# IEC 62304 – Medical device software – Software life cycle processes

> IEC 62304 sets out how you must safely develop and maintain software for medical devices across the entire life cycle - planning, requirements, architecture, implementation, verification, release, maintenance. It assigns your software to one of three safety classes (A, B or C) based on the risk to patients, users or third parties and, as the recognised 'state of the art', is the accepted basis for meeting the software requirements of the EU MDR and the Swiss MedDO.

- Type: Standard, Market-driven
- Scope: Switzerland, EU, Germany
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/iec62304
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does IEC 62304 apply to you?

- Activity: Products with software (applies if additionally: Activity: Medical devices) (Likely applies): You develop products with software, including a medical device - if this software is part of the medical device or itself qualifies as a medical device, IEC 62304 prescribes the software life cycle process, including risk classification (A/B/C) and documentation obligations. For software outside medical devices, IEC 62304 does not apply.
- Activity: Medical devices (Recommend individual review): IEC 62304 only applies to the extent your medical device contains software or is itself software - check whether this condition applies to your specific product.
- Industry: MedTech (Recommend individual review): As a MedTech company with a software component in your products, IEC 62304 is highly likely to be relevant to you; without a specific software element in the product, the standard does not apply.

## Exceptions

- Purely hardware medical devices with no software component fall outside the standard's scope.
- For products already in the field classified as 'legacy software', adapted evidence requirements apply in practice (a retrospective approach), the exact criteria for which were not verified in this session.

## Obligations

- Determine the software safety class (A, B or C) on a risk basis before development begins, or again if the risk context changes.
- Draw up a software development plan covering the processes of planning, requirements analysis, architectural design, detailed design, implementation, integration and system testing, and release.
- Document requirements and architecture in a risk-oriented manner and link them to safety aspects and - increasingly, in revised practice - security aspects.
- Operate configuration management and a problem-resolution process for the entire service life of the software, including after market launch (software maintenance process).
- Scale verification and testing activities to the risk of the respective class; higher classes require more extensive evidence.

## Evidence

- Software development plan.
- Software requirements specification and architecture documentation.
- Evidence of verification, integration and system testing, class-dependent in each case.
- Configuration management records.
- Documented software maintenance and problem-resolution process.
- As part of MDR/MedDO conformity assessment: embedding this evidence in the technical documentation of the overall product.

## Penalties

IEC 62304 is a technical standard with no penalties of its own. Since it is used as the state of the art for the software requirements of the EU MDR and the Swiss MedDO, non-compliance in practice leads to audit findings, refusal of CE marking or Swissmedic authorisation, and, in the event of harm, a weaker position in product liability.

## Frequently asked questions

**What distinguishes safety classes A, B and C?**
The classification depends on the possible harm from a software failure: broadly, class A applies to software where no injury or damage to health is possible, class B to software where a non-serious injury is possible, and class C to software where death or serious injury is possible. The exact, standard-conformant definition of the three classes was not verified word-for-word from a source read in this session (see 'unsicher') and should be checked against the standard itself before any binding classification.

**Is IEC 62304 alone sufficient for the conformity of our medical device software?**
No. IEC 62304 covers the software life cycle but does not replace the overarching risk management (for which ISO 14971 is the accepted basis in practice) or the quality management system under ISO 13485, into which the software processes must be embedded.

**Is the currently valid version of IEC 62304 up to date?**
The most recently consolidated, internationally valid version is IEC 62304:2006 with Amendment 1:2015 (sometimes referred to as Edition 1.1). A second edition is, per secondary sources, in preparation but had not yet been published as of this research.

## Open points of the research

- The full text of IEC 62304 is paywalled and could not be read in this session; the specific catalogue/publication page on webstore.iec.ch also could not be reliably located (the search function only returns results via JavaScript, and guessed publication IDs led to incorrect, unrelated documents). The URL cited is the general IEC webstore homepage, not a verified direct page for IEC 62304.
- The exact, standard-conformant wording defining safety classes A/B/C (in particular the phrasing 'no injury or damage to health', 'non-serious injury', 'death or serious injury') was not quoted word-for-word from a source read in this session, but reproduced from established professional knowledge. This should be checked against the standard's text before any binding classification as part of the regulatory check.
- The exact status and expected publication date of a second IEC 62304 edition were only sketched via a secondary source (Johner Institut) and not verified; for current compliance practice, the 2006+AMD1:2015 version is authoritative regardless.
- A specific Swissmedic reference to IEC 62304 (e.g. its own guideline) could not be found in this session (the presumed Swissmedic page on medical software returned HTTP 404).

## Sources

- [IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes](https://webstore.iec.ch/), International Electrotechnical Commission (IEC), retrieved 24 September 2026
- [IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)](https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/), Johner Institut, retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
