Service decision and evidence guide

EUDAMED module security keys: generation, storage and rotation dependencies

The acquired help makes security keys module-specific and combines them with sender SRN. Keys cannot be viewed after closing the generation window; regeneration requires new XML files to use the new module key. Plan key custody and producer cutover without placing credentials in a public brief.

Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.

Sourced criteria · EU · EUDAMED

What changes the service scope?

Decision or taskWhat the source describesWhat to prepare
generate-your-security-key / HTML p [5]The security key is specific for each EUDAMED module, and the combination of this key and the SRN of the sender is used as security to ensure that the message is received from the correct actor. Without this key, your message will not pass our security checks. An incorrect key will give the following error response: [1]Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
generate-your-security-key / HTML p [17]The security keys are generated per module. [2]Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
generate-your-security-key / HTML p [21]Please copy the security key. You will not be able to view your security key after closing the pop-up window. If you lose your security key, you must regenerate it ( see Regenerate your security key page for further details). [3]Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
regenerate-your-security-key / HTML p [17]Please copy the regenerated security key. You will not be able to view your security key after closing the pop-up window. If you lose your security key, you must regenerate it. [4]Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
regenerate-your-security-key / HTML p [19]When a security key is regenerated, all new XML files must include the new security key for that module, otherwise they will be rejected. [5]Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.

Dated technical/help evidence, not a complete legal duty set or live EUDAMED response. Current target-environment release, business rules, permissions and actual buyer records remain unresolved. Blank dictionary flags are unknown; occurrence and update notes keep their stated conditions. No credentials, registration deadline or completed production exchange is inferred.

Prepare the EUDAMED module security keys work package

Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.

  1. Inventory module and actor identities

    Record the sender actor/SRN and producing systems for each module; keep the actual tokens in approved private secret storage.

    Useful evidence: A module/actor/system inventory with secret references, never token values.

  2. Plan secure capture and custody

    Assign the person/system responsible for securely retaining the generated key and recovering from loss.

    Useful evidence: A private key-management procedure and access responsibilities.

  3. Coordinate regeneration

    Update each XML producer for the rotated module and test a new exchange; separate old queued messages from newly generated files.

    Useful evidence: A rotation/cutover plan, producing-system acknowledgements and post-change test evidence.

Work packages and dependencies

Questions for providers

Sources and data dates

Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.

European Commission / Swissmedic — published reference ↗

Thu, 27 Aug 2026 11:33:34 GMT · retrieved 2026-10-07

Audit details: precise locators and snapshot identifiers

Source key D07 · snapshot ed6fb2f7257206914496da38f49380248e0219a05d87e87de357dcafbfd740f3

  • [1] HTML p [5] · record e354abcd0b8b5fac6ec4f3fe0179c550ea075542911c3a47c69f1b801fc4d476
  • [2] HTML p [17] · record dd1f29c27868569d160daf138ef5cb776fedfe39ed4c39c12fbb3c10d1375d68
  • [3] HTML p [21] · record 8eb8fd06656b1d2a09579a0102fdd1d1097ae03ef752b1b7867703391512352b

European Commission / Swissmedic — published reference ↗

Thu, 27 Aug 2026 11:33:34 GMT · retrieved 2026-10-07

Audit details: precise locators and snapshot identifiers

Source key D07 · snapshot 7aa9cf9f69e6897c7096b9258b47b538a524155293da3735c2bf154c6cbf0eae

  • [4] HTML p [17] · record cdac7c62c6839067231c3d7bd8b67d8ea9130ce3f0d7fee376cc013b638906f8
  • [5] HTML p [19] · record a63d861b88d7eae675c43bf0002e3d9b472b673937e2a3371aa816deaab71b7c

Prepare an editable project brief

Confirm the facts, scope and contact preference before sharing your project. Preparing this page sends no provider outreach.

Choose work packages to discuss

Compare EUDAMED M2M Integration