Medical Devices & Diagnostics

Medical devices, IVDs, and device software — design controls, risk management, and post-market surveillance.

What this page does not claim

SPEQ decodes published standards and does not determine which apply to your product. An industry’s counts measure SPEQ’s coverage, not the size of its rulebook.

WHAT THIS INDUSTRY COVERS

Medical Devices & Diagnostics covers instruments, implants, in-vitro diagnostics, and the software that increasingly is the device (SaMD). Quality is built through design controls, risk management, and a lifecycle that runs from design and verification to post-market surveillance — a different centre of gravity from batch-based pharma.

REGULATORY LANDSCAPE

Governed by FDA (21 CFR 820, transitioning to the QMSR harmonised with ISO 13485; plus 21 CFR 803 device reporting), the EU MDR/IVDR, and the ISO/IEC standards — ISO 13485 (QMS), ISO 14971 (risk), IEC 62304 (software), and IEC 60601 (electrical safety). Notified bodies and unique device identification are central to market access.

WHY THIS PRODUCT IS HARD TO CONTROL

A device is used rather than consumed, and the user is part of the system. It is operated, sometimes for years, often by someone under pressure and occasionally by someone who has never read the instructions — so a design that is correct and confusing fails in the field exactly as a design that is wrong. That is why the regulation centres on design controls and human factors rather than on batch conformity, why risk management is a lifecycle activity under ISO 14971 rather than a pre-market document, and why post-market surveillance carries weight the pharmaceutical equivalent does not.

WHAT QUALITY MEANS HERE

01

Design controls & risk management

A traceable design history file and an ISO 14971 risk-management process that ties hazards to mitigations and verification — the core of device quality.

02

Device software (SaMD)

IEC 62304 software life cycles and computer-software-assurance thinking for software that is, or is in, the device — the fastest-growing device risk area.

03

The quality management system

An ISO 13485 QMS (and the FDA QMSR that harmonises with it) covering design, production, CAPA, and supplier control across the device lifecycle.

04

Post-market surveillance & vigilance

Complaint handling, medical device reporting (21 CFR 803, MDR/IVDR vigilance), and post-market clinical follow-up that close the loop after launch.

42
Standards decoded
8
GxP disciplines
566
FDA recalls · 12 mo →

STANDARDS SPEQ DECODES · 42

Open the full library →
21 CFR Part 820FDAHIGH INSPECTION RISK
Quality Management System Regulation (QMSR) — 21 CFR Part 820
ISO 9001:2015ISO
Quality Management Systems — Requirements
ISO 13485:2016ISO
Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes
ISO 14971:2019ISO
Medical Devices — Application of Risk Management to Medical Devices
Regulation (EU) 2017/745ECHIGH INSPECTION RISK
Medical Device Regulation (MDR)
21 CFR Part 803FDAHIGH INSPECTION RISK
Medical Device Reporting (MDR)
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IEC 60601-1IEC
Medical Electrical Equipment — General Requirements for Basic Safety and Essential Performance
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
ISO/IEC 17025:2017ISO
General requirements for the competence of testing and calibration laboratories
ILAC MRAILAC
ILAC Mutual Recognition Arrangement
GS1 General SpecificationsGS1
GS1 General Specifications — identification keys, data attributes and barcodes
21 CFR Part 4FDAHIGH INSPECTION RISK
Regulation of Combination Products (cGMP Requirements)
ISO 20916:2019ISO
In vitro diagnostic medical devices — Clinical performance studies using specimens from human subjects
ISO 17665:2024ISOHIGH INSPECTION RISK
Sterilization of Health Care Products — Moist Heat — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 11135:2014ISOHIGH INSPECTION RISK
Sterilization of Health-Care Products — Ethylene Oxide — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 10993-1:2018ISOHIGH INSPECTION RISK
Biological Evaluation of Medical Devices — Part 1: Evaluation and Testing Within a Risk Management Process
ISO 14155:2026ISOHIGH INSPECTION RISK
Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice
FDA CSA Guidance (2026)FDAHIGH INSPECTION RISK
Computer Software Assurance for Production and Quality Management System Software
IEC 81001-5-1:2021IEC
Health Software and Health IT Systems Safety, Effectiveness and Security — Part 5-1: Security — Activities in the Product Life Cycle
FDA GPSV (2002)FDAHIGH INSPECTION RISK
General Principles of Software Validation
FDA Premarket Cybersecurity (2026)FDAHIGH INSPECTION RISK
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA PCCP for AI-Enabled DSF (2024)FDA
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
IEC 82304-1:2016IEC
Health Software — Part 1: General Requirements for Product Safety
Regulation (EU) 2017/746ECHIGH INSPECTION RISK
In Vitro Diagnostic Medical Devices Regulation (IVDR)
21 CFR Part 830FDA
Unique Device Identification
21 CFR Part 806FDAHIGH INSPECTION RISK
Medical Devices; Reports of Corrections and Removals
IEC 62366-1:2015+A1:2020IEC
Medical Devices — Part 1: Application of Usability Engineering to Medical Devices
ISO 11607-1:2019ISO
Packaging for Terminally Sterilized Medical Devices — Part 1: Requirements for Materials, Sterile Barrier Systems and Packaging Systems
ISO 19011:2018ISO
Guidelines for Auditing Management Systems
ISO 11737-1:2018ISO
Sterilization of Health Care Products — Microbiological Methods — Part 1: Determination of a Population of Microorganisms on Products
ISO/IEC 27001:2022ISO
Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements
IEC 62443-2-1:2024IEC
Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners
IEC 62443-3-3:2013IEC
Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels
21 CFR Part 3FDA
Product Jurisdiction
21 CFR Part 807FDA
Establishment Registration and Device Listing for Manufacturers and Initial Importers of Devices
Regulation (EU) 2016/679EC
General Data Protection Regulation (GDPR)
ISO 22301:2019ISO
Security and Resilience — Business Continuity Management Systems — Requirements
ISO 31000:2018ISO
Risk Management — Guidelines
ISO 45001:2018ISO
Occupational Health and Safety Management Systems — Requirements with Guidance for Use
ISO 14001:2015ISO
Environmental Management Systems — Requirements with Guidance for Use

WHERE QUALITY FAILS

  • Design-control and risk-management gaps that surface as field failures
  • Software defects and cybersecurity vulnerabilities in connected devices
  • Late or missed adverse-event (MDR) reporting
  • Unapproved design changes or shipping without required clearance

KEY REGULATORY BODIES

Derived from the 42 standards SPEQ decodes for this industry.

Medical Devices & Diagnostics: frequently asked questions

Quick answers to common questions about GxP in Medical Devices & Diagnostics.

What quality management system applies to medical devices?

ISO 13485 is the international device QMS standard. In the US, FDA’s 21 CFR 820 is transitioning to the Quality Management System Regulation (QMSR), which harmonises with ISO 13485; the EU MDR and IVDR set the parallel European requirements.

What is Software as a Medical Device (SaMD)?

SaMD is software intended for a medical purpose that performs that purpose without being part of a hardware device. Its lifecycle is governed by IEC 62304, and FDA’s computer-software-assurance thinking increasingly applies to it — the fastest-growing device risk area.

What are design controls in medical devices?

Design controls are the traceable process — captured in a design history file — that links user needs and hazards to design inputs, outputs, verification, and validation. They are paired with an ISO 14971 risk-management process and sit at the core of device quality.