IEC 62304 Compliance

IEC 62304 Compliance

IEC 62304 Compliance

Quality Management Systems

Medical Device Software — Software Life Cycle Processes
Medical Device Software — Software Life Cycle Processes

Edition 2 Rewrites the Rules for Medical Device Software. Are Your Supplier Documentation and SOUP Records Ready?

Edition 2 Rewrites the Rules for Medical Device Software. Are Your Supplier Documentation and SOUP Records Ready?

Edition 2 Rewrites the Rules for Medical Device Software. Are Your Supplier Documentation and SOUP Records Ready?

IEC 62304 compliance demands full lifecycle traceability from development planning through post-market maintenance—with safety classification driving documentation rigor at every stage. Edition 2, targeted for August 2026, replaces three safety classes with two process rigor levels and expands scope to all health software including AI/ML. SOUP assessments require documented evidence from every software supplier in your chain. Certivo automates supplier evidence collection and AI document parsing from SOUP declaration to audit-ready traceability package.

IEC 62304 compliance demands full lifecycle traceability from development planning through post-market maintenance—with safety classification driving documentation rigor at every stage. Edition 2, targeted for August 2026, replaces three safety classes with two process rigor levels and expands scope to all health software including AI/ML. SOUP assessments require documented evidence from every software supplier in your chain. Certivo automates supplier evidence collection and AI document parsing from SOUP declaration to audit-ready traceability package.

IEC 62304 compliance demands full lifecycle traceability from development planning through post-market maintenance—with safety classification driving documentation rigor at every stage. Edition 2, targeted for August 2026, replaces three safety classes with two process rigor levels and expands scope to all health software including AI/ML. SOUP assessments require documented evidence from every software supplier in your chain. Certivo automates supplier evidence collection and AI document parsing from SOUP declaration to audit-ready traceability package.

See How Certivo Automates IEC 62304 Compliance

See How Certivo Automates IEC 62304 Compliance

See How Certivo Automates IEC 62304 Compliance

Talk to an Expert

Talk to an Expert

Talk to an Expert

3 → 2

3 → 2

3 → 2

Safety classes consolidating to rigor levels (Edition 2)

33%

33%

33%

Medical device recalls linked to software failures

5

5

5

Core lifecycle clauses requiring full documentation

Regulation Overview

Jurisdiction

Jurisdiction

Jurisdiction

Global (IEC standard; harmonized under EU MDR/IVDR; FDA-recognized consensus standard)

Global (IEC standard; harmonized under EU MDR/IVDR; FDA-recognized consensus standard)

Regulatory Body

Regulatory Body

Regulatory Body

International Electrotechnical Commission (IEC), Sub-Committee SC 62A

International Electrotechnical Commission (IEC), Sub-Committee SC 62A

Regulation Number

Regulation Number

Regulation Number

IEC 62304:2006+AMD1:2015 (Edition 2 targeted August 2026)

IEC 62304:2006+AMD1:2015 (Edition 2 targeted August 2026)

Effective Date

Effective Date

Effective Date

May 2006 (Amendment 1: June 2015; Edition 2: August 2026 projected)

May 2006 (Amendment 1: June 2015; Edition 2: August 2026 projected)

Official Source

Official Source

Official Source

Key Threshold

Key Threshold

Key Threshold

Safety classification (A/B/C) determines documentation rigor for all lifecycle processes

Safety classification (A/B/C) determines documentation rigor for all lifecycle processes

What is IEC 62304?

What is IEC 62304?

What is IEC 62304?

IEC 62304 is the international standard defining software lifecycle processes for medical device software and the foundation of global medical device software compliance. For supply chain and compliance teams, the primary obligation is ensuring that every software component—including Software of Unknown Provenance (SOUP) such as third-party libraries, open-source modules, and commercial off-the-shelf components—is documented, risk-assessed, and traceable across the entire development and maintenance lifecycle.

The current edition (IEC 62304:2006+AMD1:2015) classifies software into three safety classes—A, B, and C—based on potential patient harm from software failure. Edition 2, expected August 2026, consolidates these into two rigor levels, expands scope to all health software including SaMD and AI/ML applications, and integrates cybersecurity as a core design control. Compliance requires supplier-level evidence—SOUP identification, version tracking, CVE assessments, and functional requirements—from every component provider. When new software versions ship or SOUP components update, your entire documentation set requires reassessment.

Key Components / Sub-Frameworks

Key Components / Sub-Frameworks

Key Components / Sub-Frameworks

Obligation

Full development lifecycle documentation scaled to safety class

Clause 5 — Software Development

Eight activity areas from planning through release

Clause 5 — Software Development

Eight activity areas from planning through release

Obligation

Full development lifecycle documentation scaled to safety class

Obligation

Maintenance plan, re-verification, and re-release procedures

Clause 6 — Software Maintenance

Post-release problem resolution and change management

Clause 6 — Software Maintenance

Post-release problem resolution and change management

Obligation

Maintenance plan, re-verification, and re-release procedures

Obligation

Documented risk analysis, control measures, and residual risk assessment

Clause 7 — Software Risk Management

Integration with ISO 14971 for software-specific hazards

Clause 7 — Software Risk Management

Integration with ISO 14971 for software-specific hazards

Obligation

Documented risk analysis, control measures, and residual risk assessment

Obligation

Complete audit trail for every software build and configuration

Clause 8 — Configuration Management

Version control, change control, and release management

Clause 8 — Configuration Management

Version control, change control, and release management

Obligation

Complete audit trail for every software build and configuration

Obligation

CAPA-aligned process for all software defects and field issues

Clause 9 — Problem Resolution

Tracking anomalies from discovery through verified fix

Clause 9 — Problem Resolution

Tracking anomalies from discovery through verified fix

Obligation

CAPA-aligned process for all software defects and field issues

Obligation

Identification, requirements, risk assessment, and post-market monitoring

SOUP Management

Software of Unknown Provenance documentation

SOUP Management

Software of Unknown Provenance documentation

Obligation

Identification, requirements, risk assessment, and post-market monitoring

IEC 62304 Edition 2 Targets August 2026Replacing Safety Classes A/B/C with Two Rigor Levels and Adding AI/ML Requirements. Is Your Supplier Documentation Current?

IEC 62304 Edition 2 Targets August 2026Replacing Safety Classes A/B/C with Two Rigor Levels and Adding AI/ML Requirements. Is Your Supplier Documentation Current?

IEC 62304 Edition 2 Targets August 2026Replacing Safety Classes A/B/C with Two Rigor Levels and Adding AI/ML Requirements. Is Your Supplier Documentation Current?

IEC 62304 Edition 2 Targets August 2026Replacing Safety Classes A/B/C with Two Rigor Levels and Adding AI/ML Requirements. Is Your Supplier Documentation Current?

Edition 2 is a structural overhaul expanding scope to all health software, introducing mandatory AI development lifecycle planning, and integrating cybersecurity requirements. Regulators expect compliance within 2–3 years of publication. Notified Bodies are already incorporating Edition 2 principles into audits. SOUP declarations and safety classifications documented under Edition 1 will require remapping to the new rigor level framework.

Edition 2 is a structural overhaul expanding scope to all health software, introducing mandatory AI development lifecycle planning, and integrating cybersecurity requirements. Regulators expect compliance within 2–3 years of publication. Notified Bodies are already incorporating Edition 2 principles into audits. SOUP declarations and safety classifications documented under Edition 1 will require remapping to the new rigor level framework.

Edition 2 is a structural overhaul expanding scope to all health software, introducing mandatory AI development lifecycle planning, and integrating cybersecurity requirements. Regulators expect compliance within 2–3 years of publication. Notified Bodies are already incorporating Edition 2 principles into audits. SOUP declarations and safety classifications documented under Edition 1 will require remapping to the new rigor level framework.

Edition 2 is a structural overhaul expanding scope to all health software, introducing mandatory AI development lifecycle planning, and integrating cybersecurity requirements. Regulators expect compliance within 2–3 years of publication. Notified Bodies are already incorporating Edition 2 principles into audits. SOUP declarations and safety classifications documented under Edition 1 will require remapping to the new rigor level framework.

Key Compliance Requirements

Key Compliance Requirements

Who Must Comply

Who Must Comply

  • Medical device manufacturers developing software (embedded or standalone)

  • SaMD developers placing software on regulated markets

  • Suppliers of software components integrated into medical devices

  • Contract software development organizations (CSDOs) working on behalf of device manufacturers

  • Companies assembling multi-component medical systems with third-party software

  • AI/ML developers building diagnostic or therapeutic algorithms for clinical use

Key Thresholds

Safety Class A

No injury or damage to health possible from software failure

Safety Class A

No injury or damage to health possible from software failure

Safety Class B

Non-serious injury possible from software failure

Safety Class B

Non-serious injury possible from software failure

Safety Class C

Death or serious injury possible from software failure

Safety Class C

Death or serious injury possible from software failure

Rigor Levels I & II (Ed. 2)

Edition 2 replaces A/B/C: Level I (lightweight, replaces Class A); Level II (full process rigor, replaces Classes B and C)

Rigor Levels I & II (Ed. 2)

Edition 2 replaces A/B/C: Level I (lightweight, replaces Class A); Level II (full process rigor, replaces Classes B and C)

Core Obligations

Core Obligations

1

Development Planning (Cl. 5.1)

Documented software development plan covering lifecycle model, safety classification, and risk management integration

DEADLINE

All classes

2

Requirements & Architecture (Cl. 5.2–5.3)

Traceable requirements analysis, architectural design, and SOUP identification

DEADLINE

Class A: partial; B/C: full

3

Verification & Validation (Cl. 5.5–5.7)

Unit testing, integration testing, and system testing with documented results

DEADLINE

Class A: system test only; B: integration+system; C: all levels

4

SOUP Assessment

Documented requirements, risk assessment, CVE review, and version tracking for all third-party components

DEADLINE

All classes (depth varies by class)

5

Post-Market Maintenance (Cl. 6)

Maintenance plan, problem tracking, and re-verification for all software changes after release

DEADLINE

All classes

1

Development Planning (Cl. 5.1)

Documented software development plan covering lifecycle model, safety classification, and risk management integration

DEADLINE

All classes

2

Requirements & Architecture (Cl. 5.2–5.3)

Traceable requirements analysis, architectural design, and SOUP identification

DEADLINE

Class A: partial; B/C: full

3

Verification & Validation (Cl. 5.5–5.7)

Unit testing, integration testing, and system testing with documented results

DEADLINE

Class A: system test only; B: integration+system; C: all levels

4

SOUP Assessment

Documented requirements, risk assessment, CVE review, and version tracking for all third-party components

DEADLINE

All classes (depth varies by class)

5

Post-Market Maintenance (Cl. 6)

Maintenance plan, problem tracking, and re-verification for all software changes after release

DEADLINE

All classes

IEC 62304–Specific Pain Points

IEC 62304–Specific Pain Points

The SOUP Documentation Spiral
The SOUP Documentation Spiral
The SOUP Documentation Spiral

Every modern medical device uses dozens of third-party software components—operating systems, libraries, frameworks, encryption modules. IEC 62304 requires documented requirements, risk assessments, and anomaly reviews for each. Your team tracks 80 SOUP items in spreadsheets. A critical library updates. Three months later, an auditor finds the SOUP list still references the old version. The gap cascades into your risk file.

The Safety Classification Reclassification
The Safety Classification Reclassification
The Safety Classification Reclassification

A Notified Body questions your Class A classification during audit. The software implements a risk control measure—that should be Class C. Every downstream document—development plan, verification strategy, test reports—was scoped to Class A rigor. Reclassification means rebuilding months of documentation against higher-rigor requirements under audit pressure.

The Traceability Dead End
The Traceability Dead End
The Traceability Dead End

FDA reviewers request requirement-to-test traceability for a 510(k) submission. Your requirements live in a Word document. Test results sit in a separate QA system. SOUP records are in a spreadsheet. Architecture diagrams are in a design tool. No single thread connects a patient safety requirement through architecture, implementation, and verification. Manual reconstruction takes weeks and still produces gaps.

The Multi-Supplier Evidence Burden
The Multi-Supplier Evidence Burden
The Multi-Supplier Evidence Burden

Your device integrates software from four component suppliers—each with their own development practices, documentation formats, and release cadences. IEC 62304 requires you to demonstrate lifecycle control for every supplier component. One supplier delivers a PDF. Another sends an Excel matrix. A third provides nothing. Consolidating multi-tier supply chain transparency for a single technical file becomes a full-time project.

Certivo In Action

Certivo in Action IEC 62304 Workflow

GET EVIDENCE IN

Collect SOUP Declarations and Lifecycle Evidence from Every Software Supplier—Without the Chasing

CORA launches targeted campaigns to collect SOUP documentation, safety classification evidence, and software lifecycle artifacts from component suppliers, follows up automatically, and accepts responses in any format.

  • Launch SOUP evidence campaigns to all software suppliers with one click

  • CORA-powered outreach in suppliers' native languages

  • Accept any format: PDFs, Excel, XML exports, freeform documentation packages

  • Track response rates and escalate non-responders automatically

GET EVIDENCE IN

Collect SOUP Declarations and Lifecycle Evidence from Every Software Supplier—Without the Chasing

CORA launches targeted campaigns to collect SOUP documentation, safety classification evidence, and software lifecycle artifacts from component suppliers, follows up automatically, and accepts responses in any format.

  • Launch SOUP evidence campaigns to all software suppliers with one click

  • CORA-powered outreach in suppliers' native languages

  • Accept any format: PDFs, Excel, XML exports, freeform documentation packages

  • Track response rates and escalate non-responders automatically

MAKE SENSE OF IT

Know Instantly When SOUP Components Carry Unassessed Risk

CORA extracts software component data to version and CVE level, validates against your safety classification requirements, and flags documentation gaps automatically.

  • CORA parses supplier declarations to extract component names, versions, known vulnerabilities, and functional specifications

  • Automatic validation against safety classification requirements for each component

  • Real-time alerts when SOUP updates or new CVEs affect your device

  • BOM-level compliance intelligence mapping software architecture to supplier evidence

MAKE SENSE OF IT

Know Instantly When SOUP Components Carry Unassessed Risk

CORA extracts software component data to version and CVE level, validates against your safety classification requirements, and flags documentation gaps automatically.

  • CORA parses supplier declarations to extract component names, versions, known vulnerabilities, and functional specifications

  • Automatic validation against safety classification requirements for each component

  • Real-time alerts when SOUP updates or new CVEs affect your device

  • BOM-level compliance intelligence mapping software architecture to supplier evidence

PROVE COMPLIANCE OUT

Generate Audit-Ready Technical Files in Hours, Not Months

Produce complete IEC 62304 traceability documentation and SOUP assessment packages instantly from validated supplier data.

  • One-click SOUP assessment reports with full version and risk documentation

  • Pre-formatted traceability matrices linking requirements to architecture to verification

  • Regulator-specific templates for FDA 510(k), EU MDR technical files, and notified body audits

  • Complete audit trail for every validation, classification decision, and supplier response

PROVE COMPLIANCE OUT

Generate Audit-Ready Technical Files in Hours, Not Months

Produce complete IEC 62304 traceability documentation and SOUP assessment packages instantly from validated supplier data.

  • One-click SOUP assessment reports with full version and risk documentation

  • Pre-formatted traceability matrices linking requirements to architecture to verification

  • Regulator-specific templates for FDA 510(k), EU MDR technical files, and notified body audits

  • Complete audit trail for every validation, classification decision, and supplier response

GET EVIDENCE IN

Collect SOUP Declarations and Lifecycle Evidence from Every Software Supplier—Without the Chasing

CORA launches targeted campaigns to collect SOUP documentation, safety classification evidence, and software lifecycle artifacts from component suppliers, follows up automatically, and accepts responses in any format.

  • Launch SOUP evidence campaigns to all software suppliers with one click

  • CORA-powered outreach in suppliers' native languages

  • Accept any format: PDFs, Excel, XML exports, freeform documentation packages

  • Track response rates and escalate non-responders automatically

MAKE SENSE OF IT

Know Instantly When SOUP Components Carry Unassessed Risk

CORA extracts software component data to version and CVE level, validates against your safety classification requirements, and flags documentation gaps automatically.

  • CORA parses supplier declarations to extract component names, versions, known vulnerabilities, and functional specifications

  • Automatic validation against safety classification requirements for each component

  • Real-time alerts when SOUP updates or new CVEs affect your device

  • BOM-level compliance intelligence mapping software architecture to supplier evidence

PROVE COMPLIANCE OUT

Generate Audit-Ready Technical Files in Hours, Not Months

Produce complete IEC 62304 traceability documentation and SOUP assessment packages instantly from validated supplier data.

  • One-click SOUP assessment reports with full version and risk documentation

  • Pre-formatted traceability matrices linking requirements to architecture to verification

  • Regulator-specific templates for FDA 510(k), EU MDR technical files, and notified body audits

  • Complete audit trail for every validation, classification decision, and supplier response

One Supplier Submission. Validation Against All 253 SVHCs. Audit-Ready in Hours.

One Supplier Submission. Validation Across All SOUP Components. Audit-Ready in Hours.

One Supplier Submission. Validation Across All SOUP Components. Audit-Ready in Hours.

One Supplier Submission. Validation Across All SOUP Components. Audit-Ready in Hours.

One Supplier Submission. Validation Across All SOUP Components. Audit-Ready in Hours.

Certivo reads supplier documentation, extracts software component data to version-level precision, validates against your safety classification requirements, and generates regulator-ready evidence automatically. When suppliers release updates or new CVEs emerge, Certivo reassesses your portfolio and alerts you—before auditors ask.

Certivo reads supplier documentation, extracts software component data to version-level precision, validates against your safety classification requirements, and generates regulator-ready evidence automatically. When suppliers release updates or new CVEs emerge, Certivo reassesses your portfolio and alerts you—before auditors ask.

Certivo reads supplier documentation, extracts software component data to version-level precision, validates against your safety classification requirements, and generates regulator-ready evidence automatically. When suppliers release updates or new CVEs emerge, Certivo reassesses your portfolio and alerts you—before auditors ask.

SOUP Extraction

SOUP Extraction

Safety Classification Validation

Safety Classification Validation

Traceability Matrix Generator

Traceability Matrix Generator

CVE Monitoring

CVE Monitoring

Regulatory Intelligence Alerts

Regulatory Intelligence Alerts

Features Tabs

Declaration Collection

AI Document Parsing

Continuous Compliance Monitoring

Audit Response

Regulatory Submissions

Declaration Collection

Certivo's automated supplier data collection campaigns achieve 95% response rates vs. 20–30% with manual outreach.

  • Targeted campaigns by software component type, supplier tier, or device classification

  • Multi-language outreach in suppliers' native languages

  • Intelligent follow-up sequences adapting to supplier behavior

  • Format-agnostic: PDFs, Excel, structured exports, freeform documentation packages

95%

Supplier Response Rate

AI Document Parsing

Every SOUP declaration parsed to component version level automatically—no manual data entry.

  • Deep extraction of component names, version numbers, license types, functional specifications

  • Parses SBOM exports, supplier quality documentation, and proprietary templates

  • Multi-language document processing across global supply chains

  • Anomaly detection for inconsistent or outdated SOUP declarations

99.2%

Extraction Accuracy

Continuous Compliance Monitoring

Always validated against current vulnerability databases and regulatory requirements—not your last audit.

  • Automatic sync with CVE databases and regulatory intelligence feeds throughout the year

  • Safety classification validation against IEC 62304 clause requirements

  • Proactive alerts when new vulnerabilities or regulatory changes affect your portfolio

  • Historical tracking of SOUP component status changes and version migrations

Real-Time

CVE and Regulatory Sync

Audit Response

Generate complete IEC 62304 traceability packages in hours instead of 4–6 weeks.

  • One-click SOUP assessment packages with full component documentation

  • Traceability matrices meeting FDA and EU MDR requirements

  • Supplier evidence chain with complete provenance tracking

  • Response tracking for audit deadlines and notified body requests

4 hours

To Audit-Ready Package

Regulatory Submissions

Pre-validated documentation turns technical file assembly from burden to streamlined workflow.

  • Pre-formatted exports compatible with FDA eCopy and EU MDR GSPR formats

  • Safety classification mapping and risk management documentation

  • Multi-device portfolio support for platform-based product families

  • Centralized compliance data backbone for lifecycle evidence across product lines

Batch

Multi-Device Documentation

Declaration Collection

AI Document Parsing

Continuous Compliance Monitoring

Audit Response

Regulatory Submissions

Declaration Collection

Certivo's automated supplier data collection campaigns achieve 95% response rates vs. 20–30% with manual outreach.

  • Targeted campaigns by software component type, supplier tier, or device classification

  • Multi-language outreach in suppliers' native languages

  • Intelligent follow-up sequences adapting to supplier behavior

  • Format-agnostic: PDFs, Excel, structured exports, freeform documentation packages

95%

Supplier Response Rate

Declaration Collection

AI Document Parsing

Continuous Compliance Monitoring

Audit Response

Regulatory Submissions

Declaration Collection

Certivo's automated supplier data collection campaigns achieve 95% response rates vs. 20–30% with manual outreach.

  • Targeted campaigns by software component type, supplier tier, or device classification

  • Multi-language outreach in suppliers' native languages

  • Intelligent follow-up sequences adapting to supplier behavior

  • Format-agnostic: PDFs, Excel, structured exports, freeform documentation packages

95%

Supplier Response Rate

Related Regulations

Related Regulations

EU MDR 2017/745

IEC 62304 is the harmonized standard for MDR software GSPR requirements

Combined Value

Single evidence collection satisfies both IEC 62304 and MDR Annex I

EU MDR 2017/745

IEC 62304 is the harmonized standard for MDR software GSPR requirements

Combined Value

Single evidence collection satisfies both IEC 62304 and MDR Annex I

FDA 21 CFR Part 820

IEC 62304 satisfies FDA design control requirements for software

Combined Value

AI-native compliance automation validates against both FDA and IEC frameworks

FDA 21 CFR Part 820

IEC 62304 satisfies FDA design control requirements for software

Combined Value

AI-native compliance automation validates against both FDA and IEC frameworks

ISO 14971

IEC 62304 Clause 7 requires ISO 14971–aligned software risk management

Combined Value

Unified risk file generation from one supplier evidence set

ISO 14971

IEC 62304 Clause 7 requires ISO 14971–aligned software risk management

Combined Value

Unified risk file generation from one supplier evidence set

ISO 13485

Quality management system under which IEC 62304 processes operate

Combined Value

Integrated PLM ERP compliance thread linking QMS to software lifecycle

ISO 13485

Quality management system under which IEC 62304 processes operate

Combined Value

Integrated PLM ERP compliance thread linking QMS to software lifecycle

IEC 81001-5-1

Health software cybersecurity standard referenced by IEC 62304 Edition 2

Combined Value

Combined cybersecurity and lifecycle documentation from shared supplier data

IEC 81001-5-1

Health software cybersecurity standard referenced by IEC 62304 Edition 2

Combined Value

Combined cybersecurity and lifecycle documentation from shared supplier data

IEC 82304-1

Health software product standard that references IEC 62304 lifecycle processes

Combined Value

Digital passport and traceability systems supporting both standards

IEC 82304-1

Health software product standard that references IEC 62304 lifecycle processes

Combined Value

Digital passport and traceability systems supporting both standards

Managing IEC 62304 alongside related standards eliminates duplicate supplier requests. Certivo validates one submission against multiple frameworks.

Managing IEC 62304 alongside related standards eliminates duplicate supplier requests. Certivo validates one submission against multiple frameworks.

Managing IEC 62304 alongside related standards eliminates duplicate supplier requests. Certivo validates one submission against multiple frameworks.

Return on Investment

Return on Investment

80%
80%
80%
80%
Reduction in Documentation Labor
Reduction in Documentation Labor
Reduction in Documentation Labor
From Manual Compilation to Exception Management

CORA extracts SOUP data and generates traceability matrices automatically. Your team focuses on risk decisions that need engineering judgment—not manual evidence assembly across spreadsheets and email chains.

4 Hours
4 Hours
4 Hours
4 Hours
To Audit-Ready Package
To Audit-Ready Package
To Audit-Ready Package
Technical File Assembly Acceleration

Generate complete, validated IEC 62304 documentation packages in hours—not the 4–6 weeks of manual compilation across siloed systems.

Real-Time
Real-Time
Real-Time
Real-Time
Regulatory Intelligence
Regulatory Intelligence
Regulatory Intelligence
Proactive Compliance Monitoring

When Edition 2 publishes, new CVEs surface, or supplier components update, Certivo reassesses your portfolio instantly. Know which products require documentation updates before auditors ask.

Key Statistics

Key Statistics

5

5

5

5

Core lifecycle clauses tracked with continuous compliance monitoring

Core lifecycle clauses tracked with continuous compliance monitoring

99.2%

99.2%

99.2%

99.2%

Software component extraction accuracy from supplier declarations

Software component extraction accuracy from supplier declarations

95%

95%

95%

95%

Supplier response rate with CORA-powered automated campaigns

Supplier response rate with CORA-powered automated campaigns

Frequently Asked Questions

What products and companies are subject to IEC 62304 obligations?

Any company developing or maintaining software that is a medical device (SaMD) or part of a medical device must comply. This includes device manufacturers, contract software developers, and suppliers of software components integrated into regulated devices. The standard applies globally—it is harmonized under EU MDR, recognized by the FDA as a consensus standard, and referenced by regulators in Japan, Canada, Australia, and emerging markets. CORA helps teams manage IEC 62304 evidence collection regardless of which regulatory pathway the device follows.

What are the consequences of IEC 62304 non-compliance?

Non-compliance with IEC 62304 can result in rejection of FDA 510(k) or PMA submissions, CE marking refusal by Notified Bodies under EU MDR, and field action requirements for marketed devices. Software-related issues contribute to 12–33% of medical device recalls. In the EU, failure to demonstrate conformity with harmonized software lifecycle standards can result in fines and market withdrawal under national enforcement laws. Certivo's continuous compliance monitoring ensures documentation stays current between audits.

How does Certivo track changes to IEC 62304 and related regulatory requirements?

Certivo maintains continuous regulatory intelligence and horizon scanning aligned with IEC publications, FDA guidance updates, and EU MDR harmonized standard revisions. When Edition 2 publishes—introducing rigor levels, AI/ML requirements, and expanded health software scope—CORA reassesses your portfolio and maps existing safety classifications to the new framework, triggering updated documentation workflows automatically.

What documentation formats does Certivo accept from software suppliers?

Certivo accepts any format: PDF declarations, Excel spreadsheets, SBOM exports, XML files, structured quality documentation packages, and freeform responses. CORA's AI document parsing extracts component data regardless of format or language, eliminating the need to standardize supplier inputs across your multi-tier supply chain. This format-agnostic approach is critical for IEC 62304 compliance because SOUP suppliers rarely deliver evidence in a single standardized template.

Does Certivo support both IEC 62304 and related medical device standards simultaneously?

Yes. Certivo validates supplier evidence against IEC 62304, EU MDR GSPR requirements, FDA 21 CFR Part 820 design controls, ISO 14971 risk management, and IEC 81001-5-1 cybersecurity requirements simultaneously. The same supplier submission feeds validation across all applicable frameworks through a centralized compliance data backbone—eliminating duplicate collection campaigns and ensuring consistency across regulatory filings for multiple markets.

Ready to Automate IEC 62304 Compliance?

Ready to Automate IEC 62304 Compliance?

Ready to Automate IEC 62304 Compliance?

Ready to Automate IEC 62304 Compliance?

See how Certivo's AI-native compliance automation transforms software lifecycle documentation from reactive scrambling to proactive audit readiness.

See how Certivo's AI-native compliance automation transforms software lifecycle documentation from reactive scrambling to proactive audit readiness.

See how Certivo's AI-native compliance automation transforms software lifecycle documentation from reactive scrambling to proactive audit readiness.

See how Certivo's AI-native compliance automation transforms software lifecycle documentation from reactive scrambling to proactive audit readiness.

Book a Demo

Book a Demo

Talk to an Expert

Talk to an Expert

Every account includes a dedicated compliance expert alongside CORA.