LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 14, 2026
MSC Portal Regulatory Watch All Entries (12)
Standards, Guidance & Notices
Showing 1–10 of 12
IMDRF
IMDRF/SaMD WG/N81 FINAL:2025
Characterization Considerations for Medical Device Software and Software-Specific Risk
PUBLISHED SaMD Classification
Presents considerations for characterizing medical device software and identifying software-specific risk factors. Explains how software characteristics such as function, complexity and interconnectivity relate to the risks they introduce, enabling manufacturers and regulators to apply proportionate risk management and regulatory approaches.
Published: 2025-01-29
IMDRF
IMDRF/AIML WG/N88 FINAL:2025
Good machine learning practice for medical device development: Guiding principles
PUBLISHED AI / Machine Learning
Sets out guiding principles for the safe and effective use of machine learning in medical device development. Covers data quality management, the model development process, verification and validation, and ongoing performance monitoring, to help ensure the reliability and performance of machine learning systems.
Published: 2025-01-29
IMDRF
IMDRF/GRRP WG/N47 FINAL:2024 (Edition 2)
Essential Principles of Safety and Performance of Medical Devices and IVD Medical Devices
PUBLISHED Risk Management
Defines the internationally agreed essential principles of safety and performance that medical devices and IVD medical devices are expected to meet. Covers baseline requirements across the product life cycle, including design, manufacture, verification and risk management, with the aim of protecting patient safety and public health.
Published: 2024-04-26
IMDRF
IMDRF/CYBER WG/N73 FINAL:2023
Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity
PUBLISHED SBOM / Vulnerability
This document specifies IMDRF guidance on creating, managing, and sharing Software Bill of Materials (SBOM) for medical devices. It defines minimum SBOM elements, acceptable formats, and lifecycle management approaches necessary for effective cybersecurity management. Manufacturers should develop and maintain accurate SBOMs documenting all software components and dependencies throughout product lifecycle. The document provides the practical foundation for FDA 2023 final guidance SBOM submission requirements and supports implementation of Japan's vulnerability management notification requirements from the Ministry of Health, Labour and Welfare. SBOMs enable manufacturers, regulators, and healthcare organizations to identify and respond rapidly to software vulnerabilities affecting medical devices.
Published: 2023-04-13
IMDRF
IMDRF/CYBER WG/N70 FINAL:2023
Principles and Practices for the Cybersecurity of Legacy Medical Devices
PUBLISHED Cybersecurity
This document provides IMDRF guidance on managing cybersecurity risks in legacy medical devices that are end-of-life (EOL) or difficult to maintain. It clarifies responsibilities and practical mitigation strategies for both manufacturers and healthcare facilities. The document establishes frameworks for EOL management planning, identifying alternative solutions, and making informed risk acceptance decisions. As a complementary document to N60, it addresses the specific challenges posed by legacy systems that cannot be readily updated with security patches or improvements. Manufacturers and healthcare organizations should use this guidance to systematically assess legacy device risks and implement appropriate risk mitigation measures aligned with current cybersecurity standards.
Published: 2023-04-11
IMDRF
IMDRF/AIMD WG/N67 (Edition 1)
Machine Learning-enabled Medical Devices: Key Terms and Definitions
PUBLISHED AI / Machine Learning
Establishes a common vocabulary for machine learning used in medical devices. Defines key terms including model, training data, algorithm and performance evaluation measures, in order to promote a shared technical understanding and to facilitate regulatory communication across jurisdictions.
Published: 2022-05-09
IMDRF
IMDRF/CYBER WG/N60 FINAL:2020
Principles and Practices for Medical Device Cybersecurity
PUBLISHED Cybersecurity
This core document establishes international principles and practices for medical device cybersecurity, covering the complete device lifecycle. It specifies requirements for security by design, vulnerability management, and incident response frameworks. Manufacturers should integrate cybersecurity considerations throughout product development, maintenance, and end-of-life phases. The document serves as the common foundation referenced in Japan's Basic Principles for Conformity Assessment of Medical Devices (Article 12, Paragraph 3), FDA 2023 final cybersecurity guidance, and EU MDCG cybersecurity guidance. Japanese regulatory authorities directly reference this document in official notifications, making it essential for regulatory compliance in multiple jurisdictions.
Published: 2020-04-20
IMDRF
IMDRF/SaMD WG/N41 FINAL:2017
Software as a Medical Device (SaMD): Clinical Evaluation
PUBLISHED SaMD Classification
This document specifies the clinical evaluation framework for SaMD, defining a three-layer structure for evidence of effectiveness: analytical validation, technical verification, and clinical validation. Manufacturers should determine the depth of clinical evidence required based on the SaMD risk category established in the N12 framework. The document provides guidance on what constitutes appropriate clinical evidence for each risk level and serves as the baseline for clinical evaluation requirements in regulatory submissions. This framework is referenced in FDA, PMDA, and EU MDCG approval processes, establishing harmonized expectations for clinical documentation and evidence standards in SaMD regulatory submissions globally.
Published: 2017-09-21
IMDRF
IMDRF/SaMD WG/N23 FINAL:2015
Software as a Medical Device (SaMD): Application of Quality Management System
PUBLISHED SaMD Classification
Describes how quality management system principles apply to Software as a Medical Device. Addresses requirements definition, the software development process, verification and validation, change management and risk management, setting out the quality assurance structure and process requirements needed to develop and deliver SaMD.
Published: 2015-10-02
IMDRF
IMDRF/MC/N35 FINAL:2015
Statement regarding Use of IEC 62304:2006 "Medical device software - Software life cycle processes"
PUBLISHED Software Life Cycle
An official statement by IMDRF regulators on the use of IEC 62304:2006. Sets out a common international position on the scope, interpretation and anticipated revision of the standard for medical device software development, in order to promote consistency among regulatory authorities.
Published: 2015-10-02
1 2