LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 13, 2026
MSC Portal Regulatory Watch All Entries (146)
Standards, Guidance & Notices
Showing 141–146 of 146
IMDRF
IMDRF/SaMD WG/N10 FINAL:2013
Software as a Medical Device (SaMD): Key Definitions
PUBLISHED SaMD Classification
This foundational document establishes international definitions and terminology for Software as a Medical Device (SaMD), distinguishing it from hardware-based medical devices. SaMD is defined as software intended for use in achieving a medical purpose without being part of a hardware medical device. This definition serves as the baseline reference for all subsequent IMDRF SaMD guidance documents and national regulatory frameworks. The FDA, PMDA, and EU MDR all reference this definition in their respective SaMD regulatory frameworks, making it essential to understanding harmonized international SaMD regulation and classification schemes adopted globally.
Published: 2013-12-18
NIST
SP
SP 800-30 Rev. 1
Guide for Conducting Risk Assessments
PUBLISHED NEW Risk Management
The purpose of Special Publication 800-30 is to provide guidance for conducting risk assessments of federal information systems and organizations, amplifying the guidance in Special Publication 800-39. Risk assessments, carried out at all three tiers in the risk management hierarchy, are part of an overall risk management process—providing senior leaders/executives with the information needed to determine appropriate courses of action in response to identified risks.
Published: 2012-09-17
NIST
SP
SP 800-39
Managing Information Security Risk: Organization, Mission, and Information System View
PUBLISHED NEW Cybersecurity
The purpose of Special Publication 800-39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. Special Publication 800-39 provides a structured, yet flexible approach for managing information security risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. The guidance provided in this publication is not intended to replace or subsume other risk-related activities, programs, processes, or approaches that organizations have implemented or intend to implement addressing areas of risk management covered by other legislation, directives, policies, programmatic initiatives, o
Published: 2011-03-01
IEC
IEC/TR 80002-1:2009
Medical device software — Part 1: Guidance on the application of ISO 14971 to medical device software
PUBLISHED Risk Management
Provides guidance on the application of ISO 14971 to medical device software, addressing software-specific aspects of risk management.
Published: 2009-08-01
FDA
CDRH
FDA-Cybersecurity-OTS-2005
Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software
PUBLISHED Cybersecurity
This FDA guidance document (2005) addresses cybersecurity management for network-connected medical devices incorporating off-the-shelf (OTS) software components. The guidance delineates responsibility allocation between manufacturers and healthcare facility information technology personnel, acknowledging shared accountability for device cybersecurity posture. Key technical topics include operating system patch management, antivirus software deployment, network access controls, and authentication mechanisms. The document establishes that manufacturers bear primary responsibility for device design incorporating security controls, while healthcare facilities assume responsibility for network infrastructure, patch management, and periodic security assessments appropriate to their operational environments. While superseded by more contemporary 2023 guidance addressing current cybersecurity threats and FDA regulatory expectations, this 2005 document provides valuable historical context for understanding the evolution of FDA cybersecurity requirements. Manufacturers and healthcare organizations benefit from understanding these foundational cybersecurity management principles, which remain relevant despite advances in threat landscape and technology. The document emphasizes that cybersecurity is a shared responsibility requiring collaboration between device manufacturers and end-users.
Published: 2005-01-14
FDA
CDRH
FDA-SW-Validation-2002
General Principles of Software Validation — Final Guidance
FINAL Software Life Cycle
This FDA final guidance (Version 2.0) establishes foundational principles for validating medical device software and software used in device design and manufacturing. The document systematically addresses software lifecycle methodologies, verification and validation (V&V) concepts, and documentation expectations. It defines key terminology including validation, verification, and testing, and describes the relationship between software development processes and regulatory submissions. Although IEC 62304 provides a more recent international standard framework, this guidance document remains a critical reference for FDA submissions and regulatory expectations. Manufacturers should apply the lifecycle principles outlined herein to demonstrate software safety and effectiveness. The guidance emphasizes that validation must be commensurate with device risk classification and intended use. It provides practical examples of validation approaches for various software categories and addresses both standalone software (SaMD) and software as a component of hardware devices. The document serves as essential foundational material for understanding FDA's expectations regarding software documentation in premarket applications.
Published: 2002-01-11
1 13 14 15