Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · ISO and IEC standards for MedTech and pharma

IEC 62304

Also known as: IEC 62304:2006+A1:2015, EN 62304, Medical device software life cycle processes

IEC 62304 is the international standard for software life cycle processes of medical device software. It defines development, maintenance, software risk management, configuration management and problem resolution processes, scaled by software safety class A, B or C.

  • Standards
  • MDR
  • IVDR

In one sentence

IEC 62304 defines life cycle processes for medical device software, scaled by software safety classes A, B and C.

Example

A startup developing an AI-based ECG analysis app classifies its software as safety class B, documents its software architecture, lists each third-party library as SOUP with known anomalies, and keeps unit and integration test records for its notified body review.

How it applies

  • Safety classes: Class A where no injury or damage to health is possible, class B where non-serious injury is possible, class C where death or serious injury is possible. The class determines which activities and documents are required.
  • Processes: Software development planning, requirements, architecture, detailed design, unit implementation and verification, integration, system testing and release; plus maintenance, configuration management and problem resolution. Risk management follows ISO 14971.
  • SOUP: Software of unknown provenance, such as open-source libraries or operating systems, must be identified with its version, requirements and known anomalies.
  • Scope limit: IEC 62304 covers the software life cycle, not the validation of the whole device. Validation of the medical device software against its intended purpose sits at device level. Security activities are covered by IEC 81001-5-1.
  • Status: A new edition is in preparation; check the current status before citing it, and check the current list of harmonized standards.
  • Technical documentation: Development plan, requirements, architecture, SOUP list, test records, known residual anomalies and release notes form the software evidence in the technical documentation. Changes after release run through the maintenance process and change control.

IEC 62304 vs. IEC 61508

IEC 61508 is the generic functional safety standard for E/E/PE safety-related systems and assigns Safety Integrity Levels with quantified failure targets. IEC 62304 is specific to medical device software, doesn't quantify failure rates and scales its requirements by the severity of possible harm. A SIL rating says nothing about the IEC 62304 class, and vice versa.

Compared with the USA

The FDA recognizes IEC 62304 as a consensus standard. Its guidance on the content of premarket submissions for device software functions asks for a documentation level (basic or enhanced) based on risk, which is related to but not the same as the IEC 62304 safety class.

By knowledge.aitechdoc.world · Published September 25, 2026 · Last reviewed

Source: IEC 62304:2006+A1:2015, Medical device software — Software life cycle processes

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!