Verification and validation: Differences and definitions
What is the difference between verification and validation, and how are these terms defined? Even standards and regulations use the terms incorrectly or misleadingly. This article
DetailsIEC 62304 is a European harmonized* standard for “medical device software.” It is entitled “Medical device software – Software life-cycle processes” and sets minimum requirements for processes such as the development and maintenance of software.
Content
On this page, you will find:
* IEC 62304 was harmonized under the MDD and IVDD and is meanwhile harmonized under the MDR and IVDR.
IEC 62304 is applicable for
Because IEC 82304-1 references the standard, IEC 62304 is even relevant for health software.
Qualification and classification
Please also note the articles on life-cycle activities under point 2.
Particular requirements for software
The following articles are grouped according to the chapters of IEC 62304.
Chapter 5.1: Design and development planning
The first requirement of the standard is to create a design and development plan. These articles are worth reading in this context:
Chapter 5.2: Requirements
The manufacturer must derive the software requirements from the requirements of the device or the stakeholder requirements.
Chapters 5.3 and 5.4: Architecture
In the architecture, the manufacturer determines the “blueprint.”
Chapters 5.5 to 5.7: Implementation and verification
The software must then be implemented and verified in accordance with the architecture. Validation is not covered by IEC 62304 but by IEC 82304-1.
Chapter 5.8: Release
Development and maintenance conclude with the release, which should not be confused with the product release:
Further requirements and processes of the standard
Medical devices that are and contain software and that have external interfaces such as USB or ethernet as subject to IT security requirements. Please note the requlatory requirements related to IT security.
In Annex I, the MDR and IVDR medical device regulations formulate the so-called “General Safety and Performance Requirements” (GSPR).
One of these requirements is that “For devices that incorporate software or for software that are devices in themselves,” the
“software shall be developed and manufactured in accordance with the state of the art taking into account the principles of development life cycle, risk management, including information security, verification and validation.”
This is a statutory requirement. A breach of this can be punished with fines and imprisonment as defined in national laws such as the German MDCG.
Manufacturers of medical devices should demonstrate conformity with these requirements by complying with harmonized standards.
The IEC 62304 standard is the standard specifically harmonized for life-cycle processes. Another standard is IEC 82304-1.
The FDA recognizes IEC 62304 as a “Consensus Standard,” but it does not expect conformity with this standard. However, the authority does have comparable requirements in its guidelines on software validation, for example.
Some test centers offer “certification according to IEC 62304”. Manufacturers should be aware of the limitations of these certifications:
The Johner Institute does not generally advise against certification in accordance with IEC 62304. But everyone should be aware of the “probative value” of these certificates.
Benefit from the support of the Johner Institute:
Contact us right away so that we can discuss the next steps together. This will ensure that your “approval” is a success and that your devices are quickly launched on the market.
What is the difference between verification and validation, and how are these terms defined? Even standards and regulations use the terms incorrectly or misleadingly. This article
DetailsThe qualification and classification of IVD software determine how and how quickly IVD manufacturers can bring their software to market and what costs arise for “approval.” This article will help you correctly qualify and classify IVD software, thereby avoiding regulatory problems and the resulting costs and delays.
DetailsLaws and standards require medical device manufacturers to compile a Software Bill of Materials, the SBOM. However, standardized SBOM formats are not always sufficient to meet these requirements. In particular, medical device manufacturers who do not supply and use SBOMs for their software are no longer accepted in the market. Here are the reasons.
DetailsThe Medical Device Regulation (MDR) (like the Medical Device Directive (MDD) and thus the Medical Device Act before it) requires manufacturers to comply with life cycle processes for their software. IEC 62304 and IEC 82304 also refer to software life cycle processes. But what is a software life cycle?
1. Documentation Level: End of Level of Concern On June 14, 2023, the FDA released the guidance document Content of Premarket Submissions for Device Software Functions. This document replaces the guidance document introducing the Level of Concern and only distinguishes between two classes.
DetailsSoftware maintenance is the phase in which software is further developed, e.g., with the objective of According to the FDA, 79% of all bugs occur during software maintenance. Accordingly, some regulations address this topic.
DetailsGLP (Good Laboratory Practice) defines requirements for a quality assurance system for non-clinical health and environmental safety tests. It also describes the organizational procedure and conditions under which laboratory tests are planned, carried out, and monitored. GLP also covers the record and reporting of. In this article, you can read which requirements medical device manufacturers…
DetailsUnderstandably, laws and standards also require IT security for legacy devices. However, the way in which these requirements are formulated often leads to confusion. For example, legislators and standard committees have been unable to agree on common definitions. One definition refers to the IT security of legacy devices, another to the IT security of old…
DetailsMDCG published guideline MDCG 2023-4 in October 2023 entitled “Medical Device Software (MDSW) – Hardware combinations – Guidance on MDSW intended to work in combination with hardware or hardware components.”
Both the FDA and IEC 62304 recognize software developed by third parties. They refer to Off-the-Shelf Software (OTS) and Software Of Unknown Provenance (SOUP). What is the difference between OTS and SOUP? What do they have in common? What legal requirements do they have to meet? This article provides answers.
Details