IECRegulatory IntelligenceStandard
IEC 62304:2006+A1:2015

Medical Device Software — Software Life Cycle Processes

The international standard defining life-cycle requirements for medical device software — development, maintenance, risk management, configuration management, and problem resolution. It classifies software into safety classes A, B, and C by the severity of harm a failure could cause and scales the required rigour accordingly.

LAST REVISED
June 2015
PRODUCT AREAS
Devices
SCOPE & APPLICABILITY

Software that is part of a medical device or is itself a medical device (SaMD), across its development and maintenance life cycle.

KEY REQUIREMENTS
  • 01Assign and justify a software safety class (A, B, or C)
  • 02Plan and document the software development life cycle
  • 03Integrate software risk management with ISO 14971
  • 04Operate configuration management and problem-resolution processes
IMPLEMENTATION TIPS
Set the safety class early — it governs the entire required process depth
Bridge your CSV/GAMP practices into 62304 rather than building a parallel system
Keep the risk-management file (ISO 14971) linked to software items and anomalies
REVISION NOTES

The 2006 standard plus Amendment 1 (2015) clarified legacy software and safety classification; widely referenced by FDA and harmonized under the EU MDR.

IEC 62304:2006+A1:2015: frequently asked questions

Quick answers to common questions about IEC 62304:2006+A1:2015.

What is IEC 62304:2006+A1:2015?

IEC 62304:2006+A1:2015 — Medical Device Software — Software Life Cycle Processes — is a standard issued by the International Electrotechnical Commission. The international standard defining life-cycle requirements for medical device software — development, maintenance, risk management, configuration management, and problem resolution. It classifies software into safety classes A, B, and C by the severity of harm a failure could cause and scales the required rigour accordingly.

Who does IEC 62304:2006+A1:2015 apply to?

Software that is part of a medical device or is itself a medical device (SaMD), across its development and maintenance life cycle.

What are the key requirements of IEC 62304:2006+A1:2015?

IEC 62304:2006+A1:2015 requires, among other things: Assign and justify a software safety class (A, B, or C); Plan and document the software development life cycle; Integrate software risk management with ISO 14971; Operate configuration management and problem-resolution processes.

When was IEC 62304:2006+A1:2015 last updated?

The current version of IEC 62304:2006+A1:2015 dates from June 2015. The 2006 standard plus Amendment 1 (2015) clarified legacy software and safety classification; widely referenced by FDA and harmonized under the EU MDR.

RELATED STANDARDS
RELATED FDA RECALLS
where Validation & Qualification control fails
See all Validation & Qualification recalls →

Live openFDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

THIS STANDARD IN PRACTICE

Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.

Weekly Briefing

Track the standards that move

When IEC 62304:2006+A1:2015 — or any GxP requirement — is revised, recalled against, or clarified by new guidance, the Weekly GxP Briefing surfaces it. Free, one email a week.

Read a past issue →