MedTech Terms
    The authoritative reference
    All terms
    Software & AISoftware LifecycleSOUP

    Software of Unknown Provenance

    Software not developed for the purpose of being incorporated into a medical device.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Per IEC 62304, SOUP is software that is already developed and generally available and that has not been developed for the purpose of being incorporated into the medical device - or software previously developed for which adequate records of development processes are not available.

    What this means in practice

    SOUP components must be documented, risk-assessed, and tracked. SBOM and vulnerability monitoring obligations make SOUP management essential.

    Cross-references

    Used by

    Things that build on this term.

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-05-09
    ISO·1MDCG·1FDA·1
    1. 1
      IEC 62304
      Verified
      ISOiso.org
    2. 2
      MDCG Software Guidance
      Verified
      MDCGhealth.ec.europa.eu
    3. 3
      FDA - Software as a Medical Device (SaMD)
      Verified
      FDAfda.gov

    Inline markers like [1] jump to the matching reference above.