Skip to content
Assyro AI
Back to Glossary
Medical Devices

IEC 62304

IEC 62304 is the international standard defining the life cycle processes for medical device software, covering development and maintenance of software that is itself a device or embedded in one, but stopping short of final device validation and release.

Usage Examples

  • The SaMD is built under IEC 62304, so the maintenance and configuration management plans go into the submission, not just the test reports.
  • We are declaring conformity to the FDA-recognized version of ANSI/AAMI/IEC 62304 for that documentation element instead of writing it from scratch.
  • The notified body will read the IEC 62304 records as our Annex I 17.2 evidence, so the change history has to be complete.

What is IEC 62304?

IEC 62304 is the international standard defining the life cycle processes for medical device software, covering development and maintenance of software that is itself a device or embedded in one, but stopping short of final device validation and release.

IEC 62304 exists because medical device software cannot be judged by inspecting the finished build. A latent defect is invisible in compiled code, so the only durable evidence of safety is how the software was planned, written, changed, and controlled. IEC 62304 therefore specifies life cycle processes, activities, and tasks, and establishes a common framework for them, rather than specifying properties of the product itself.

IEC 62304 applies to the development and maintenance of medical device software when the software is itself a medical device or is an embedded or integral part of the final device, which puts SaMD, device firmware, and mobile medical apps inside one framework. IEC 62304 does not cover validation and final release of the medical device, even when the device consists entirely of software. That step belongs to the quality system.

IEC 62304 reaches regulators through two doors. FDA recognizes the complete standard, Edition 1.1, under recognition number 13-79, so a US sponsor can answer a premarket documentation element with a Declaration of Conformity to named clauses instead of narrative text. In the EU, IEC 62304 records are how manufacturers evidence the development life cycle that MDR Annex I 17.2 demands as state of the art.

Not to be confused with

ISO 14971
ISO 14971 governs risk management for the whole device and produces the risk management file; IEC 62304 governs the software life cycle and consumes that risk output. FDA recognizes and lists them as separate consensus standards, and conformity to one demonstrates nothing about the other.
FDA Documentation Level (Basic / Enhanced)
the Documentation Level is FDA's premarket documentation axis, driven by whether a software failure could present a hazardous situation with a probable risk of death or serious injury before risk controls. It is not the software safety class assigned inside IEC 62304, and FDA has said the two categorizations differ.
21 CFR Part 820 (QMSR)
Part 820 is a binding FDA regulation covering the manufacturer's quality management system, enforced by inspection, and since 2 February 2026 it incorporates ISO 13485:2016 by reference. IEC 62304 is a voluntary consensus standard covering one product's software processes, and declaring conformity to it discharges no quality system obligation.
IEC 82304-1
IEC 82304-1 sets general product safety requirements for health software products. IEC 62304 sets the life cycle processes used to build that software, so the two are complementary rather than alternatives.

IEC 62304 obligations a device software team actually has to execute, plus what each regulator does with them:

What you must do

  1. 1Apply the life cycle processes to any software that is itself a medical device or is an embedded or integral part of the final device, and keep validation and final release of the finished device outside the IEC 62304 deliverables, because the standard stops before themIEC 62304:2006+A1:2015, Scope
  2. 2Declare conformity only against the version FDA recognizes, IEC 62304 Edition 1.1 (2015-06) adopted as ANSI AAMI IEC 62304:2006/A1:2016, which FDA recognizes as a complete standardFDA Recognition Number 13-79
  3. 3In a US premarket submission, either write the software development, configuration management and maintenance documentation directly, or provide a Declaration of Conformity covering subclauses 5.1.1, 5.1.2, 5.1.3, 5.1.6, 5.1.7, 5.1.8, 5.1.9, clause 6, and clause 8, rather than declaring to the complete standardFDA Device Software Guidance (June 2023), Section VI.G
  4. 4State the device's Documentation Level with a rationale, and provide Enhanced Documentation where a failure or flaw of any device software function could present a hazardous situation with a probable risk of death or serious injury, assessed before risk control measures are appliedFDA Device Software Guidance (June 2023), Documentation Level
  5. 5For the EU market, show the software was developed and manufactured in accordance with the state of the art, taking into account development life cycle, risk management including information security, verification and validationEU MDR Annex I, 17.2

Common mistakes

  • Treating a Declaration of Conformity to IEC 62304 as the software submission

    FDA offers the Declaration as an alternative for one documentation element, not for the package, and has said a Declaration to the complete standard is not needed because its categorization of device software functions differs from FDA's. The Documentation Level rationale, risk management file, software description, architecture, and testing documentation are still expected, and substituting the Declaration for them buys an information request while the review clock sits.

  • Treating IEC 62304 conformity as EU MDR compliance

    a standard carries a presumption of conformity only once it is harmonised under the Regulation and published in the Official Journal, a limit the Commission's own MDCG guidance states about the standards it lists. A notified body assesses Annex I 17.2 on its own terms; 62304 records are evidence toward it, not a substitute for it.

  • Setting the FDA Documentation Level from the device's regulatory class

    the Documentation Level follows software risk, not classification. FDA's own worked example in the 2023 guidance assigns a class III in vitro nucleic acid test for HPV DNA the Basic Documentation Level, because a software failure would not present a probable risk of death or serious injury before risk controls. Inferring Enhanced from class III alone buys months of documentation nobody asked for.

When This Matters

  • The SaMD is built under IEC 62304, so the maintenance and configuration management plans go into the submission, not just the test reports.
  • We are declaring conformity to the FDA-recognized version of ANSI/AAMI/IEC 62304 for that documentation element instead of writing it from scratch.
  • The notified body will read the IEC 62304 records as our Annex I 17.2 evidence, so the change history has to be complete.

Frequently Asked Questions

No. FDA does not require IEC 62304 conformity, but it recognizes the complete standard, Edition 1.1, as ANSI AAMI IEC 62304:2006/A1:2016 under recognition number 13-79. Its 2023 device software guidance lets a sponsor answer the development, configuration management and maintenance documentation element with a Declaration of Conformity to named clauses.

Related Use Cases

Related Regulatory Intelligence

Related Actions

Sources & References

Share this page
Agent CTA Background

Simplify IEC 62304 compliance