Standards, Guidance & Notices
Showing 111–120 of 129
NIST
SP
SP
SP 800-37 Rev. 2
Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
This publication describes the Risk Management Framework (RMF) and provides guidelines for applying the RMF to information systems and organizations. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. The RMF includes activities to prepare organizations to execute the framework at appropriate risk management levels. The RMF also promotes near real-time risk management and ongoing information system and common control authorization through the implementation of continuous monitoring processes; provides senior leaders and executives with the necessary information to make efficient, cost-effective, risk management decisions about the systems supporting their missions and business functions; and incorporates security and privacy into the system development life cycle. E
Published: 2018-12-20
AAMI
TIR
TIR
AAMI SW91 ED1:2018
AAMI SW91 ED1:2018
This AAMI technical information report establishes a standardized
classification system for defects identified in health software,
including software embedded in medical devices and Software as a
Medical Device (SaMD). The document defines defect categories based
on type, severity, and origin within the software development
lifecycle, enabling consistent defect tracking, root cause analysis,
and process improvement. The classification scheme supports
compliance with IEC 62304 software lifecycle requirements and FDA
quality system expectations, and is referenced in the context of
cybersecurity vulnerability management and postmarket surveillance
activities. Currently under reaffirmation review by the AAMI SM-WG08
Software Defect Classification Working Group (as of April 2025).
Published: 2018-11-02
EU
MDCG
MDCG
MDCG 2018-5
UDI assignment to medical device software
Clarifies, for software that is placed on the market either as a standalone medical device or as a component of another medical device, when manufacturers must assign a new Basic UDI-DI as opposed to simply updating the UDI-PI (production identifier) for a minor version change. A new Basic UDI-DI is required when a change affects the software's original performance, safety, or interpretation of data -- for example, new or modified algorithms, database structures, operating platforms, architecture, user interfaces, or new interoperability channels -- or when the Basic UDI-DI itself, the name/trade name, version/model number, critical warnings or contraindications, or the user-interface language changes. By contrast, minor revisions such as bug fixes, non-safety-related usability improvements, security patches, or operating-efficiency changes do not require a new Basic UDI-DI; these are tracked instead through the manufacturer's own version/release identification scheme reflected in the UDI-PI. The guidance notes that UDI placement (labelling/display) criteria are addressed in a separate, later guide, and should be read together with MDCG 2018-1 on UDI assignment.
Published: 2018-10-01
JIS
Std
Std
JIS Q 13485:2018
JIS Q 13485:2018 Medical devices - Quality management systems - Requirements for regulatory purposes (equivalent to ISO 13485:2016)
This JIS standard specifies quality management system (QMS) requirements for medical devices across their entire lifecycle, from design and development through manufacturing, storage, distribution, installation, servicing, and disposal, corresponding to ISO 13485:2016. The document establishes the foundational QMS framework required for medical device manufacturers to obtain manufacturing and sales licenses and manufacturing registration under Japan's Pharmaceutical Affairs Law (Yakuhin Kikai Hou). Manufacturers must establish documented procedures for design control, risk management, supplier management, production and process controls, verification and validation, nonconforming product management, corrective and preventive actions, and post-market surveillance. The standard emphasizes management responsibility, resource provision, competence and training, and management review to ensure consistent product quality and safety. Organizations must maintain traceability, manage changes, and implement effective management of product recalls. This QMS standard serves as the regulatory foundation integrating all other technical standards (IEC 62304, ISO 14971, IEC 62366-1) into a coordinated governance structure.
Published: 2018-04-20
IMDRF
IMDRF/SaMD WG/N41 FINAL:2017
Software as a Medical Device (SaMD): Clinical Evaluation
IMDRF final document on the clinical evaluation of SaMD. It defines clinical evaluation as a set of ongoing activities to assess and analyze a SaMD's clinical safety, effectiveness, and performance, consisting of three components: valid clinical association (is there a valid clinical association between the SaMD output and the targeted clinical condition?), analytical validation (does the SaMD correctly process input data to generate accurate, reliable, and precise output data?), and clinical validation (does use of that output achieve the intended purpose in the target population in the context of clinical care?). All SaMD should demonstrate these components, using existing evidence or generating new evidence. Depending on the N12 risk category and subject to each jurisdiction's laws, manufacturers of certain low-risk SaMD may self-declare the appropriateness of the evidence, while independent review of clinical evidence becomes more important for higher-risk SaMD. Manufacturers continue to collect real-world performance data after market entry.
Published: 2017-09-21
FDA
CDRH
CDRH
FDA-Interoperability-2017
Design Considerations and Pre-market Submission Recommendations for Interoperable Medical Devices
This FDA final guidance addresses the safe and effective interoperability of medical devices that connect and exchange information electronically (e.g., devices integrated with EHRs or connected to networks). It covers design considerations (risk management, error management, and data integrity), the technical documentation to include in premarket submissions, and labeling. It shows the correspondence with ISO 14971 (risk management). Essential reading for submissions of network-connected SaMD and medical IoT devices.
Published: 2017-09-06
JIS
Std
Std
JIS T 2304:2017
JIS T 2304:2017 Medical device software - Software lifecycle processes (equivalent to IEC 62304:2006+Amd.1:2015)
This JIS standard specifies software lifecycle processes for embedded software in medical devices and Software as a Medical Device (SaMD), corresponding to IEC 62304:2006+Amendment 1:2015. The document defines development and maintenance requirements according to safety classes A, B, and C, establishing a comprehensive framework for software development activities. Originally enacted in 2006, the standard was revised in 2017 to align with the 2015 amendment of the international standard. Manufacturers must comply with this standard when developing medical device software to ensure systematic control of design, development, verification, validation, and post-market activities. The lifecycle processes encompass requirements analysis, design specification, implementation, verification, and validation phases tailored to device risk classification. This standard serves as a foundational requirement under the Pharmaceutical Affairs Law (Yakuhin Kikai Hou) for medical device approval and registration in Japan.
Published: 2017-03-01
IEC
IEC 82304-1:2016
Health software — Part 1: General requirements for product safety
Applies to health software intended to be operated on general-purpose computing platforms. Covers product safety requirements for the complete life cycle.
Published: 2016-10-01
ISO
ISO 13485:2016
Medical devices — Quality management systems — Requirements for regulatory purposes
Specifies requirements for a quality management system where an organization needs to demonstrate its ability to provide medical devices and related services.
Published: 2016-03-01
IMDRF
IMDRF/SaMD WG/N23 FINAL:2015
Software as a Medical Device (SaMD): Application of Quality Management System
IMDRF final document on applying a quality management system (QMS) to SaMD. It is aimed mainly at software development organizations that apply good software quality and engineering practices but may not be familiar with medical device QMS principles, and explains those principles from a software perspective. An effective QMS for SaMD is described in terms of three principles: leadership and organizational support, providing leadership, accountability, governance, and adequate resources to assure the safety, effectiveness, and performance of SaMD; SaMD lifecycle support processes, which are scalable for the size of the organization and applied consistently across all realization and use processes; and SaMD realization and use processes, covering activities from requirements through design, development, and verification and validation. The three principles are not separate series of processes: leadership and organizational support provides the foundation for the lifecycle support processes, which apply across the realization and use processes. The concepts in each section are related to clauses of ISO 13485:2003.
Published: 2015-10-02
