LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (129)
Standards, Guidance & Notices
Showing 121–129 of 129
IMDRF
IMDRF/MC/N35 FINAL:2015
Statement regarding Use of IEC 62304:2006 "Medical device software - Software life cycle processes"
PUBLISHED Software Life Cycle
Information document of the IMDRF Management Committee listing how IEC 62304:2006 (Medical device software – Software life cycle processes) is used in each jurisdiction's regulatory system (as of 2015). In Australia, compliance is used as evidence of meeting the Essential Principles; in Canada and the US, it is a recognized standard that can be used as evidence of conformity or for a declaration of conformity. In Europe, the corresponding EN 62304:2006 is a harmonized standard providing a presumption of conformity. In China, it has been adopted as the recommended (not mandatory) standard YY/T 0664-2008, while in Brazil and Russia the use of standards is voluntary. For Japan (MHLW/PMDA), the standard was not yet referred to, but could be used in a premarket application to rationally explain conformity with the Essential Principles. The document does not set out a common position or an interpretation of the standard.
Published: 2015-10-02
IEC
IEC 62304:2006+AMD1:2015
Medical device software — Software life cycle processes
PUBLISHED Software Life Cycle
Defines life cycle requirements for software in medical devices and in vitro diagnostic medical devices. Applies to development and maintenance of medical device software.
Published: 2015-06-01
IMDRF
IMDRF/SaMD WG/N12 FINAL:2014
Software as a Medical Device: Possible Framework for Risk Categorization and Corresponding Considerations
PUBLISHED SaMD Classification & Approval
IMDRF final document proposing a possible framework for risk categorization of SaMD and the corresponding considerations. The category is determined by combining two factors: the significance of the information provided by the SaMD to the healthcare decision (treat or diagnose, drive clinical management, or inform clinical management) and the state of the healthcare situation or condition (critical, serious, or non-serious), resulting in four categories, I to IV, with treating or diagnosing a critical condition in the highest category (IV). The categories are relative and reflect the level of impact on the patient or public health, where accurate information provided by the SaMD is vital to avoid death, long-term disability, or other serious deterioration of health. Categorization relies on an accurate and complete SaMD definition statement. Other aspects, such as the transparency of inputs or technological characteristics, do not influence the category but inform the identification of considerations specific to a given SaMD, such as clinical evaluation, quality management, and information security.
Published: 2014-09-18
IMDRF
IMDRF/SaMD WG/N10 FINAL:2013
Software as a Medical Device (SaMD): Key Definitions
PUBLISHED SaMD Classification & Approval
IMDRF final document setting out a common definition of SaMD and a reminder of related key terms. SaMD is defined as software intended to be used for one or more medical purposes that perform these purposes without being part of a hardware medical device, and the document converges on the term SaMD in place of terms such as "standalone software." Notes to the definition state that SaMD is a medical device and includes IVD medical devices; that it is capable of running on general purpose (non-medical purpose) computing platforms; that "without being part of" means the software is not necessary for a hardware medical device to achieve its intended medical purpose; that software intended to drive a hardware medical device does not meet the definition; that SaMD may be used in combination with (e.g., as a module) or interfaced with other products, including medical devices; and that mobile apps meeting the definition are SaMD. Software used to make or maintain a device is not considered SaMD. Relevant key terms previously defined in GHTF documents are also restated.
Published: 2013-12-18
NIST
SP
SP 800-30 Rev. 1
Guide for Conducting Risk Assessments
PUBLISHED NEW Risk Management
The purpose of Special Publication 800-30 is to provide guidance for conducting risk assessments of federal information systems and organizations, amplifying the guidance in Special Publication 800-39. Risk assessments, carried out at all three tiers in the risk management hierarchy, are part of an overall risk management process—providing senior leaders/executives with the information needed to determine appropriate courses of action in response to identified risks.
Published: 2012-09-17
NIST
SP
SP 800-39
Managing Information Security Risk: Organization, Mission, and Information System View
PUBLISHED NEW Cybersecurity
The purpose of Special Publication 800-39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. Special Publication 800-39 provides a structured, yet flexible approach for managing information security risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. The guidance provided in this publication is not intended to replace or subsume other risk-related activities, programs, processes, or approaches that organizations have implemented or intend to implement addressing areas of risk management covered by other legislation, directives, policies, programmatic initiatives, o
Published: 2011-03-01
IEC
IEC/TR 80002-1:2009
Medical device software — Part 1: Guidance on the application of ISO 14971 to medical device software
PUBLISHED Risk Management
Provides guidance on the application of ISO 14971 to medical device software, addressing software-specific aspects of risk management.
Published: 2009-08-01
FDA
CDRH
FDA-Cybersecurity-OTS-2005
Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software
PUBLISHED Cybersecurity
Early FDA guidance (2005) on cybersecurity management of off-the-shelf (OTS) software incorporated into network-connected medical devices. It sets out the division of responsibilities between manufacturers and healthcare facilities and the approach to operating system patching, antivirus protection, and access control. Useful for understanding the regulatory history as a predecessor of the current final cybersecurity guidance (first issued in September 2023 and since revised, including the June 2025 version).
Published: 2005-01-14
FDA
CDRH
FDA-SW-Validation-2002
General Principles of Software Validation — Final Guidance
FINAL Software Life Cycle
FDA final guidance (Version 2.0) setting out the general principles applicable to the validation of medical device software and of software used in design and manufacturing. It systematically organizes the concepts of the software life cycle, verification, and validation. It continues to serve as a reference document after the adoption of IEC 62304 and is a foundational document for preparing premarket submissions.
Published: 2002-01-11
‹ 1 … 11 12 13