SaMD Risk Categorization
Software as a Medical Device Risk Categorization
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
The IMDRF framework categorizes Software as a Medical Device by combining the significance of the information it provides to a healthcare decision (inform, drive, or treat/diagnose) with the state of the healthcare situation (non-serious, serious, or critical). The resulting category (I to IV) sets the level of regulatory scrutiny the software warrants.
The two axes create a matrix: software that treats or diagnoses in a critical situation sits at the highest category and demands the most rigorous evidence, while software that merely informs a non-serious decision sits at the lowest. The category is about the consequence of the software’s output being wrong, not the technology used.
This risk framing feeds into design controls, clinical evaluation, and the depth of software verification and validation. It is intended to be a common language across jurisdictions even though each regulator maps it into its own classification and premarket pathway.
- —Two axes: significance of information × state of healthcare situation.
- —Yields categories I–IV in the IMDRF SaMD framework.
- —Category reflects consequence of a wrong output, not the technology.
- —Drives evidence, design controls, and V&V depth.
IMDRF SaMD risk categorization framework (IMDRF/SaMD WG/N12, 2014); IMDRF SaMD key definitions (N10).
Frequently asked questions
What does SaMD Risk Categorization stand for?
SaMD Risk Categorization stands for Software as a Medical Device Risk Categorization.
What is SaMD Risk Categorization?
The IMDRF framework categorizes Software as a Medical Device by combining the significance of the information it provides to a healthcare decision (inform, drive, or treat/diagnose) with the state of the healthcare situation (non-serious, serious, or critical). The resulting category (I to IV) sets the level of regulatory scrutiny the software warrants.
Which regulations cover SaMD Risk Categorization?
IMDRF SaMD risk categorization framework (IMDRF/SaMD WG/N12, 2014); IMDRF SaMD key definitions (N10).