Skip to main content

IEC 62304

IEC 62304 defines software life cycle processes for medical device software. It provides a structured framework for development and maintenance without replacing the broader validation, risk management and regulatory obligations for the finished device.

What is IEC 62304?
Last reviewed:

What does IEC 62304 cover?

IEC 62304 establishes processes, activities and tasks for developing and maintaining medical device software. It applies when software is itself a medical device and when software is embedded in or forms an integral part of a medical device.

As of July 2026, the current consolidated edition is IEC 62304:2006 with Amendment 1:2015, Edition 1.1.

Does IEC 62304 apply to SaMD and embedded software?

Yes. The standard can apply to Software as a Medical Device operating on general-purpose platforms and to software controlling medical equipment.

Whether a particular function is regulated as medical device software depends on its intended purpose and the applicable jurisdiction. IEC 62304 does not decide whether software is a medical device; it provides a life cycle framework once its applicability has been established.

What are IEC 62304 software safety classes?

IEC 62304 assigns software Classes A, B or C according to the possible harm from a hazardous situation to which the software system can contribute. The classification analysis considers risk controls external to the software system as specified by the standard, and the assigned class affects the rigor of applicable software life cycle activities.

These software safety classes are not the same as regulatory device classes such as FDA Class II or EU MDR Class IIa. One classification cannot be inferred directly from the other.

Does IEC 62304 cover validation and cybersecurity?

IEC 62304 addresses important development and maintenance controls, but the IEC states that it does not cover validation and final release of the complete medical device. Manufacturers need additional evidence demonstrating that the finished device meets user needs and intended uses.

It is also not a complete cybersecurity standard. Cybersecurity requires coordinated security risk management, architecture, testing, vulnerability management and post-market processes. See Pure Global’s medical device cybersecurity consulting.

How does IEC 62304 relate to ISO 14971?

IEC 62304 relies on medical device risk management to connect software failures and contributing factors to hazardous situations. The software process should therefore align with the manufacturer’s broader ISO 14971 risk management.

Market submissions may require software documentation beyond IEC 62304. Manufacturers should verify current FDA software guidance for the United States and MDCG guidance for the European Union.

Let's Talk,
Anywhere You Are.

Whether looking for more information or ready to partner with us, we're here to guide you through every step of the regulatory process.

Contact us