IEC 62304
Lifecycle requirements for medical device software.
Definition
IEC 62304:2006 (with Amendment 1:2015) defines the lifecycle requirements for medical device software, including software development planning, requirements analysis, architectural design, implementation, integration, testing, release, and maintenance - scaled by software safety classification (Class A, B, C).What this means in practice
IEC 62304 is a recognized consensus standard by FDA and a harmonized standard under EU MDR. It is foundational for SaMD and software-containing devices. The standard scales its expectations by software safety class: Class A (no injury possible) requires the lightest process, Class B (non-serious injury) adds detailed design and integration testing, and Class C (death or serious injury) adds unit testing, more rigorous architecture, and stronger SOUP controls.Examples
- A Class C infusion pump control application with unit tests, formal architectural design records, and full SOUP evaluation for the RTOS and TLS stack.
- A Class B mobile SaMD dose calculator with documented software requirements, integration tests, and a maintained anomaly list.
Use cases
1 scenarioLegacy infusion pump firmware refresh
Software leadA team refactoring 10-year-old C firmware classifies the safety class as C, retrofits a software development plan, traces requirements to unit tests, and documents SOUP for the RTOS and TCP/IP stack.
- •Under-classifying software to avoid Class C obligations. Auditors and reviewers actively challenge classifications that do not align with the device's hazard analysis.
- •Skipping SOUP (Software of Unknown Provenance) requirements for open-source libraries and third-party components.
- •Treating IEC 62304 as an alternative to ISO 14971. It complements risk management; it does not replace it.
- •Losing traceability between software requirements, architecture items, unit tests, and integration tests.
Frequently asked questions
Cross-references
Governs
Things this term applies rules or requirements to.
Uses
Concepts or artefacts this term builds on.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsIEC 62304 classes A, B, C reflecting potential harm from software failure.
Software intended for medical purposes that performs without being part of a hardware device.
Software not developed for medical device use, or lacking adequate development records, incorporated into a device.
International standard for the application of risk management to medical devices.
SaMD & AI/ML Devices
· From this learning pathSoftware embedded in or required to operate a hardware medical device.
Software providing healthcare professionals with knowledge and patient-specific information.
FDA mechanism to pre-authorize specific modifications to AI/ML-enabled devices.
Guiding principles for the development of AI/ML-enabled medical devices.
Standards Stack for Medical Devices
· From this learning pathInternational standard defining secure-product-lifecycle activities for health software, including medical devices.
EMC requirements for medical electrical equipment.
Application of usability engineering to medical devices.
General requirements for basic safety and essential performance of medical electrical equipment.
Software Team Onboarding
· From this learning pathThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
Primary references
3 sources- 1
IEC 62304:2006/AMD1:2015VerifiedISOiso.org
- 2
FDA Recognized Consensus StandardsUncheckedFDAaccessdata.fda.gov
- 3
IEC Webstore - Medical EquipmentVerifiedIECwebstore.iec.ch
Inline markers like [1] jump to the matching reference above.