Eclevar MedTech runs the evidence and regulatory programme for medical device software under EU MDR 2017/745 and the EU AI Act: qualification, Rule 11 classification, clinical evaluation, IEC 62304 lifecycle alignment, cybersecurity and post-market performance, built by clinicians and former Notified Body reviewers.
Platinum Award 2026
Top prize in the xShare x European CRO Federation "EHDS & Clinical Research" Open Call, awarded to Eclevar MedTech and its Milo Health platform, presented at the EUCROF 2026 conference in Amsterdam.
Horizon Europe · Grant Agreement No. 101136734 · Amsterdam, 2 Feb 2026
Device and software makers rely on Eclevar for a file that survives Notified Body review. Read all client success stories.


Before joining Eclevar MedTech, Dr Mark DaCosta spent years on the Notified Body side as a lead clinical reviewer at TÜV SÜD, where he assessed and certified several hundred devices under EU MDR, including software and active implantable systems in the highest risk classes. That experience changes how a SaMD file is built: we anticipate the questions a Notified Body will raise around Rule 11 reasoning, IEC 62304 documentation depth and the clinical validation of an algorithm, and structure the technical documentation to answer them before they are asked.
In the European Union, the term Software as a Medical Device (SaMD), coined by the IMDRF, maps onto the legal category of Medical Device Software (MDSW). Under MDCG 2019-11 (revised in 2025), software qualifies as a medical device when the manufacturer's intended purpose covers diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease or injury.
The decisive factor is the intended purpose, not the raw technical capability. How the software is positioned, labelled and marketed determines its regulatory status, which is exactly what a Notified Body examines first. Where a product sits at the boundary between MDR and IVDR, an early regulatory opinion prevents costly rework of the technical documentation later.
The revised MDCG 2019-11 also clarifies modular software: a medical purpose module inside a wider system, for example a decision-support module inside an electronic health record, must comply with MDR in its own right even when the surrounding platform does not.
Rule 11 in Annex VIII of EU MDR, read together with the IMDRF risk framework adopted in MDCG 2019-11, sets the risk class from the significance of the information the software provides and the seriousness of the clinical situation. In practice, Class I is rare and Notified Body involvement is the norm.
Software providing information used to take decisions with a diagnostic or therapeutic purpose. The baseline for most MDSW, and already triggers a Notified Body conformity assessment.
Software whose information could lead to a serious deterioration of health or a surgical intervention. Many monitoring, triage and treatment-planning tools land here, with deeper evidence expectations.
Software whose information may cause death or an irreversible deterioration of health. The highest evidence bar, with a full clinical investigation frequently required.
A defensible software dossier is a stack of aligned evidence, from the development lifecycle to the clinical validation of the output. Eclevar MedTech builds and connects every layer for the Notified Body review.
The lifecycle standard sets the required depth of planning, documentation, testing and quality control according to the software safety class. The class you assign drives how much evidence a reviewer expects for every unit and integration step.
For standalone health software, this standard covers product-level safety and security across the full product life, complementing the process view of IEC 62304 with product requirements, validation and accompanying documentation.
The clinical evaluation of software rests on a valid clinical association between the output and the targeted condition, technical (analytical) validation that the software processes input data correctly, and clinical validation that the output delivers the intended clinical benefit. We plan and evidence all three.
A software-specific risk management file that connects hazards, foreseeable misuse and residual risk to the clinical evaluation and the post-market plan, so the benefit-risk determination holds up end to end.
Use-related risk is central to software safety. We structure formative and summative usability evaluation so the user interface and the use environment are evidenced to the standard reviewers expect.
Security is a safety requirement for connected software. We align the security risk assessment, secure development and post-market security monitoring to the MDCG guidance and the applicable Annex I requirements.
If your SaMD includes AI or machine learning, a second framework applies on top of EU MDR. Any AI system that is itself a medical device, or a safety component of one, and that requires Notified Body assessment is automatically classified as high-risk under Article 6(1) of the EU AI Act. There is no separate AI risk-classification step: the status follows from the MDR route.
The two frameworks are complementary, not interchangeable. MDR governs whether the device is safe and performs as claimed; the AI Act governs how the AI was built, trained and governed: data governance, algorithmic transparency, bias testing, human oversight, AI-specific post-market monitoring and registration in the EU high-risk AI database. Compliance with IEC 62304 does not, on its own, satisfy these obligations.
For continuously learning systems, a predetermined change control plan lets you define in advance which model updates are permitted without a new conformity assessment, a critical piece of planning for any adaptive algorithm.
Documented MDSW qualification and Rule 11 classification with the IMDRF framework, MDR versus IVDR boundary opinions and a defensible intended-purpose statement your Notified Body can accept.
Clinical evaluation of software to MDCG 2020-1, with clinical investigation design where the class requires it, and the analytical and clinical validation of your algorithm built into a coherent plan.
ISO 13485 quality management aligned to IEC 62304 and IEC 82304-1, with risk management, usability and cybersecurity structured for the technical documentation review.
Gap assessment against the high-risk obligations, data governance and human-oversight architecture, bias-testing plans and a predetermined change control plan for adaptive models.
Post-market surveillance and PMCF designed for software, with real-world performance monitoring, update and change management, and vigilance connected back to the clinical evaluation.
Registry and real-world data strategies that support performance claims, indication extension and the continued certification of legacy software under EU MDR.
Illustrative of the software programmes Eclevar MedTech supports, from AI-based diagnostic tools to connected monitoring platforms. Figures reflect the respective programme documentation.
A developer of an AI radiology triage tool needed a single evidence plan covering both frameworks. Eclevar MedTech structured the clinical evaluation to MDCG 2020-1, built the analytical and clinical validation, and mapped the high-risk AI obligations onto the existing IEC 62304 documentation so the two files reinforced rather than duplicated each other.
For a remote monitoring platform, Eclevar MedTech designed a post-market clinical follow-up study on MILO, capturing real-world performance and patient-reported outcomes at scale. The design linked update and change management to the clinical evaluation so software releases stayed inside a controlled, documented evidence loop.
Generating clinical and post-market evidence for software needs an equally rigorous data backbone. Eclevar MedTech runs MILO EDC, its proprietary electronic data capture platform, fully aligned to FDA 21 CFR Part 11 and the GDPR. MILO brings the eCRF, automated ePRO surveys and long-term real-world data collection into a single, audit-ready ecosystem, built to sustain patient engagement across multi-year software follow-up.
Whitepapers, client testimonials and publications produced by our teams and partners (BSI, TÜV SÜD, RegenLab).
Written with Notified Body BSI: a practical reading of the clinical evidence expectations under EU MDR 2017/745, directly relevant to any software file.
Eclevar MedTech manages RegenLab's PMCF programme on chronic wound devices: a randomized study of 160 patients across 14 sites in 5 EU countries, combining Eclevar's ISO 14155 clinical expertise with the Milo Studio platform.
« Eclevar, with its tailor-made approach and advanced Milo Studio platform, represents a major strategic asset. »Antoine Turzi, CEO, RegenLab
In the EU the legal term is Medical Device Software (MDSW); SaMD is the international IMDRF term for standalone software with a medical purpose. Under MDCG 2019-11 (Rev.1, 2025), software qualifies as a medical device when its intended purpose covers diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease or injury. It is the manufacturer's stated intended purpose, not the raw capability, that determines regulatory status.
Rule 11 in Annex VIII of EU MDR, read together with the IMDRF risk framework adopted in MDCG 2019-11, classifies MDSW. Most SaMD falls into Class IIa as a minimum, and Class IIb or III when it drives diagnosis or treatment or carries a high impact on patient health. Class I is rare, so Notified Body involvement is the norm rather than the exception.
Yes. Any AI system that is itself a medical device, or a safety component of one, requiring Notified Body assessment under EU MDR is automatically classified as high-risk under Article 6(1) of the EU AI Act. The classification is automatic; the AI Act adds data governance, transparency, bias testing, human oversight and AI-specific post-market monitoring on top of MDR and IEC 62304.
Core high-risk obligations became applicable on 2 August 2026, with an extended transition to 2 August 2027 for AI embedded in devices assessed by a Notified Body. The 2026 Digital Omnibus package (political agreement reached in May 2026, formal adoption expected before August 2026) is set to move the deadline for AI embedded in regulated products, including medical devices, to 2 August 2028. Treat the original dates as the binding baseline until the Omnibus is formally adopted.
MDCG 2020-1 structures the clinical evaluation of MDSW around three pillars: a valid clinical association between the software output and the targeted clinical condition, technical (analytical) validation that the software processes input data correctly, and clinical validation that the output achieves the intended clinical benefit. Eclevar MedTech builds each pillar into the clinical evaluation plan and the PMCF strategy.
IEC 62304 governs the software lifecycle with safety classes A, B and C; IEC 82304-1 covers health software product safety; ISO 14971 covers risk management; IEC 62366-1 covers usability engineering; and MDCG 2019-16 covers cybersecurity. Eclevar MedTech aligns the evidence and technical documentation to all of these for the Notified Body review.
Talk with our regulatory and clinical specialists to map your route from qualification and classification to CE marking and AI Act readiness. You speak with Dr Mark DaCosta, COO and former Notified Body reviewer at TÜV SÜD, and the Eclevar clinical team.
Book a consultation