Devices & Software

SOUP / OTS Software

Software of Unknown Provenance / Off-The-Shelf Software

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

SOUP (software of unknown provenance) — closely related to off-the-shelf (OTS) software — is software already developed and generally available, or previously developed with records not accessible, that is incorporated into a medical device but was not developed under the device’s own controlled lifecycle. Because its internal development quality is not fully known, it must be risk-assessed and controlled as an integrated component.

IEC 62304 requires SOUP to be identified, its functional and performance requirements specified, its hardware/software environment defined, and its known anomalies evaluated against the device’s risk analysis — especially anomalies that could contribute to a hazardous situation.

Open-source libraries, operating systems, and commercial components are common SOUP/OTS; they are also the main entry point for cybersecurity vulnerabilities, which is why the software bill of materials and vulnerability monitoring focus heavily on these components.

KEY POINTS
  • Pre-existing software not built under the device lifecycle.
  • Must be identified, spec’d, and its known anomalies risk-assessed.
  • A primary source of cybersecurity vulnerabilities.
  • Tracked in the software bill of materials.
REGULATORY BASIS

IEC 62304:2006/AMD1:2015 SOUP requirements; FDA guidance on off-the-shelf software use in medical devices.

Frequently asked questions

What does SOUP / OTS Software stand for?

SOUP / OTS Software stands for Software of Unknown Provenance / Off-The-Shelf Software.

What is SOUP / OTS Software?

SOUP (software of unknown provenance) — closely related to off-the-shelf (OTS) software — is software already developed and generally available, or previously developed with records not accessible, that is incorporated into a medical device but was not developed under the device’s own controlled lifecycle. Because its internal development quality is not fully known, it must be risk-assessed and controlled as an integrated component.

Which regulations cover SOUP / OTS Software?

IEC 62304:2006/AMD1:2015 SOUP requirements; FDA guidance on off-the-shelf software use in medical devices.