IEC 62304 Compliance Software | Medical Device Software Lifecycle Automation | Certivo - Certivo
IEC 62304 Compliance
Edition 2 Rewrites the Rules for Medical Device Software. Are Your Supplier Documentation and SOUP Records Ready?
IEC 62304 compliance demands full lifecycle traceability from development planning through post-market maintenance—with safety classification driving documentation rigor at every stage. Edition 2, targeted for August 2026, replaces three safety classes with two process rigor levels and expands scope to all health software including AI/ML. SOUP assessments require documented evidence from every software supplier in your chain.
Certivo automates supplier evidence collection and AI document parsing from SOUP declaration to audit-ready traceability package.
Safety levels and core lifecycle clauses
- Safety classes consolidating to rigor levels (Edition 2)
- 33% Medical device recalls linked to software failures
- 5 Core lifecycle clauses requiring full documentation
Regulation Overview
- Jurisdiction: Global (IEC standard; harmonized under EU MDR/IVDR; FDA-recognized consensus standard)
- Regulatory Body: International Electrotechnical Commission (IEC), Sub-Committee SC 62A
- Regulation Number: IEC 62304:2006+AMD1:2015 (Edition 2 targeted August 2026)
- Effective Date: May 2006 (Amendment 1: June 2015; Edition 2: August 2026 projected)
- Official Source: ISO Standard
- Key Threshold: Safety classification (A/B/C) determines documentation rigor for all lifecycle processes
What is IEC 62304?
IEC 62304 is the international standard defining software lifecycle processes for medical device software and the foundation of global medical device software compliance. The primary obligation is ensuring that every software component—including Software of Unknown Provenance (SOUP) such as third-party libraries, open-source modules, and commercial off-the-shelf components—is documented, risk-assessed, and traceable across the entire development and maintenance lifecycle.
Key Components / Sub-Frameworks
Obligation
- Full development lifecycle documentation scaled to safety class
Clause 5 — Software Development
- Eight activity areas from planning through release
Obligation
- Maintenance plan, re-verification, and re-release procedures
Clause 6 — Software Maintenance
- Post-release problem resolution and change management
Obligation
- Documented risk analysis, control measures, and residual risk assessment
Clause 7 — Software Risk Management
- Integration with ISO 14971 for software-specific hazards
Obligation
- Complete audit trail for every software build and configuration
Clause 8 — Configuration Management
- Version control, change control, and release management
Obligation
- CAPA-aligned process for all software defects and field issues
Clause 9 — Problem Resolution
- Tracking anomalies from discovery through verified fix
Obligation
- Identification, requirements, risk assessment, and post-market monitoring
SOUP Management
- Software of Unknown Provenance documentation
Key Compliance Requirements
Who Must Comply
- Medical device manufacturers developing software (embedded or standalone)
- SaMD developers placing software on regulated markets
- Suppliers of software components integrated into medical devices
- Contract software development organizations (CSDOs) working on behalf of device manufacturers
- Companies assembling multi-component medical systems with third-party software
- AI/ML developers building diagnostic or therapeutic algorithms for clinical use
Key Thresholds
Safety Class A
- No injury or damage to health possible from software failure
Safety Class B
- Non-serious injury possible from software failure
Safety Class C
- Death or serious injury possible from software failure
Rigor Levels I & II (Ed. 2)
- Edition 2 replaces A/B/C: Level I (lightweight, replaces Class A); Level II (full process rigor, replaces Classes B and C)
Core Obligations
Development Planning (Cl. 5.1)
- Documented software development plan covering lifecycle model, safety classification, and risk management integration
- Deadline: All classes
Requirements & Architecture (Cl. 5.2–5.3)
- Traceable requirements analysis, architectural design, and SOUP identification
- Deadline: Class A: partial; B/C: full
Verification & Validation (Cl. 5.5–5.7)
- Unit testing, integration testing, and system testing with documented results
- Deadline: Class A: system test only; B: integration+system; C: all levels
SOUP Assessment
- Documented requirements, risk assessment, CVE review, and version tracking for all third-party components
- Deadline: All classes (depth varies by class)
Post-Market Maintenance (Cl. 6)
- Maintenance plan, problem tracking, and re-verification for all software changes after release
- Deadline: All classes
IEC 62304 Specific Pain Points
The SOUP Documentation Spiral
Every modern medical device uses multiple third-party software components. IEC 62304 requires documented requirements, risk assessments, and anomaly reviews for each. A critical library update may cascade into your risk file.
The Safety Classification Reclassification
A Notified Body questions your Class A classification during audit. Reclassification means rebuilding documentation against higher-rigor requirements.
The Traceability Dead End
FDA reviewers request requirement-to-test traceability for a 510(k) submission. Manual reconstruction takes weeks and still produces gaps.
The Multi-Supplier Evidence Burden
Your device integrates software from multiple suppliers. consolidating multi-tier supply chain transparency becomes a full-time project.
Certivo in Action
Certivo's Workflow
Get Evidence In: Collect SOUP Declarations and Lifecycle Evidence from Every Software Supplier—Without the Chasing
Make Sense of It: Know Instantly When SOUP Components Carry Unassessed Risk
Prove Compliance Out: Generate Audit-Ready Technical Files in Hours, Not Months
Related Regulations
- EU MDR 2017/745
- FDA 21 CFR Part 820
- ISO 14971
- ISO 13485
- IEC 81001-5-1
- IEC 82304-1
Key Statistics
- 5 Core lifecycle clauses tracked with continuous compliance monitoring
- 99.2% Software component extraction accuracy from supplier declarations
- 95% Supplier response rate with CORA-powered automated campaigns
Frequently Asked Questions
What products and companies are subject to IEC 62304 obligations?
Any company developing software that is a medical device (SaMD) or part of a medical device must comply.
How does Certivo track changes to IEC 62304 and related regulatory requirements?
Certivo maintains continuous regulatory intelligence and horizon scanning aligned with IEC publications.
What documentation formats does Certivo accept from software suppliers?
Certivo accepts various formats, eliminating the need to standardize supplier inputs.
Does Certivo support both IEC 62304 and related medical device standards simultaneously?
Yes, Certivo validates supplier evidence against multiple frameworks simultaneously.