LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (13)
Standards, Guidance & Notices
Showing 1–10 of 13
IMDRF
IMDRF/SaMD WG/N90 FINAL:2026
Essential Principles and Content of Predetermined Change Control Plans
FINAL NEW SaMD Classification & Approval
Final document of the IMDRF Software as a Medical Device Working Group setting out high-level principles for Predetermined Change Control Plans (PCCPs), through which manufacturers can seek authorization in advance for certain planned modifications to medical device software (as defined in N81) that remain within the original intended use or intended purpose. It identifies five essential principles (focused and bounded, risk-based, evidence-based, transparent, and TPLC perspective) and three interconnected elements: Description of Changes, Change Plan (performance evaluation methods with pre-specified acceptance criteria, and update procedures including labelling and communication to users), and Impact Assessment (individual and cumulative benefits, risks and mitigations). Changes are expected to be implemented under the quality management system of the manufacturer, in line with standards such as IEC 62304. It also discusses benefits and challenges, including more complex submissions and differing adoption across jurisdictions. The document aims to support international convergence and does not establish regulatory requirements or serve as regulation or guidance in any jurisdiction.
Published: 2026-08-06
IMDRF
IMDRF/SaMD WG/N81 FINAL:2025
Characterization Considerations for Medical Device Software and Software-Specific Risk
PUBLISHED SaMD Classification & Approval
Final document of the IMDRF SaMD Working Group that supplements the N12 SaMD risk categorization framework and broadens its scope to all medical device software, including software that is part of a hardware medical device. It identifies key elements of an intended use/intended purpose statement and organizes characterization features and attributes into four groupings: medical problem and/or objective, context of use, function and/or use (e.g., output type, input source, degree of autonomy, explainability), and change management. For risk characterization, it focuses on information-related (performance-related) hazards, considers both direct and indirect harms including reduction of effectiveness, and notes that it can be helpful to set the probability of software failure to 1 when estimating software-specific risk. Appendices provide guiding questions and worked examples. The document is not regulation or guidance, does not provide guidance on device classification, and does not replace N12 or risk management standards such as ISO 14971.
Published: 2025-01-29
IMDRF
IMDRF/AIML WG/N88 FINAL:2025
Good machine learning practice for medical device development: Guiding principles
PUBLISHED AI / Machine Learning
Final document of the IMDRF AI/ML-enabled Working Group setting out 10 guiding principles for Good Machine Learning Practice (GMLP), intended to promote the development of safe, effective, and high-quality AI-enabled medical devices across the total product life cycle. The principles cover: understanding the intended use and leveraging multidisciplinary expertise; good software engineering, medical device design, and security practices; clinical evaluation using datasets representative of the intended patient population; independence of training and test datasets; fit-for-purpose reference standards; model choice and design tailored to the available data and intended use; assessment focused on human-AI interactions and the performance of the human-AI team rather than the device in isolation; testing under clinically relevant conditions; clear, essential information for users; and monitoring of deployed models and management of re-training risks. The document presents the principles as a call to action for standards organizations, regulators, and other bodies to further advance GMLP, and notes that generative AI may heighten their importance.
Published: 2025-01-29
IMDRF
IMDRF/GRRP WG/N47 FINAL:2024 (Edition 2)
Essential Principles of Safety and Performance of Medical Devices and IVD Medical Devices
PUBLISHED SaMD Classification & Approval
Edition 2 of the IMDRF guidance providing harmonized Essential Principles of Safety and Performance: the fundamental design and manufacturing requirements a manufacturer is expected to meet so that a medical device or IVD medical device is safe and performs as intended throughout its life cycle. Section 5 sets out principles that apply to all medical devices including IVD medical devices, Section 6 those for medical devices other than IVD medical devices, and Section 7 those that apply only to IVD medical devices. Design and manufacturing activities should be under the control of the manufacturer's quality management system, and conformity with the applicable principles is demonstrated and assessed according to procedures designated by the regulatory authority. The document uses "should" to indicate recommendations and reserves "must" for unavoidable situations, including those mandated by regulation. For the content of labeling, it refers to IMDRF/GRRP WG/N52.
Published: 2024-04-26
IMDRF
IMDRF/CYBER WG/N73 FINAL:2023
Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity
PUBLISHED SBOM / Vulnerability
Final document of the IMDRF Medical Device Cybersecurity Working Group on the Software Bill of Materials (SBOM), complementing the medical device cybersecurity principles set out in IMDRF N60. It provides recommendations for medical device manufacturers on creating, maintaining, and distributing SBOMs, and for healthcare providers on receiving and managing them. It also describes how both manufacturers and healthcare providers can use SBOMs in risk management, vulnerability management, and incident response across the total product life cycle.
Published: 2023-04-13
IMDRF
IMDRF/CYBER WG/N70 FINAL:2023
Principles and Practices for the Cybersecurity of Legacy Medical Devices
PUBLISHED Cybersecurity
Final document of the IMDRF Medical Device Cybersecurity Working Group on the cybersecurity of legacy medical devices, complementing IMDRF N60. It divides the total product life cycle for cybersecurity into four stages (Development, Support, Limited Support, and End of Support (EOS)) and sets out the responsibilities and expectations of medical device manufacturers and healthcare providers at each stage in three areas: communication, risk management, and transfer of responsibility. Responsibility shifts from the manufacturer to the healthcare provider as the life cycle progresses, and cybersecurity responsibility for devices used beyond the EOS communicated by the manufacturer rests entirely with the healthcare provider. The document also notes that the end of life or end of support of a software or firmware component can prematurely move the device itself into a later stage, which manufacturers should address in advance.
Published: 2023-04-11
IMDRF
IMDRF/AIMD WG/N67 (Edition 1)
Machine Learning-enabled Medical Devices: Key Terms and Definitions
PUBLISHED AI / Machine Learning
Edition 1 of the IMDRF Artificial Intelligence Medical Devices (AIMD) Working Group document on key terms and definitions for Machine Learning-enabled Medical Devices (MLMD). It establishes terms and definitions across the total product life cycle to promote consistency, support global harmonization, and provide a foundation for future guidelines on MLMD. Section 5 provides key definitions relevant to machine learning used in medical devices (including the definition of MLMD), Section 6 gives definitions from technical standards (e.g., bias, continuous learning, reference standard, reinforcement learning), and Section 7 discusses common machine learning terms. Most terms were previously defined in GHTF documents or internationally recognized AI standards, while some were developed or discussed by the AIMD Working Group. The document also notes that the term "bias" is used differently in data science and in legal discussions.
Published: 2022-05-09
IMDRF
IMDRF/CYBER WG/N60 FINAL:2020
Principles and Practices for Medical Device Cybersecurity
PUBLISHED Cybersecurity
The first IMDRF document to focus exclusively on medical device cybersecurity. It provides concrete recommendations to all responsible stakeholders, including manufacturers, healthcare providers, and regulators, on the general principles and best practices for the cybersecurity of medical devices, including IVD medical devices. It sets out four general principles (global harmonization, total product life cycle, shared responsibility, and information sharing) and organizes premarket considerations (e.g., building security in at the design stage through threat modeling, and preparing customer security documentation) and postmarket considerations (e.g., vulnerability monitoring and remediation, information sharing, and incident response). It is intended to be considered together with the IMDRF Essential Principles of Safety and Performance (N47) throughout the total product life cycle.
Published: 2020-04-20
IMDRF
IMDRF/SaMD WG/N41 FINAL:2017
Software as a Medical Device (SaMD): Clinical Evaluation
PUBLISHED SaMD Classification & Approval
IMDRF final document on the clinical evaluation of SaMD. It defines clinical evaluation as a set of ongoing activities to assess and analyze a SaMD's clinical safety, effectiveness, and performance, consisting of three components: valid clinical association (is there a valid clinical association between the SaMD output and the targeted clinical condition?), analytical validation (does the SaMD correctly process input data to generate accurate, reliable, and precise output data?), and clinical validation (does use of that output achieve the intended purpose in the target population in the context of clinical care?). All SaMD should demonstrate these components, using existing evidence or generating new evidence. Depending on the N12 risk category and subject to each jurisdiction's laws, manufacturers of certain low-risk SaMD may self-declare the appropriateness of the evidence, while independent review of clinical evidence becomes more important for higher-risk SaMD. Manufacturers continue to collect real-world performance data after market entry.
Published: 2017-09-21
IMDRF
IMDRF/SaMD WG/N23 FINAL:2015
Software as a Medical Device (SaMD): Application of Quality Management System
PUBLISHED Quality Management
IMDRF final document on applying a quality management system (QMS) to SaMD. It is aimed mainly at software development organizations that apply good software quality and engineering practices but may not be familiar with medical device QMS principles, and explains those principles from a software perspective. An effective QMS for SaMD is described in terms of three principles: leadership and organizational support, providing leadership, accountability, governance, and adequate resources to assure the safety, effectiveness, and performance of SaMD; SaMD lifecycle support processes, which are scalable for the size of the organization and applied consistently across all realization and use processes; and SaMD realization and use processes, covering activities from requirements through design, development, and verification and validation. The three principles are not separate series of processes: leadership and organizational support provides the foundation for the lifecycle support processes, which apply across the realization and use processes. The concepts in each section are related to clauses of ISO 13485:2003.
Published: 2015-10-02
1 2 ›