How does EU MDR treat Software as a Medical Device (SaMD)?
MDR Article 2(1) · Annex VIII Rule 11 · MDCG 2019-11 · MDCG 2025-4
The short answer
Software is explicitly named as a medical device in Article 2(1) MDR. Software that qualifies as a medical device is classified under Rule 11 of Annex VIII. MDCG 2019-11 (updated by MDCG 2025-4) provides the authoritative qualification and classification guidance.
Software qualification decision tree
Not all software used in healthcare is a medical device. Use the following qualification logic (based on MDCG 2019-11):
- Does the software perform actions on data beyond simple storage, archival, lossless compression, or search? No → not a medical device
- Is the output intended for the benefit of individual patients? No → not a medical device
- Does the software have a medical intended purpose (diagnosis, prevention, monitoring, treatment)? No → not a medical device. Yes → MDSW (Medical Device Software), apply MDR
Rule 11 — SaMD classification table
| Software output / function | Class |
|---|---|
| Decisions causing death or irreversible deterioration of health | Class III |
| Decisions causing serious deterioration of health or requiring surgical intervention | Class IIb |
| Other diagnostic or therapeutic decision support (reversible outcomes) | Class IIa |
| Patient management / scheduling / no diagnostic or therapeutic decision support | Class I |
MDCG 2025-4 clarifies that classification is based on the intended purpose and the potential consequences of failure — not on the technology used (AI/ML vs rule-based) or deployment platform (cloud, mobile, on-premise).
Required standards for SaMD
| Standard | What it covers |
|---|---|
| IEC 62304 | Software lifecycle — development, maintenance, SOUP management; applies to all software safety classes |
| IEC 82304-1 | Health software product safety — applies specifically to standalone SaMD (not embedded in hardware); extends IEC 62304 with product-level safety requirements and intended use documentation |
| ISO 14971 | Risk management; feeds software safety classification and risk control requirements |
| IEC 62366-1 | Usability engineering; human factors for medical software interfaces |
| MDCG 2019-16 | Cybersecurity guidance for MDSW; addresses security by design and vulnerability management |
Cloud SaMD and AI/ML considerations
Cloud-based SaMD has no special exemption from MDR — the regulation applies regardless of deployment platform. Additional considerations for cloud software include data residency, availability requirements, and cybersecurity per MDCG 2019-16.
AI/ML-enabled devices are subject to the same classification framework (Rule 11) as other software. From August 2026, the EU AI Act will additionally apply to AI systems classified as high-risk under Annex III of the AI Act, which includes AI used as medical devices. Manufacturers should begin AI Act compliance planning now.
Frequently asked questions
Does my mobile health app qualify as a medical device?
If the app has a medical intended purpose and produces output for individual patient benefit beyond storage, it likely qualifies as MDSW and must comply with MDR. Wellness apps with no medical claims are outside scope — but a declared intended purpose stating medical benefit brings the app into scope regardless of the app store category.
Are AI diagnostic tools classified as Class III?
Not necessarily. The class depends on the severity of harm that could result from an incorrect output. An AI tool that flags a possible finding for a radiologist to review (who makes the final clinical decision) is typically Class IIa. An AI that autonomously issues treatment recommendations for life-threatening conditions would be Class III.
Are wellness apps excluded from MDR?
Apps with no medical intended purpose — pure fitness tracking, step counting without medical claims — are outside MDR scope. However, if the manufacturer makes any medical claim, the app falls within scope. Apps claiming to detect specific conditions or inform clinical decisions are in scope.
Is software an accessory to a medical device always in scope?
Software that is an accessory to a medical device is regulated under MDR separately from the device it accompanies. Accessories have their own intended purpose, classification, and may require their own technical documentation and conformity assessment.