Software as a Medical Device · MDSW · EU MDR + AI Act

The clinical and regulatory partner for Software as a Medical Device.

Eclevar MedTech runs the evidence and regulatory programme for medical device software under EU MDR 2017/745 and the EU AI Act: qualification, Rule 11 classification, clinical evaluation, IEC 62304 lifecycle alignment, cybersecurity and post-market performance, built by clinicians and former Notified Body reviewers.

Rule 11 classification IEC 62304 lifecycle AI Act high-risk 21 CFR Part 11
Eclevar MedTech receiving the Platinum Award at the xShare and EUCROF Open Call Awards for Clinical Research in Amsterdam Platinum Award 2026

Eclevar MedTech and Milo took the Platinum Award at xShare & EUCROF.

Top prize in the xShare x European CRO Federation "EHDS & Clinical Research" Open Call, awarded to Eclevar MedTech and its Milo Health platform, presented at the EUCROF 2026 conference in Amsterdam.

Co-funded by the European Union

Horizon Europe · Grant Agreement No. 101136734 · Amsterdam, 2 Feb 2026

Trusted by medical device manufacturers

Software teams that need defensible evidence.

Device and software makers rely on Eclevar for a file that survives Notified Body review. Read all client success stories.

TERUMO Meril NIHON KOHDEN VYGON Coloplast SHOFU ASAHI INTECC RegenLab TERUMO Meril NIHON KOHDEN VYGON Coloplast SHOFU ASAHI INTECC RegenLab
Dr Mark DaCosta, COO at Eclevar MedTech and former TÜV SÜD Notified Body reviewer
Dr Mark DaCosta COO · Former Notified Body reviewer Former reviewer at TÜV SÜD
Medical & regulatory leadership

The reviewer who assessed the dossiers now builds them.

Before joining Eclevar MedTech, Dr Mark DaCosta spent years on the Notified Body side as a lead clinical reviewer at TÜV SÜD, where he assessed and certified several hundred devices under EU MDR, including software and active implantable systems in the highest risk classes. That experience changes how a SaMD file is built: we anticipate the questions a Notified Body will raise around Rule 11 reasoning, IEC 62304 documentation depth and the clinical validation of an algorithm, and structure the technical documentation to answer them before they are asked.

400+Devices assessed under EU MDR
Rule 11Software classification expertise
Cl. IIa to IIIMDSW and active implants
Ex Notified Body Technical documentation Clinical strategy
LinkedIn
Aligned to EU MDR 2017/745 EU AI Act IEC 62304 ISO 14971 ISO 13485 21 CFR Part 11
Qualification

Is your software a medical device?

In the European Union, the term Software as a Medical Device (SaMD), coined by the IMDRF, maps onto the legal category of Medical Device Software (MDSW). Under MDCG 2019-11 (revised in 2025), software qualifies as a medical device when the manufacturer's intended purpose covers diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease or injury.

The decisive factor is the intended purpose, not the raw technical capability. How the software is positioned, labelled and marketed determines its regulatory status, which is exactly what a Notified Body examines first. Where a product sits at the boundary between MDR and IVDR, an early regulatory opinion prevents costly rework of the technical documentation later.

The revised MDCG 2019-11 also clarifies modular software: a medical purpose module inside a wider system, for example a decision-support module inside an electronic health record, must comply with MDR in its own right even when the surrounding platform does not.

Typically in scope as MDSW

  • AI imaging triage and detection software.
  • Clinical decision support systems (CDSS).
  • Symptom assessment and patient triage apps.
  • Therapeutic algorithms and digital therapeutics.
  • Remote patient monitoring and ePRO platforms.
  • Software that drives or influences a hardware device.
Classification under Rule 11

Most SaMD is Class IIa or above.

Rule 11 in Annex VIII of EU MDR, read together with the IMDRF risk framework adopted in MDCG 2019-11, sets the risk class from the significance of the information the software provides and the seriousness of the clinical situation. In practice, Class I is rare and Notified Body involvement is the norm.

Class IIa

Information for clinical decisions

Software providing information used to take decisions with a diagnostic or therapeutic purpose. The baseline for most MDSW, and already triggers a Notified Body conformity assessment.

Class IIb

Serious deterioration or surgery

Software whose information could lead to a serious deterioration of health or a surgical intervention. Many monitoring, triage and treatment-planning tools land here, with deeper evidence expectations.

Class III

Death or irreversible deterioration

Software whose information may cause death or an irreversible deterioration of health. The highest evidence bar, with a full clinical investigation frequently required.

The practical consequence: because Class I is rare under Rule 11, nearly every SaMD manufacturer needs a Notified Body, an Annex IX quality management system and a technical documentation file that survives review. Getting the classification wrong at the start is one of the most expensive mistakes in a software programme. Eclevar MedTech documents the qualification and classification reasoning explicitly, the way a reviewer expects to see it.
Lifecycle & evidence

The standards a SaMD file is measured against.

A defensible software dossier is a stack of aligned evidence, from the development lifecycle to the clinical validation of the output. Eclevar MedTech builds and connects every layer for the Notified Body review.

01 / 06

Software lifecycle

IEC 62304 · safety classes A, B, C

The lifecycle standard sets the required depth of planning, documentation, testing and quality control according to the software safety class. The class you assign drives how much evidence a reviewer expects for every unit and integration step.

02 / 06

Health software product safety

IEC 82304-1

For standalone health software, this standard covers product-level safety and security across the full product life, complementing the process view of IEC 62304 with product requirements, validation and accompanying documentation.

03 / 06

Clinical evaluation of MDSW

MDCG 2020-1 · three pillars

The clinical evaluation of software rests on a valid clinical association between the output and the targeted condition, technical (analytical) validation that the software processes input data correctly, and clinical validation that the output delivers the intended clinical benefit. We plan and evidence all three.

04 / 06

Risk management

ISO 14971

A software-specific risk management file that connects hazards, foreseeable misuse and residual risk to the clinical evaluation and the post-market plan, so the benefit-risk determination holds up end to end.

05 / 06

Usability engineering

IEC 62366-1

Use-related risk is central to software safety. We structure formative and summative usability evaluation so the user interface and the use environment are evidenced to the standard reviewers expect.

06 / 06

Cybersecurity

MDCG 2019-16

Security is a safety requirement for connected software. We align the security risk assessment, secure development and post-market security monitoring to the MDCG guidance and the applicable Annex I requirements.

AI-based SaMD & the EU AI Act

Two regulations, one integrated file.

If your SaMD includes AI or machine learning, a second framework applies on top of EU MDR. Any AI system that is itself a medical device, or a safety component of one, and that requires Notified Body assessment is automatically classified as high-risk under Article 6(1) of the EU AI Act. There is no separate AI risk-classification step: the status follows from the MDR route.

The two frameworks are complementary, not interchangeable. MDR governs whether the device is safe and performs as claimed; the AI Act governs how the AI was built, trained and governed: data governance, algorithmic transparency, bias testing, human oversight, AI-specific post-market monitoring and registration in the EU high-risk AI database. Compliance with IEC 62304 does not, on its own, satisfy these obligations.

For continuously learning systems, a predetermined change control plan lets you define in advance which model updates are permitted without a new conformity assessment, a critical piece of planning for any adaptive algorithm.

Moving target: the 2026 Digital Omnibus package (political agreement reached in May 2026) is set to shift the deadline for AI embedded in regulated products to 2 August 2028, but it only takes legal effect once formally adopted and published. Treat the original dates as the binding baseline and plan for the extension.
1 Aug 2024
AI Act enters into forceRegulation (EU) 2024/1689 begins its phased roll-out.
2 Aug 2026
High-risk core obligations applyData governance, transparency, human oversight and technical documentation duties become applicable; the AI literacy duty also applies from this date.
2 Aug 2027
Extended transition for devicesOriginal deadline for AI embedded in Notified Body assessed medical devices under Article 6(1).
2 Aug 2028
Proposed extension (Digital Omnibus)Likely new deadline for AI embedded in regulated products including medical devices, subject to formal adoption.
How Eclevar helps

One team across the whole software file.

01

Qualification & classification

Documented MDSW qualification and Rule 11 classification with the IMDRF framework, MDR versus IVDR boundary opinions and a defensible intended-purpose statement your Notified Body can accept.

02

Clinical evidence

Clinical evaluation of software to MDCG 2020-1, with clinical investigation design where the class requires it, and the analytical and clinical validation of your algorithm built into a coherent plan.

03

Quality & lifecycle

ISO 13485 quality management aligned to IEC 62304 and IEC 82304-1, with risk management, usability and cybersecurity structured for the technical documentation review.

04

AI Act readiness

Gap assessment against the high-risk obligations, data governance and human-oversight architecture, bias-testing plans and a predetermined change control plan for adaptive models.

05

Post-market performance

Post-market surveillance and PMCF designed for software, with real-world performance monitoring, update and change management, and vigilance connected back to the clinical evaluation.

06

Real-world evidence

Registry and real-world data strategies that support performance claims, indication extension and the continued certification of legacy software under EU MDR.

Selected experience

Software programmes built to survive review.

Illustrative of the software programmes Eclevar MedTech supports, from AI-based diagnostic tools to connected monitoring platforms. Figures reflect the respective programme documentation.

MDSW Class IIb · AI diagnostic support

AI imaging triage software, EU MDR and AI Act readiness

Indication: radiology triage

A developer of an AI radiology triage tool needed a single evidence plan covering both frameworks. Eclevar MedTech structured the clinical evaluation to MDCG 2020-1, built the analytical and clinical validation, and mapped the high-risk AI obligations onto the existing IEC 62304 documentation so the two files reinforced rather than duplicated each other.

3 pillarsClinical evaluation built
Art 6(1)High-risk mapped
1 fileMDR and AI Act aligned
AI / MLMDCG 2020-1IEC 62304AI Act
MDSW Class IIa · Remote monitoring

Connected patient monitoring platform, PMCF and RWE

Chronic disease management

For a remote monitoring platform, Eclevar MedTech designed a post-market clinical follow-up study on MILO, capturing real-world performance and patient-reported outcomes at scale. The design linked update and change management to the clinical evaluation so software releases stayed inside a controlled, documented evidence loop.

PMCFSoftware-specific design
RWEReal-world performance
21 CFR 11Validated capture
Remote monitoringePROPMCFMILO EDC
Unified data platform

Validated data capture for software clinical evidence.

Generating clinical and post-market evidence for software needs an equally rigorous data backbone. Eclevar MedTech runs MILO EDC, its proprietary electronic data capture platform, fully aligned to FDA 21 CFR Part 11 and the GDPR. MILO brings the eCRF, automated ePRO surveys and long-term real-world data collection into a single, audit-ready ecosystem, built to sustain patient engagement across multi-year software follow-up.

FDA 21 CFR Part 11 compliant
ISO 27001 & GDPR
Automated ePRO surveys
Real-world performance capture
Registry API integration
Official content

Our content, signed Eclevar.

Whitepapers, client testimonials and publications produced by our teams and partners (BSI, TÜV SÜD, RegenLab).

Whitepaper by BSI and Eclevar on the EU MDR
Whitepaper · BSI × Eclevar

A BSI and Eclevar whitepaper on the EU MDR.

Written with Notified Body BSI: a practical reading of the clinical evidence expectations under EU MDR 2017/745, directly relevant to any software file.

PMCF Studies · Regenerative Medicine · 5 EU Countries

A client's live testimonial on Eclevar's capability to run complex trials.

Eclevar MedTech manages RegenLab's PMCF programme on chronic wound devices: a randomized study of 160 patients across 14 sites in 5 EU countries, combining Eclevar's ISO 14155 clinical expertise with the Milo Studio platform.

« Eclevar, with its tailor-made approach and advanced Milo Studio platform, represents a major strategic asset. »Antoine Turzi, CEO, RegenLab
160patients · 14 sites
5EU countries
RegenLab video testimonial on the PMCF programme managed by Eclevar
FAQ

SaMD under EU MDR, answered.

Is my software a medical device under EU MDR?

In the EU the legal term is Medical Device Software (MDSW); SaMD is the international IMDRF term for standalone software with a medical purpose. Under MDCG 2019-11 (Rev.1, 2025), software qualifies as a medical device when its intended purpose covers diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease or injury. It is the manufacturer's stated intended purpose, not the raw capability, that determines regulatory status.

What class is Software as a Medical Device under Rule 11?

Rule 11 in Annex VIII of EU MDR, read together with the IMDRF risk framework adopted in MDCG 2019-11, classifies MDSW. Most SaMD falls into Class IIa as a minimum, and Class IIb or III when it drives diagnosis or treatment or carries a high impact on patient health. Class I is rare, so Notified Body involvement is the norm rather than the exception.

Does the EU AI Act apply to AI-based SaMD?

Yes. Any AI system that is itself a medical device, or a safety component of one, requiring Notified Body assessment under EU MDR is automatically classified as high-risk under Article 6(1) of the EU AI Act. The classification is automatic; the AI Act adds data governance, transparency, bias testing, human oversight and AI-specific post-market monitoring on top of MDR and IEC 62304.

When do the EU AI Act obligations apply to medical device software?

Core high-risk obligations became applicable on 2 August 2026, with an extended transition to 2 August 2027 for AI embedded in devices assessed by a Notified Body. The 2026 Digital Omnibus package (political agreement reached in May 2026, formal adoption expected before August 2026) is set to move the deadline for AI embedded in regulated products, including medical devices, to 2 August 2028. Treat the original dates as the binding baseline until the Omnibus is formally adopted.

What clinical evidence does SaMD need under EU MDR?

MDCG 2020-1 structures the clinical evaluation of MDSW around three pillars: a valid clinical association between the software output and the targeted clinical condition, technical (analytical) validation that the software processes input data correctly, and clinical validation that the output achieves the intended clinical benefit. Eclevar MedTech builds each pillar into the clinical evaluation plan and the PMCF strategy.

Which standards apply to SaMD development?

IEC 62304 governs the software lifecycle with safety classes A, B and C; IEC 82304-1 covers health software product safety; ISO 14971 covers risk management; IEC 62366-1 covers usability engineering; and MDCG 2019-16 covers cybersecurity. Eclevar MedTech aligns the evidence and technical documentation to all of these for the Notified Body review.

Guaranteed response within 24 hours

Let us scope your SaMD file.

Talk with our regulatory and clinical specialists to map your route from qualification and classification to CE marking and AI Act readiness. You speak with Dr Mark DaCosta, COO and former Notified Body reviewer at TÜV SÜD, and the Eclevar clinical team.

Book a consultation

Reforming Clinical Evaluation of Medical Devices in Europe