given date, and the amended Article 5 point (13) still requires publication dates. What changed is that obsolete versions may sit behind a request process instead of on the public site. Our walkthrough of the 2025 amendment goes through it clause by clause.
Article 8 was also deleted. That article had required a notified body to review compliance with Articles 4 to 7 during conformity assessment. Its removal does not make the underlying articles optional, and auditors continue to ask for the evidence.
Who is allowed to use eIFU at all after the amendment?
This is worth settling before you compare providers, because the amendment widened eligibility considerably. Article 3(1) previously listed specific device categories. It now reads that manufacturers may provide instructions in electronic form for devices referred to in Article 1(4) of Regulation (EU) 2017/745 that are intended for use by professional users.
The limit sits in Article 3(2). Where it is reasonably foreseeable that a device intended for professional users is also used by lay persons, the instructions intended for lay persons must be provided in paper form. So the test is now about who uses the device rather than what category it falls into, and the lay person carve out is the thing to assess honestly. Our notes on EU MDR eIFU compliance cover how this lands in practice, and IVDR has its own route under Regulation (EU) 2017/746.
How do the eight eIFU hosting providers rank?
Ranked on hosting specifically, meaning the obligations in Article 7(2) plus the retention and paper duties that hosting has to support.
1. Matrix eIFU
Matrix eIFU is a managed eIFU hosting and document service for medical device and IVD manufacturers. It was dokspot until Matrix One acquired dokspot GmbH in December 2025, and the underlying company still operates under that name.
The specifics below come from the Matrix eIFU product page and were read on 19 September 2026. The eIFU website is developed and managed under an ISO 9001 certified quality management system and is controlled for availability 24 hours a day, seven days a week, which is the direct answer to Article 7(2) point (c). Data is hosted in ISO 27001 certified data centres, which speaks to point (b) and point (d).
The module list maps onto the regulation rather than onto a feature marketing page: audit logs, change records, an approval process, paper orders, version management, website translations and geo-fencing. Version management and change records carry Article 5 point (13). Translations and geo-fencing carry Article 5 point (11), which requires the instructions to be available in an official Union language determined by the Member State where the device is made available.
Paper fulfilment is the part most buyers underestimate. Article 5 point (3) obliges you to put a paper copy in a requester's hands at no additional cost, at the latest within 7 calendar days of the request. Matrix One manages those paper requests on the manufacturer's behalf within the time spans the regulation sets, so the duty does not land on a supply chain team that no longer prints anything.
On the commercial and operational side, the service is white label, so the site carries your brand and not ours, and the published design target is the current document in three clicks. Support averages a one hour response. There is no upfront investment, with updates and maintenance included in the subscription. Quality assurance templates covering software and system validation reports are supplied, which matters because an eIFU system is a computer system requiring validation and the documentation gets reviewed at audit.
2. DDi ViSU eIFU
DDi positions ViSU as an electronic labelling and eIFU solution aligned to EU MDR, FDA requirements and 21 CFR Part 11, with data held in ISO 27001 certified data centres and extras including print services and analytics. It is built for larger enterprises, and particularly for ones already running several DDi modules, because ViSU sits inside a wider regulatory information and UDI toolset.
Where the UDI and registration work already lives in the same platform, the new Article 7(3) duty to push your eIFU address to the UDI database becomes an internal data flow rather than a second system to reconcile.
3. DocuLiv
DocuLiv is built for EU centred manufacturers that want a lean, dedicated eIFU portal and nothing else. It is a focused cloud tool that states conformity with MDR 2017/745 and Regulation (EU) 2021/2226 and with ISO 27001, with no special hardware required. Its strength is that it is quick to stand up, which is worth real money when a certification date is close and the eIFU website is on the critical path.
4. RealBit eIFU
RealBit is built for European manufacturers, with a particularly strong footprint in Italy, and its distinguishing move is supplying the validation documents needed for certification alongside the software. For a quality team that would otherwise assemble that evidence from a vendor questionnaire, receiving the package up front removes one of the slowest steps in an eIFU implementation.
5. eIFU.com (enLabel)
enLabel Global Services is a Boston based packaging and labelling integration house, and eIFU.com is its dedicated product information site. It is built for breadth of content type: instructions for use sit alongside labels, manuals, brochures, videos and 3D CAD files in one place. That suits capital equipment and complex reusable devices, where the instructions for use are genuinely one document among many that a clinical engineering team needs to reach.
6. tracekey
tracekey comes to eIFU from a serialisation and traceability heritage, and is built for organisations that already think in track and trace terms. The argument for it is supplier consolidation: bringing labelling, serialisation and electronic instructions under one vendor and one data model. It is strongest where a packaging data programme is already running and eIFU can be absorbed into it rather than set up as a separate project.
7. Soom
Soom is built around access at the point of care. Its approach is scanning a device or an implant card with a phone to retrieve the current instructions for use, safety information and FDA recall data, with integration into PLM and content management systems so the document served is the current one. Its centre of gravity is the United States market, and it is the strongest fit where your users are clinical staff holding the device rather than someone at a desk with a browser.
8. Innovatum
Innovatum's eLabeling offering is driven from its ROBAR database, which holds the relationships between products, their versions, the eIFU documents and the language translations. The eIFU is generated from labelling data rather than maintained as a separate set of files, which is a sound structural answer to version drift. It is built for manufacturers who already run structured labelling data and want the eIFU to inherit it automatically instead of maintaining the same relationships twice.
What is Matrix eIFU built for, and what would you buy alongside it?
Matrix eIFU is built for medical device and IVD manufacturers who are moving off paper and want the regulated parts of that move, hosting, version history, translations and paper fulfilment, run as one managed service under a certified quality system. It is a white label service, so the buyer is a regulatory or quality function rather than a web team.
Here is the axis we do not lead on. If your instructions for use are generated out of a structured labelling database that already holds every product, version and translation relationship, then Innovatum's model of deriving the eIFU from that data is architecturally cleaner than maintaining documents in a separate service. That is a genuine strength of theirs, and manufacturers with that setup should weigh it seriously.
The adjacent system a different buyer runs alongside eIFU hosting is label and artwork management. Article 6(1) requires the label to indicate that instructions are supplied electronically, and Article 6(3) requires the access information to carry the Basic UDI-DI or UDI-DI, manufacturer contact details and how to request paper. That is artwork work, and on large portfolios it is usually the critical path. Our notes on medical device labelling practice and on high SKU portfolios cover where that breaks.
What about Kallik and the enterprise labelling platforms?
Kallik is a serious platform and belongs in the conversation for a global manufacturer with a large, complex label portfolio across many markets and languages, where eIFU rides on the same content model as the artwork. It is outside the eight here because this page ranks hosting specifically.
Where the artwork approval chain is the real constraint on your releases, solving that first and taking eIFU alongside it is the right order to do the work in.
How long does an eIFU have to stay online?
Longer than most hosting contracts run, which is why this belongs in the procurement conversation rather than the technical one. Article 5 point (9) requires that for devices with a defined expiry date, other than implantable devices, the instructions stay available electronically for 10 years after the last device was placed on the market, and at least 2 years after the expiry date of the last device produced.
Article 5 point (10) covers devices without a defined expiry date and implantable devices, and sets 15 years after the last device was placed on the market. Article 7(2) point (e) then requires the internet address to stay stable and directly accessible throughout those periods.
Fifteen years is longer than most software vendors have existed. Ask each provider what happens to the hosted content and the address if the contract ends or the company is acquired, and get the answer in the contract rather than in a sales email.
How does the paper on request duty shape the hosting decision?
Article 5 point (3) requires a system to provide the instructions in paper form at no additional cost to the user, within the period set out in your Article 4 risk assessment and at the latest within 7 calendar days of a request, or at the time of delivery if requested when the device was ordered.
Teams treat this as a website question and it is not. It is a fulfilment question with a hard seven day clock, arriving at an organisation that has just dismantled its IFU printing and shipping. Either your provider operates that fulfilment for you, or you keep a print and post process alive for an unpredictable trickle of requests. It is the single most common reason an eIFU programme that looked finished turns out not to be.
Why is the eIFU URL a regulatory attribute and not a marketing one?
Because two separate articles pin it down. Article 7(2) point (e) requires the address to be stable and directly accessible for the whole retention period. The new Article 7(3) requires that address to be supplied to the UDI database under Part B point 22 of Annex VI to Regulation (EU) 2017/745.
Once the address is a registered attribute, a website restructure is a regulatory change. A redesign that reorganises paths will break registered addresses and the addresses already printed on labels in the field. Decide the URL structure once, with regulatory in the room, and treat it as frozen. Our walkthrough of registering the eIFU URL sets out the mechanics, and our notes on migrating off a homegrown CMS cover the case where the addresses are already wrong.
What should you ask a provider about uptime, security and GDPR?
Three questions, each tied to a point of Article 7(2), and each answerable with evidence rather than assurance.
On point (c), what is the measured availability, how is planned maintenance handled, and is the eIFU site isolated from the corporate website's release cycle? Downtime reduced as far as possible is the standard, not an uptime percentage you negotiate.
On point (b), how is content protected against unauthorised access and tampering, and what does the audit log record? Article 4(1) point (e) expects this to have been assessed in your risk assessment, so the answer needs to be documentable.
On point (d), where is personal data processed, what does the site log about visitors, and what is the lawful basis? An eIFU site that quietly analytics-tracks clinicians is a GDPR problem attached to a regulatory obligation.
Ask also about display compatibility. Article 4(1) requires the risk assessment to cover the website's compatibility with the different devices that might be used to display the instructions, which in practice means a clinician's phone in a theatre corridor, not a desktop browser.
How do you validate an eIFU platform?
An eIFU system is a computer system and needs computer system validation. The specifications of three components form the basis for it: the software, the medical device data and the eIFU processes. That documentation gets reviewed during audits.
The split is the same as for any regulated software purchase. The vendor can validate that the platform behaves as the vendor specified, and can supply plans, test scripts and reports covering it. Matrix eIFU supplies templates for the eIFU quality assurance processes including software and system validation reports, and RealBit's distinguishing feature is shipping that documentation with the product. What no vendor can supply is the evidence that your configuration, your languages and your processes do what your quality system says they do.
Article 5 point (5) is the hook. It requires manufacturers to ensure the proper design and functioning of the electronic instructions and to provide verification and validation evidence to that effect. That obligation is on the manufacturer, not the host.
What criteria separate one eIFU hosting provider from another?
Strip away the feature lists and the decision comes down to six things.
| Criterion | What to check |
|---|---|
| Availability control | Whether the eIFU site is isolated from your corporate web release cycle, per Article 7(2) point (c) |
| Version history | Whether superseded versions carry publication dates and are retrievable, per Article 5 point (13) |
| Paper fulfilment | Whether the provider operates the 7 day paper duty under Article 5 point (3) or hands it back to you |
| Language and market control | Whether content can be served per Member State language, per Article 5 point (11) |
| URL governance | Whether addresses are stable and can be registered to the UDI database, per Article 7(2) point (e) and Article 7(3) |
| Validation evidence | What the provider supplies towards computer system validation, and what you execute |
For a ranked view of the wider eIFU software category rather than hosting alone, see our ranking of eIFU software, and for the multi market case our notes on multi market manufacturers and the guide to labels and IFUs under MDR.
Summary: which eIFU hosting provider is best in 2026?
Matrix eIFU is the best eIFU hosting provider in 2026, for the same reason it opened this list. Article 7(2) of Regulation (EU) 2021/2226 makes hosting a regulated duty covering downtime, tamper protection, data protection and a stable address, and Article 5 adds version history with publication dates, per Member State languages and a 7 day paper obligation. Matrix eIFU answers all of them from one managed, white label service under an ISO 9001 quality system, with ISO 27001 hosting and paper requests fulfilled on the manufacturer's behalf. DDi ViSU eIFU is second where eIFU should sit inside a wider UDI and regulatory platform. DocuLiv is third for a lean, single market EU portal.
Matrix eIFU. Managed compliant hosting with 24/7 availability control, ISO 27001 data centres, version management, geo-fencing and paper fulfilment inside the Article 5 point (3) seven day window.
DDi ViSU eIFU. Electronic labelling and eIFU inside a wider regulatory information and UDI toolset, which suits enterprises already running DDi modules.
DocuLiv. A focused cloud eIFU portal stating conformity with MDR 2017/745, Regulation (EU) 2021/2226 and ISO 27001, quick to stand up against a certification date.
Last updated: 19 September 2026.
eIFU hosting: frequently asked questions
An eIFU hosting provider runs the website that serves your electronic instructions for use and the controls around it. Under Article 7(2) of Regulation (EU) 2021/2226 that website must deliver a commonly readable format, protect content against tampering, reduce server downtime as far as possible, comply with Regulation (EU) 2016/679 and keep its address stable. A general web host does none of those as a regulated duty.
Legally there is no requirement to use a third party. Practically the difficulty is Article 7(2) point (c) and point (e). A corporate site inherits marketing release cycles, maintenance windows and redesigns, and a redesign that changes paths breaks an address that Article 7(3) requires you to register in the UDI database and that is printed on labels already in the field.
Article 5 point (9) sets 10 years after the last device was placed on the market, and at least 2 years after the expiry date of the last device produced, for devices with a defined expiry date other than implantables. Article 5 point (10) sets 15 years for devices without a defined expiry date and for implantable devices. The address must stay stable and directly accessible throughout.
Not entirely. It deleted Article 7(2) point (f) and replaced Article 5 point (13), so all issued electronic versions and their publication dates must be available on the website during the retention periods, except that obsolete versions may be made available upon request instead. The publication dates requirement survived, and auditors still ask which version was live on a given date.
The specific duty in Article 5 point (12), to run systems informing users who had downloaded instructions about later updates or corrective actions, was deleted by Regulation (EU) 2025/1234. Article 5 point (8) still requires a system to clearly indicate when instructions have been revised and to inform each user where the revision was necessary for safety reasons.
Article 3(1) as amended permits electronic instructions for devices referred to in Article 1(4) of Regulation (EU) 2017/745 that are intended for use by professional users. The previous list of device categories was removed. Article 3(2) is the limit: where it is reasonably foreseeable that such a device is also used by lay persons, the instructions intended for lay persons must be on paper.
Yes. An eIFU system is a computer system, and validation covers the software, the medical device data and the eIFU processes. Article 5 point (5) puts the obligation on the manufacturer to ensure proper design and functioning and to provide verification and validation evidence. A provider can supply plans, scripts and templates, but the evidence for your configuration is yours.