# IEC 62304 Compliance

## Edition 2 Rewrites the Rules for Medical Device Software. Are Your Supplier Documentation and SOUP Records Ready?

IEC 62304 compliance demands full lifecycle traceability from development planning through post-market maintenance—with safety classification driving documentation rigor at every stage. Edition 2, targeted for August 2026, replaces three safety classes with two process rigor levels and expands scope to all health software including AI/ML. SOUP assessments require documented evidence from every software supplier in your chain.

Certivo automates supplier evidence collection and AI document parsing from SOUP declaration to audit-ready traceability package.

### Safety levels and core lifecycle clauses

- **Safety classes consolidating to rigor levels (Edition 2)**
- **33% Medical device recalls linked to software failures**
- **5 Core lifecycle clauses requiring full documentation**

## Regulation Overview

- **Jurisdiction:** Global (IEC standard; harmonized under EU MDR/IVDR; FDA-recognized consensus standard)
- **Regulatory Body:** International Electrotechnical Commission (IEC), Sub-Committee SC 62A
- **Regulation Number:** IEC 62304:2006+AMD1:2015 (Edition 2 targeted August 2026)
- **Effective Date:** May 2006 (Amendment 1: June 2015; Edition 2: August 2026 projected)
- **Official Source:** [ISO Standard](https://www.iso.org/standard/38421.html)
- **Key Threshold:** Safety classification (A/B/C) determines documentation rigor for all lifecycle processes

# What is IEC 62304?

IEC 62304 is the international standard defining software lifecycle processes for medical device software and the foundation of global medical device software compliance. The primary obligation is ensuring that every software component—including Software of Unknown Provenance (SOUP) such as third-party libraries, open-source modules, and commercial off-the-shelf components—is documented, risk-assessed, and traceable across the entire development and maintenance lifecycle.

## Key Components / Sub-Frameworks

### Obligation
- **Full development lifecycle documentation scaled to safety class**

### Clause 5 — Software Development
- Eight activity areas from planning through release

### Obligation
- **Maintenance plan, re-verification, and re-release procedures**

### Clause 6 — Software Maintenance
- Post-release problem resolution and change management

### Obligation
- **Documented risk analysis, control measures, and residual risk assessment**

### Clause 7 — Software Risk Management
- Integration with ISO 14971 for software-specific hazards

### Obligation
- **Complete audit trail for every software build and configuration**

### Clause 8 — Configuration Management
- Version control, change control, and release management

### Obligation
- **CAPA-aligned process for all software defects and field issues**

### Clause 9 — Problem Resolution
- Tracking anomalies from discovery through verified fix

### Obligation
- **Identification, requirements, risk assessment, and post-market monitoring**

### SOUP Management
- Software of Unknown Provenance documentation

## Key Compliance Requirements

### Who Must Comply
- Medical device manufacturers developing software (embedded or standalone)  
- SaMD developers placing software on regulated markets  
- Suppliers of software components integrated into medical devices  
- Contract software development organizations (CSDOs) working on behalf of device manufacturers  
- Companies assembling multi-component medical systems with third-party software  
- AI/ML developers building diagnostic or therapeutic algorithms for clinical use

### Key Thresholds
#### Safety Class A
- No injury or damage to health possible from software failure

#### Safety Class B
- Non-serious injury possible from software failure

#### Safety Class C
- Death or serious injury possible from software failure

#### Rigor Levels I & II (Ed. 2)
- Edition 2 replaces A/B/C: Level I (lightweight, replaces Class A); Level II (full process rigor, replaces Classes B and C)

## Core Obligations
1. **Development Planning (Cl. 5.1)**
   - Documented software development plan covering lifecycle model, safety classification, and risk management integration  
   - **Deadline:** All classes

2. **Requirements & Architecture (Cl. 5.2–5.3)**
   - Traceable requirements analysis, architectural design, and SOUP identification  
   - **Deadline:** Class A: partial; B/C: full

3. **Verification & Validation (Cl. 5.5–5.7)**
   - Unit testing, integration testing, and system testing with documented results  
   - **Deadline:** Class A: system test only; B: integration+system; C: all levels

4. **SOUP Assessment**
   - Documented requirements, risk assessment, CVE review, and version tracking for all third-party components  
   - **Deadline:** All classes (depth varies by class)

5. **Post-Market Maintenance (Cl. 6)**
   - Maintenance plan, problem tracking, and re-verification for all software changes after release  
   - **Deadline:** All classes

## IEC 62304 Specific Pain Points

### The SOUP Documentation Spiral
Every modern medical device uses multiple third-party software components. IEC 62304 requires documented requirements, risk assessments, and anomaly reviews for each. A critical library update may cascade into your risk file.

### The Safety Classification Reclassification
A Notified Body questions your Class A classification during audit. Reclassification means rebuilding documentation against higher-rigor requirements.

### The Traceability Dead End
FDA reviewers request requirement-to-test traceability for a 510(k) submission. **Manual reconstruction takes weeks and still produces gaps.**

### The Multi-Supplier Evidence Burden
Your device integrates software from multiple suppliers. consolidating multi-tier supply chain transparency becomes a full-time project.

## Certivo in Action

### Certivo's Workflow

- **Get Evidence In:** Collect SOUP Declarations and Lifecycle Evidence from Every Software Supplier—Without the Chasing

- **Make Sense of It:** Know Instantly When SOUP Components Carry Unassessed Risk

- **Prove Compliance Out:** Generate Audit-Ready Technical Files in Hours, Not Months

## Related Regulations

- **EU MDR 2017/745**  
- **FDA 21 CFR Part 820**  
- **ISO 14971**  
- **ISO 13485**  
- **IEC 81001-5-1**  
- **IEC 82304-1**

## Key Statistics
- **5** Core lifecycle clauses tracked with continuous compliance monitoring  
- **99.2%** Software component extraction accuracy from supplier declarations  
- **95%** Supplier response rate with CORA-powered automated campaigns

## Frequently Asked Questions
### What products and companies are subject to IEC 62304 obligations?
Any company developing software that is a medical device (SaMD) or part of a medical device must comply.

### How does Certivo track changes to IEC 62304 and related regulatory requirements?
Certivo maintains continuous regulatory intelligence and horizon scanning aligned with IEC publications.

### What documentation formats does Certivo accept from software suppliers?
Certivo accepts various formats, eliminating the need to standardize supplier inputs.

### Does Certivo support both IEC 62304 and related medical device standards simultaneously?
Yes, Certivo validates supplier evidence against multiple frameworks simultaneously.
