Pre-market Services

Software Lifecycle Management

Support compliant software development and maintenance throughout the product lifecycle with processes aligned to regulatory and quality requirements. Whether you are developing a medical device, an electronic health record system or wellness application, lifecycle management is important.

Services

  • Software lifecycle process implementation
  • IEC 62304 compliance support
  • IEC 5338 compliance support
  • Software maintenance and change management
  • Software risk management support
  • Configuration and release management
  • Software documentation and traceability
  • Verification and validation planning
  • Software lifecycle audit preparation
Our Specialty

What Do We Offer?

Software lifecycle management is a core requirement for healthcare related software including medical device software, AI-enabled systems, electronic health record systems, and wellness applications. Manufacturers must demonstrate that software is developed, maintained, and updated through controlled processes that support safety, performance, and regulatory compliance.

We support organisations in implementing software lifecycle processes aligned with IEC 62304, the MDR, IVDR, FDA guidance, EHDS, AI Act, CRA, and related international standards. This includes definition of your product’s lifecycle from development through, maintenance processes and ultimately decommissioning. We cover aspects to ensure traceability, risk management, cybersecurity management and delivery of the appropriate software documentation.

Our approach focuses on integrating lifecycle management into practical development workflows. Effective software processes support compliance while helping organisations manage updates, changes, cybersecurity considerations, and long-term product maintenance.

Relevant Resources - EU

  • MDR 2017/745 (EU Medical Device Regulation)
  • IVDR 2017/746 (EU In Vitro Diagnostic Medical Device Regulation)
  • AI Act 2024/1689 (EU Artificial Intelligence Act)
  • EHDS 2025/327 (European Health Data Space Regulation)
  • CRA 2024/2847 (Cyber Resilience Act)
  • MDCG 2019-16 Guidance on Cybersecurity for Medical Devices
  • MDCG 2020-3 Significant Changes Regarding Transitional Provisions under Article 120 MDR

Relevant Resources - US

  • FDA Guidance – Content of Premarket Submissions for Device Software Functions
  • FDA Guidance – Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions
  • FDA Guidance – Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
  • FDA Artificial Intelligence-Enabled Medical Devices
  • FDA Digital Health Policy Navigator

Relevant Resources - Others

  • IEC 62304 – Medical Device Software Lifecycle Processes
  • IEC 82304-1 – Health Software Product Safety
  • IEC 81001-5-1 – Health Software and Health IT Systems Security Activities
  • ISO 14971 – Medical Device Risk Management
  • ISO 13485 – Quality Management Systems for Medical Devices
  • IMDRF Software as a Medical Device (SaMD) Framework Documents
  • IMDRF SaMD: Application of Quality Management System
  • IMDRF SaMD: Clinical Evaluation
  • Health Canada – Software as a Medical Device Guidance
  • TGA (Australia) – Software-Based Medical Devices Guidance
Blog Hub

Latest Insights & Updates

Explore our blog posts on MDR, IVDR, and EU AI Act medical device compliance to stay ahead of regulatory changes.

Frequently Asked Questions

Find answers to common questions about our services, compliance processes, and how we can assist your business.

Do I need a Predetermined Change Control Plan (PCCP) for my AI/ML medical device?

A PCCP is not mandatory, but it is the FDA-recognized mechanism (finalized in the December 2024 guidance) that allows you to make pre-specified modifications to an AI/ML-enabled device after authorization without a new 510(k) submission. If your model will be retrained, updated, or refined post-market, including a PCCP in your original submission can save months or years of regulatory rework. The PCCP must define the specific modifications, the modification protocol, and an impact assessment. Within the EU we also expect manufacturers to be able to apply PCCP’s for medical devices and AI Systems.

What is software lifecycle management for medical devices?

Software lifecycle management is the process of planning, developing, maintaining, updating, and retiring medical device software through controlled procedures. It helps manufacturers demonstrate that software remains safe, effective, and compliant throughout its entire lifecycle rather than only at the point of market entry.

Do medical device manufacturers need to comply with IEC 62304?

In most cases, yes. IEC 62304 is the internationally recognised standard for medical device software lifecycle processes and is widely used to demonstrate structured software development, maintenance, risk management, configuration management, and problem resolution activities for software-based medical devices.

Does IEC 62304 apply to Software as a Medical Device (SaMD)?

Yes. IEC 62304 applies to both standalone Software as a Medical Device (SaMD) and software embedded within medical devices. The standard provides a framework for managing software activities throughout development, maintenance, and eventual retirement regardless of how the software is deployed.

How does software lifecycle management support MDR and IVDR compliance?

Software lifecycle management provides the processes and documentation needed to demonstrate compliance with MDR and IVDR requirements. Traceability, risk management, software maintenance, verification, validation, and change control activities all contribute to demonstrating that software remains safe and performs as intended.

What documentation is required for medical device software development?

The exact documentation depends on the product and regulatory pathway, but commonly includes software development plans, software requirements specifications, architecture documentation, risk management files, verification and validation records, cybersecurity documentation, maintenance procedures, and traceability records linking requirements to testing and risk controls.

How should software changes be managed after market release?

Software changes should be managed through formal change control processes that assess potential impacts on safety, performance, cybersecurity, regulatory compliance, and documentation. Effective change management helps organisations determine whether updates require additional validation, regulatory notifications, or revised risk assessments.

What is software traceability and why is it important?

Software traceability is the ability to link requirements, risks, design decisions, development activities, testing, and released functionality throughout the software lifecycle. It helps demonstrate compliance, supports audits and regulatory reviews, and provides evidence that requirements have been implemented and verified appropriately.

How does cybersecurity fit into software lifecycle management?

Cybersecurity should be integrated throughout the software lifecycle rather than treated as a separate activity. Secure development practices, threat modelling, vulnerability management, software updates, security testing, and post-market monitoring all contribute to maintaining software security throughout the product lifecycle.

What happens when a medical device software product reaches end of life?

Software lifecycle management includes controlled decommissioning and end-of-life planning. Manufacturers should establish processes for managing product retirement, supporting customers, maintaining records, addressing cybersecurity considerations, and ensuring regulatory obligations continue to be met where applicable.

Can agile development be used for regulated medical device software?

Yes. Agile development methodologies can be used for regulated medical device software provided appropriate controls, documentation, traceability, risk management, and verification activities are maintained. Many organisations successfully integrate agile practices within compliant software lifecycle frameworks.

Can MedQAIR help implement software lifecycle processes?

Yes. MedQAIR supports organisations in establishing and improving software lifecycle processes aligned with IEC 62304, MDR, IVDR, FDA expectations, and related standards. This includes lifecycle planning, software documentation, traceability, risk management integration, cybersecurity considerations, maintenance activities, and change management processes.

We already have a device on the market. Can you still help?

Yes. Software lifecycle obligations continue throughout the product’s operational life. MedQAIR supports manufacturers with software maintenance processes, lifecycle documentation updates, change management, cybersecurity activities, audits, regulatory updates, and broader post-market software compliance activities.

Book a Free 30-Minute Consultation

Schedule a Meeting With Our Experts

Get a Free Consultation