Standards, Guidance & Notices
Showing 11–15 of 15
FDA
CDRH
CDRH
FDA-OTS-Software-2023
Off-The-Shelf (OTS) Software Use in Medical Devices
FDA guidance setting out the recommended documentation in premarket submissions for off-the-shelf (OTS) software incorporated into medical devices, such as operating systems, database management systems, and libraries. A practical basis for managing SOUP (Software of Unknown Provenance). It presents requirements for evaluating and documenting vendor information, known anomalies, and the support life cycle. Referenced in relation to the SOUP management requirements of IEC 62304.
Published: 2023-09-28
FDA
CDRH
CDRH
FDA-Device-Software-Functions-2023
Content of Premarket Submissions for Device Software Functions
FDA final guidance (2023) on the content of software documentation required in premarket submissions (510(k), PMA, De Novo) for SaMD and SiMD. It organizes documentation requirements by documentation level (Basic or Enhanced) and specifies what to include for software design specifications, architecture, verification and validation, and unresolved anomalies. It replaces the 2005 Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices.
Published: 2023-06-14
FDA
CDRH
CDRH
FDA-Interoperability-2017
Design Considerations and Pre-market Submission Recommendations for Interoperable Medical Devices
This FDA final guidance addresses the safe and effective interoperability of medical devices that connect and exchange information electronically (e.g., devices integrated with EHRs or connected to networks). It covers design considerations (risk management, error management, and data integrity), the technical documentation to include in premarket submissions, and labeling. It shows the correspondence with ISO 14971 (risk management). Essential reading for submissions of network-connected SaMD and medical IoT devices.
Published: 2017-09-06
FDA
CDRH
CDRH
FDA-Cybersecurity-OTS-2005
Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software
Early FDA guidance (2005) on cybersecurity management of off-the-shelf (OTS) software incorporated into network-connected medical devices. It sets out the division of responsibilities between manufacturers and healthcare facilities and the approach to operating system patching, antivirus protection, and access control. Useful for understanding the regulatory history as a predecessor of the current final cybersecurity guidance (first issued in September 2023 and since revised, including the June 2025 version).
Published: 2005-01-14
FDA
CDRH
CDRH
FDA-SW-Validation-2002
General Principles of Software Validation — Final Guidance
FDA final guidance (Version 2.0) setting out the general principles applicable to the validation of medical device software and of software used in design and manufacturing. It systematically organizes the concepts of the software life cycle, verification, and validation. It continues to serve as a reference document after the adoption of IEC 62304 and is a foundational document for preparing premarket submissions.
Published: 2002-01-11
