Medical Device Software — Software Life Cycle Processes
The international standard defining life-cycle requirements for medical device software — development, maintenance, risk management, configuration management, and problem resolution. It classifies software into safety classes A, B, and C by the severity of harm a failure could cause and scales the required rigour accordingly.
What this does not cover
stated in the document's own scope- Covers the software life-cycle process; it does not provide the quality management system (ISO 13485) or the overall device risk-management process (ISO 14971), which it presumes are in place.
- Addresses software safety by potential severity of harm, not the clinical evaluation or validation of the device’s intended medical benefit.
- Covers device software life cycle, not the safety of the medical electrical equipment the software may run on, which is IEC 60601-1.
- Applies to the software of medical devices; general-purpose or non-medical software falls outside its scope.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
IEC 62304:2006, amended by Amendment 1 (2015), defines the life-cycle processes for medical device software — whether the software is itself a medical device or is an embedded or integral part of one. It sets requirements for software development, software maintenance, software risk management, configuration management, and problem resolution, all framed within a quality management system and a risk-management process. Its organising idea is the software safety classification: each software item is assigned Class A, B, or C according to the severity of the harm a failure could contribute to (from no injury, through non-serious injury, to death or serious injury), and the required activities scale with that class.
Scope & applicability
Software that is part of a medical device or is itself a medical device (SaMD), across its development and maintenance life cycle.
Legal basis & how it acquires force
IEC 62304 is a voluntary international consensus standard; it does not create legal duties by itself. It gains force through recognition and reference: it is an FDA-recognised consensus standard used to support device software in submissions, and it is adopted as EN 62304 in Europe, giving a presumption of conformity to the relevant software requirements of the Medical Device Regulation (EU) 2017/745. It presumes an ISO 13485 quality management system and an ISO 14971 risk-management process around it, so it is applied alongside those standards rather than in isolation.
Document structure
| Part | Covers |
|---|---|
| Clauses 4–5 — General and development | General requirements (QMS, risk management, safety classification) and the software development process from planning to release |
| Clause 6 — Maintenance | The software maintenance process, including handling of feedback and modifications after release |
| Clause 7 — Risk management | Software risk-management activities, including analysis of contributing software items and risk-control measures |
| Clause 8 — Configuration management | Configuration identification, change control, and configuration status accounting |
| Clause 9 — Problem resolution | Investigating, resolving, and tracking problem reports and communicating relevant information |
| Safety classification (A/B/C) | Assigning each software item a safety class by potential severity of harm, scaling required rigour accordingly |
Key requirements
- Assign and justify a software safety class (A, B, or C)
- Plan and document the software development life cycle
- Integrate software risk management with ISO 14971
- Operate configuration management and problem-resolution processes
Implementation tips
- Set the safety class early — it governs the entire required process depth
- Bridge your CSV/GAMP practices into 62304 rather than building a parallel system
- Keep the risk-management file (ISO 14971) linked to software items and anomalies
Revision notes
The 2006 standard plus Amendment 1 (2015) clarified legacy software and safety classification; widely referenced by FDA and harmonized under the EU MDR.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
IEC 62304 is designed to sit within ISO 13485 (the quality management system) and to draw its risk framework from ISO 14971 (medical-device risk management). It is recognised by FDA and adopted as EN 62304 under the EU MDR, and it interfaces with IEC 82304-1 (health software product safety) and, for software within powered devices, with the programmable-systems (PEMS) requirements of IEC 60601-1.
IEC 62304:2006+A1:2015: frequently asked questions
Quick answers to common questions about IEC 62304:2006+A1:2015.
What are the software safety classes in IEC 62304?
Class A — no injury or damage to health is possible; Class B — non-serious injury is possible; Class C — death or serious injury is possible. The class reflects the severity of harm a software failure could contribute to, and the required activities scale up from A to C.
Does IEC 62304 stand alone?
No. It presumes an ISO 13485 quality management system and an ISO 14971 risk-management process around it. IEC 62304 supplies the software life-cycle processes within that framework.
Is IEC 62304 recognised by regulators?
Yes, as a voluntary standard given force by reference. It is an FDA-recognised consensus standard for device software and is adopted as EN 62304 supporting the software requirements of the EU MDR.
What does the 2015 amendment (A1) change?
Amendment 1 (2015) refined the safety-classification approach, clarified that all software is treated as at least Class A until classified, and adjusted requirements for legacy software and the relationship to the risk-management process.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.