Software as a Medical Device (SaMD): Regulatory & Development Guide

Software as a Medical Device (SaMD) has fundamentally changed the clinical landscape. From AI-driven diagnostic image scanning to standalone smartphone apps used for real-time clinical decision-making, digital health tools are scaling faster than ever. However, understanding exactly how SaMD is regulated, classified, and maintained is critical to securing market access under current MHRA and EU Notified Body expectations.
Software as a Medical Device (SaMD)

Updated: 20th June 2026

Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)

What is SaMD?

According to the International Medical Device Regulators Forum (IMDRF), SaMD is defined as software intended to perform one or more medical purposes without being part of a hardware medical device. Crucially, SaMD operates independently of any physical diagnostic or therapeutic hardware—it runs on general-purpose computing platforms, mobile devices, or in cloud environments.

Common examples of standalone medical software include:

  • Mobile apps that actively monitor or calculate insulin dosages for chronic diabetes management.

  • Computer-aided detection (CAD) software that analyzes medical images to identify malignant tumors.

  • Machine learning algorithms that process patient data streams to provide specific treatment recommendations to clinicians.

Key Architectural Note: If your software controls or directly drives a physical hardware medical device, it is typically classified as Software in a Medical Device (SiMD) or embedded firmware. If you are unsure which framework your product falls under, specialized SaMD consulting can help map your architecture before you commit to development.

Software as a Medical Device (SaMD) infographic explaining the IMDRF definition, examples and regulatory considerations.

Regulatory Considerations for SaMD

Navigating international regulatory frameworks remains one of the most significant hurdles for digital health startups and established manufacturers alike.

1. SaMD Under the EU MDR (2017/745)

Under the European Medical Device Regulation (MDR), the rules for software classification became substantially more stringent, particularly through the introduction of Rule 11. Most standalone software intended for diagnostic or therapeutic decision-making is automatically pushed out of Class I and into Class IIa, IIb, or Class III. This means that self-declaration is rarely an option; the vast majority of SaMD products entering the EU require a full Notified Body audit.

2. SaMD Under UK Regulations (MHRA)

In Great Britain, standalone software must comply with the Medical Devices Regulations 2002 and secure a UKCA mark. The MHRA places heavy emphasis on robust post-market monitoring and lifecycle risk management. Manufacturers must demonstrate strict adherence to ISO 14971 to identify and continuously mitigate software anomalies throughout the entire product lifecycle.

Technical and Development Challenges

  • Developing regulatory-compliant medical software requires balancing agile development speeds with rigid quality management guidelines:

    • Data Privacy and Cybersecurity: SaMD must adhere to strict data security frameworks, incorporating GDPR compliance by design alongside secure encryption protocols for transmitting patient health data.

    • Lifecycle Control (IEC 62304): Regulators require your software code to be built under a controlled lifecycle. For a comprehensive breakdown of software safety classes (Class A, B, C) and technical file documentation, see our complete guide on IEC 62304 compliance 

Infographic explaining the regulatory considerations for Software as a Medical Device (SaMD), including EU MDR Rule 11, UK MHRA requirements, cybersecurity, GDPR, ISO 14971 risk management and IEC 62304 software lifecycle controls.

How Specialized SaMD Consulting Drives Commercial Success

Errors made during the initial classification and design phases can lead to millions in lost development hours or catastrophic Notified Body rejections. Partnering with an experienced compliance team streamlines your route to market.

At Patient Guard, we provide end-to-end SaMD consulting to guide developers through complex digital health frameworks. Our services include:

  • Precise qualification and risk classification under EU MDR (Rule 11) and MHRA guidelines.

  • Establishing an ISO 13485 compliant Quality Management System (QMS) optimized for software lifecycles.

  • Compilation of audit-ready Technical Documentation, including software development plans, verification protocols, and traceability matrices.

  • Strategic alignment with evolving requirements, such as the EU AI Act and FDA digital health guidelines.

SaMD Regulatory & Compliance FAQ

Software qualifies as SaMD under the EU MDR if it has a specific medical intended purpose, such as diagnosing, preventing, monitoring, predicting, or treating a disease or injury. If the software merely logs data, manages administrative hospital tasks, or tracks general fitness, it does not qualify as a medical device.

SaMD can be updated as frequently as your development cycle requires, but you must implement a robust configuration and change management process under IEC 62304. Minor bug fixes or security patches rarely require regulatory re-submission, but any update that alters the core algorithm, changes the intended use, or impacts clinical safety requires a formal impact assessment and may require notifying your Notified Body or the MHRA.

Yes, AI and machine learning are increasingly common in SaMD, particularly for diagnostic imaging and triage. However, AI software faces intense regulatory scrutiny regarding algorithmic bias, transparency, and data training validation. Manufacturers must align their development with emerging frameworks like the EU AI Act and specific FDA/MHRA guiding principles for Good Machine Learning Practice (GMLP).

Cybersecurity is a core component of your technical file. Regulators expect manufacturers to implement secure lifecycle processes, perform continuous vulnerability testing, establish strict user access controls, and provide a software bill of materials (SBOM). You must demonstrate that your software is resilient against data breaches and unauthorized access that could compromise patient safety.

References

This guide is based on the following international standards, legislation and official regulatory guidance relating to Software as a Medical Device (SaMD), medical device software regulation and lifecycle compliance.

Organisation Reference Why it's relevant
International Medical Device Regulators Forum (IMDRF) Software as a Medical Device (SaMD): Key Definitions Provides the internationally recognised definition of Software as a Medical Device (SaMD), which forms the foundation of regulatory approaches adopted by authorities worldwide.
European Union Regulation (EU) 2017/745 on Medical Devices (MDR) Establishes the European regulatory framework for medical devices, including standalone software and the classification requirements applied under Rule 11.
Medicines and Healthcare products Regulatory Agency (MHRA) Software and Artificial Intelligence (AI) as a Medical Device Provides UK regulatory guidance on Software as a Medical Device (SaMD), AI-enabled medical devices and software classification.
International Electrotechnical Commission (IEC) IEC 62304 – Medical Device Software – Software Life Cycle Processes Defines the internationally recognised software lifecycle processes expected during the development, maintenance and validation of medical device software.
International Organization for Standardization (ISO) ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices Provides the internationally recognised framework for identifying, evaluating and controlling risks associated with medical device software throughout its lifecycle.
U.S. Food and Drug Administration (FDA) Software as a Medical Device (SaMD) Explains the FDA's regulatory approach to standalone medical device software and its adoption of the IMDRF SaMD framework.

Software regulation, international standards and regulatory guidance continue to evolve. Manufacturers should always consult the latest published legislation, standards and official guidance when developing, classifying and maintaining Software as a Medical Device throughout its lifecycle.

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

Patient Guards Related Services

Patient Guards Regulatory Tools

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:
Posted on Google Google
Munna P profile picture
Munna P
52 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.
Posted on Google Google
Peter Reeve profile picture
Peter Reeve
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.
Posted on Google Google
Derek Timm profile picture
Derek Timm
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South Lımıted
Posted on Google Google
BMSCriticalCare profile picture
BMSCriticalCare
116 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,
Posted on Google Google
Thomson Software profile picture
Thomson Software
787 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.
Verified by Trustindex
Trustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more

Most Popular

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

IVDR Performance Evaluation Explained: A Complete Guide for Manufacturers

Performance Evaluation is one of the most important requirements under the EU In Vitro Diagnostic Regulation (IVDR). Every manufacturer must demonstrate that their in vitro diagnostic medical device achieves its intended purpose through robust scientific validity, analytical performance and clinical performance evidence. This guide explains every stage of IVDR Performance Evaluation, including Performance Evaluation Plans (PEPs), Performance Evaluation Reports (PERs), Post-Market Performance Follow-up (PMPF) and how Performance Evaluation supports successful CE marking under Regulation (EU) 2017/746.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.