Definition
The standard defining the software development lifecycle for medical device software: safety classification A to C, planning, requirements, architecture, verification, configuration management, problem resolution, and maintenance after release.
Related terms
SaMD
Software intended for a medical purpose that performs that purpose on its own, without being part of a hardware device. Under MDR and IVDR it is qualified and classified in its own right, with clinical evidence, usability, and cybersecurity requirements.
ISO 14971
The standard for applying risk management to medical devices across the lifecycle: risk analysis, evaluation, control, evaluation of overall residual risk, and production and post-production information feeding back into the risk file.
EU AI Act
The European regulation on artificial intelligence, applying a risk-based framework. AI-enabled medical devices and IVDs generally fall in the high-risk category, adding requirements on data governance, transparency, human oversight, robustness, and post-market monitoring on top of MDR or IVDR.
Cybersecurity
For regulated devices, the set of design and process controls protecting confidentiality, integrity, and availability, as described in MDCG 2019-16. It spans secure design, threat modelling, vulnerability handling, and security updates over the supported lifetime.
Need more than a definition?
Our regulatory, quality, and clinical specialists turn these requirements into working submissions, systems, and studies.