IECRegulatory IntelligenceStandard
IEC 62304:2006+A1:2015

Medical Device Software — Software Life Cycle Processes

The international standard defining life-cycle requirements for medical device software — development, maintenance, risk management, configuration management, and problem resolution. It classifies software into safety classes A, B, and C by the severity of harm a failure could cause and scales the required rigour accordingly.

LAST REVISED
June 2015
PRODUCT AREAS
Devices

What this does not cover

stated in the document's own scope
  • Covers the software life-cycle process; it does not provide the quality management system (ISO 13485) or the overall device risk-management process (ISO 14971), which it presumes are in place.
  • Addresses software safety by potential severity of harm, not the clinical evaluation or validation of the device’s intended medical benefit.
  • Covers device software life cycle, not the safety of the medical electrical equipment the software may run on, which is IEC 60601-1.
  • Applies to the software of medical devices; general-purpose or non-medical software falls outside its scope.
SOURCE & PROVENANCE
ISSUING BODY
International Electrotechnical Commission
JURISDICTION
International
DOCUMENT ID
IEC 62304:2006+A1:2015
Official site — International Electrotechnical Commission

Always verify against the current published text before relying on it for a submission or inspection.

Overview

IEC 62304:2006, amended by Amendment 1 (2015), defines the life-cycle processes for medical device software — whether the software is itself a medical device or is an embedded or integral part of one. It sets requirements for software development, software maintenance, software risk management, configuration management, and problem resolution, all framed within a quality management system and a risk-management process. Its organising idea is the software safety classification: each software item is assigned Class A, B, or C according to the severity of the harm a failure could contribute to (from no injury, through non-serious injury, to death or serious injury), and the required activities scale with that class.

Scope & applicability

Software that is part of a medical device or is itself a medical device (SaMD), across its development and maintenance life cycle.

Legal basis & how it acquires force

IEC 62304 is a voluntary international consensus standard; it does not create legal duties by itself. It gains force through recognition and reference: it is an FDA-recognised consensus standard used to support device software in submissions, and it is adopted as EN 62304 in Europe, giving a presumption of conformity to the relevant software requirements of the Medical Device Regulation (EU) 2017/745. It presumes an ISO 13485 quality management system and an ISO 14971 risk-management process around it, so it is applied alongside those standards rather than in isolation.

Document structure

PartCovers
Clauses 4–5 — General and developmentGeneral requirements (QMS, risk management, safety classification) and the software development process from planning to release
Clause 6 — MaintenanceThe software maintenance process, including handling of feedback and modifications after release
Clause 7 — Risk managementSoftware risk-management activities, including analysis of contributing software items and risk-control measures
Clause 8 — Configuration managementConfiguration identification, change control, and configuration status accounting
Clause 9 — Problem resolutionInvestigating, resolving, and tracking problem reports and communicating relevant information
Safety classification (A/B/C)Assigning each software item a safety class by potential severity of harm, scaling required rigour accordingly

Key requirements

  • Assign and justify a software safety class (A, B, or C)
  • Plan and document the software development life cycle
  • Integrate software risk management with ISO 14971
  • Operate configuration management and problem-resolution processes

Implementation tips

  • Set the safety class early — it governs the entire required process depth
  • Bridge your CSV/GAMP practices into 62304 rather than building a parallel system
  • Keep the risk-management file (ISO 14971) linked to software items and anomalies

Revision notes

The 2006 standard plus Amendment 1 (2015) clarified legacy software and safety classification; widely referenced by FDA and harmonized under the EU MDR.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

IEC 62304:2006+A1:2015: frequently asked questions

Quick answers to common questions about IEC 62304:2006+A1:2015.

What are the software safety classes in IEC 62304?

Class A — no injury or damage to health is possible; Class B — non-serious injury is possible; Class C — death or serious injury is possible. The class reflects the severity of harm a software failure could contribute to, and the required activities scale up from A to C.

Does IEC 62304 stand alone?

No. It presumes an ISO 13485 quality management system and an ISO 14971 risk-management process around it. IEC 62304 supplies the software life-cycle processes within that framework.

Is IEC 62304 recognised by regulators?

Yes, as a voluntary standard given force by reference. It is an FDA-recognised consensus standard for device software and is adopted as EN 62304 supporting the software requirements of the EU MDR.

What does the 2015 amendment (A1) change?

Amendment 1 (2015) refined the safety-classification approach, clarified that all software is treated as at least Class A until classified, and adjusted requirements for legacy software and the relationship to the risk-management process.