All terms
Software & AISoftware Lifecycle
Software Maintenance Plan
IEC 62304 §6 documented plan for handling problem reports, changes, and releases over the software lifecycle.
Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026
Definition
The Software Maintenance Plan covers problem and modification analysis, modification implementation, system release, and migration/retirement. It bridges the gap between design controls and post-market software changes. What the regulation says
Regulatory bodies such as the FDA (e.g., in their guidance for Content of Premarket Submissions for Device Software) and the EU MDR (Annex I, General Safety and Performance Requirements, Section 17.2) expect a well-defined software maintenance plan as part of a medical device’s lifecycle documentation. Regulators view this plan as crucial for ensuring the continued safety, effectiveness, and cybersecurity of software throughout its deployed lifetime, particularly for managing post-market changes.
What this means in practice
A robust maintenance plan is what makes Letter-to-File decisions defensible and prevents post-market changes from becoming new submissions.Examples
- A manufacturer maintains a detailed plan for distributing security patches to an implanted cardiac device’s programmer software, including validation testing and user notification procedures.
- A diagnostic software company outlines its process for analyzing field reported software bugs, determining the impact, and implementing corrective code changes under its established maintenance plan.
- A medical imaging device’s software maintenance plan specifies the criteria and process for upgrading operating system versions on the device’s embedded computer, ensuring compatibility and data integrity.
Common pitfalls
- •A common pitfall is treating the Software Maintenance Plan as a static document rather than a living one that evolves with the software and regulatory landscape.
- •Failing to adequately define criteria for determining when a software change necessitates a new regulatory submission instead of a Letter to File is a frequent mistake.
- •Underestimating the resources, both human and technical, required to execute the maintenance plan effectively can lead to non-compliance and product issues.
- •Another pitfall is not integrating cybersecurity maintenance activities, such as vulnerability management and patch deployment, directly into the Software Maintenance Plan.
- •Neglecting to establish clear processes for documenting and verifying all software changes made under the maintenance plan can lead to audit findings.
Frequently asked questions
The primary purpose is to outline the systematic activities for managing, updating, and sustaining medical device software throughout its post-market lifecycle, ensuring its continued safety, effectiveness, and compliance with regulatory requirements.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMore in Software & AI
· Same categorySoftware & AI
AAMI TIR45(TIR45)
AAMI Technical Information Report providing guidance on applying Agile software development practices within an IEC 62304-compliant medical device software lifecycle.
Software & AI
Adversarial Robustness
Resilience of an ML model to inputs deliberately crafted to cause misclassification.
Software & AI
AI/ML-Enabled Medical Device
Medical device that uses artificial intelligence or machine learning to perform its intended use.
Software & AI
Algorithm Change Protocol(ACP)
The detailed procedural section of a PCCP that specifies how planned modifications to an AI/ML model will be developed, validated, and implemented.
Primary references
3 sourcesLink health: 3 verified· last checked 2026-06-20
IEC·1FDA·1IMDRF·1
- 1
IEC 62304VerifiedIECwebstore.iec.ch
- 2
FDA - AI/ML-Enabled Medical DevicesVerifiedFDAfda.gov
- 3
IMDRF - Software as a Medical DeviceVerifiedIMDRFimdrf.org
Inline markers like [1] jump to the matching reference above.