IEC 62304 lifecycle processes for European medical device software
Asteron builds the software-development and maintenance processes needed to create medical device and IVD software under controlled, traceable conditions. IEC 62304 connects software planning, requirements, architecture, implementation, verification, release, maintenance and problem resolution across the product lifecycle. The service is designed for European medical software companies preparing products for the Netherlands, Germany and wider MDR or IVDR markets.
- Software lifecycle built around the real product
- Safety classification and risk connected
- Requirements, tests and changes traceable
- MDR or IVDR evidence prepared
Medical Device Track from €30,000
What is IEC 62304?
IEC 62304 defines lifecycle processes for the development and maintenance of medical device software. It applies when software is itself a medical device and when software is embedded in or forms an integral part of a medical device.
The standard establishes a common structure for planning software work, defining and tracing requirements, controlling architecture and implementation, verifying the software, managing releases, maintaining supported versions and resolving software problems.
For a software manufacturer, IEC 62304 is not simply a documentation checklist. The required records must demonstrate how the team makes and controls product decisions throughout development and maintenance.
IEC 62304 controls the medical device software lifecycle. It does not by itself provide CE marking, determine the regulatory classification of the product or cover final validation and release of the complete medical device.
The current consolidated publication is IEC 62304:2006 with Amendment 1:2015. A future edition may be under development, but draft requirements must not be presented as the current mandatory standard.
Who needs IEC 62304?
Software as a medical device manufacturers
A company developing standalone software with an intended medical purpose may need IEC 62304 processes as part of its MDR or IVDR technical and quality documentation.
Embedded medical device software teams
The standard also applies where software controls, supports or forms an integral part of a physical medical device or IVD system.
Suppliers developing medical software components
A supplier may use IEC 62304 processes when developing software on behalf of a legal manufacturer. The contract and quality agreement should clarify responsibilities, deliverables and access to lifecycle evidence.
Teams bringing an existing product into a regulated route
A healthtech company may already have working software but lack the planning, traceability, risk integration, configuration history and problem-resolution records expected for medical device software.
Not every health application is a medical device. Intended use, qualification and classification should be assessed before the complete IEC 62304 implementation scope is finalised.
What the IEC 62304 lifecycle covers
The standard connects development and maintenance activities rather than treating them as separate document-production exercises. The implementation should fit the organisation’s actual engineering model while preserving the required control and evidence.
Software development planning
Define the lifecycle model, activities, responsibilities, methods, tools, deliverables and review points for the medical device software.
The plan should explain how software risk management, configuration management, problem resolution and supporting processes interact with development.
Requirements and architecture
Translate product and system needs into controlled software requirements and an architecture that supports traceability, verification and risk control.
Interfaces, software items, external components and important dependencies should be sufficiently understood to support development and assessment.
Implementation and verification
Control implementation, unit-level work and the verification appropriate to the software item and safety classification.
The organisation needs defined acceptance criteria and evidence that identified issues are resolved, justified or tracked.
Integration, testing and release
Plan software integration, integration testing and software-system testing against controlled requirements. Release records should identify the approved software version, known residual issues and the evidence supporting release readiness.
IEC 62304 software release does not replace final validation and release of the complete medical device.
Maintenance and change control
Maintain the software through controlled analysis, modification, verification and release activities.
Changes should be assessed for their impact on requirements, architecture, risks, tests and existing technical documentation.
Configuration and problem resolution
Identify and control software items, versions, tools and relevant records.
Software problems must be recorded, investigated, evaluated for risk and carried through an appropriate resolution and verification process.
Asteron maps these activities into the existing product workflow so that engineering, quality, risk and regulatory evidence remain connected.
Software safety classification
IEC 62304 uses software safety classes A, B and C to determine the rigour applied to lifecycle activities. The classification considers the possible contribution of software failure to a hazardous situation and the potential resulting harm.
The IEC 62304 software safety class is not the same as the MDR or IVDR regulatory class of the complete product. Both classifications may influence the project, but they answer different questions and must be documented separately.
Final classification must follow the standard and the product’s documented risk analysis. A software safety class should not be determined from a marketing description or MDR class alone.
Relevance for the Netherlands and Germany
Netherlands
Medical software manufacturers selling into the Netherlands follow the applicable European MDR or IVDR route. Dutch healthcare customers may also expect information-security evidence connected to NEN 7510, hospital procurement and health-data processing.
IEC 62304 addresses medical device software lifecycle processes. It does not replace NEN 7510 or other Dutch healthcare-security requirements.
Germany
German medical software and DiGA companies may need IEC 62304 evidence when their product qualifies as medical device software. The product may also be subject to ISO 13485, ISO 14971, IEC 81001-5-1, BSI security requirements or the applicable BfArM pathway.
IEC 62304 implementation alone does not establish DiGA eligibility or German reimbursement approval.
Asteron builds one European medical-software lifecycle and then connects the country-specific evidence required for Dutch, German and other target markets.
How Asteron implements IEC 62304
Confirm the software and regulatory scope
Asteron reviews the intended use, regulatory role, qualification, classification, software architecture, development model and target markets.
The scope identifies the software system and items covered by the lifecycle and the relationship with the complete medical device.
Map the existing development lifecycle
Current planning, requirements, architecture, development, testing, release, maintenance and issue-management practices are mapped against IEC 62304.
Existing engineering records are reused where they are controlled, traceable and suitable for the intended assessment.
Define the integrated processes
Asteron designs the missing lifecycle, risk, configuration and problem-resolution activities and connects them to ISO 13485, ISO 14971 and included cybersecurity processes.
Responsibilities, required records and review points are defined around the team’s real product workflow.
Apply the lifecycle to the product
The team uses the agreed processes and templates on the included product scope. Existing requirements, architecture, tests and release records are updated where explicitly included.
Client implementation actions remain assigned to named product and engineering owners.
Verify readiness
Asteron reviews the lifecycle evidence, prepares internal review and supports the intended certification-body, notified-body or customer assessment.
The independent assessor determines whether the evidence is sufficient for its assessment route.
Asteron maps the standard, designs the agreed lifecycle processes, prepares the included documentation structure and coordinates readiness work.
The manufacturer approves intended use and product decisions, provides engineering evidence, assigns lifecycle owners, implements technical actions and remains legally accountable for the medical device.
What Asteron delivers
The final deliverable set depends on software safety classification, product architecture, regulatory pathway and the maturity of existing engineering records. A standard scope may include:
Lifecycle foundation
- – Confirmed software and lifecycle scope
- – Software development plan
- – Software safety classification record
- – Lifecycle roles and responsibilities
- – Software risk-management integration
- – Configuration-management process
- – Software problem-resolution process
Product and assessment evidence
- – Requirements and traceability structure
- – Architecture and software-item structure
- – Verification and testing approach
- – Release and maintenance controls
- – Change-impact workflow
- – Existing lifecycle evidence review
- – Prioritised remediation plan
- – Audit and assessment readiness review
Writing or reconstructing complete product requirements, architecture, tests or technical documentation is included only when explicitly stated in the Medical Device Track proposal.
IEC 62304 is delivered through the Medical Device Track
Asteron does not publish a generic standalone IEC 62304 price because the work depends on software safety classification, product architecture, number of software items, existing engineering evidence and the required MDR or IVDR route.
The approved starting point is Medical Device Track from €30,000.
- – ISO 13485
- – ISO 14971
- – IEC 62304
- – IEC 81001-5-1
- – MDR or IVDR pathway support
- – Specialist coordination and co-delivery
Larger, multi-product, higher-class or documentation-recovery engagements are scoped individually.
- – 40% at signing
- – 40% when audit-ready
- – 20% after certification
Prices exclude VAT where applicable.
Independent assessment boundaries
Asteron implements the agreed lifecycle processes, prepares the included evidence and supports assessment readiness. Asteron does not act as the notified body, certification body or regulatory authority.
IEC 62304 does not usually create a standalone product certificate. Its evidence may be reviewed within:
- – ISO 13485 certification
- – MDR or IVDR conformity assessment
- – Technical-documentation review
- – Customer or partner assessment
- – Another independent medical-device review
External certification-body, notified-body and assessment fees are separate and are contracted and paid directly by the client.
Notified-body pricing depends on product classification, number of devices, audit scope, technical-documentation review and assessment route. ISO 27001 audit estimates are not applicable as medical-device assessment fees.
What remains separate
Unless explicitly included in the proposal, the following remain separate:
- – Final product qualification and classification decisions
- – Formal legal or regulatory opinions
- – Complete product-system validation
- – Clinical or performance evaluation
- – Usability validation
- – Source-code development or remediation
- – Full reconstruction of legacy technical documentation
- – Penetration testing
- – Notified-body and certification-body fees
- – Regulatory authority fees
Frequently asked questions
What is IEC 62304?
IEC 62304 defines lifecycle processes for developing and maintaining medical device software.
Which version of IEC 62304 is current?
The current consolidated publication is IEC 62304:2006 with Amendment 1:2015. Draft future editions should not be treated as current requirements until formally published.
Does IEC 62304 apply to software as a medical device?
Yes. It applies when software is itself a medical device and when software is embedded in or forms an integral part of a medical device.
What are IEC 62304 software safety classes?
Classes A, B and C determine the lifecycle rigour applied based on the potential contribution of software failure to harm. They are not the same as the MDR or IVDR product class.
Does IEC 62304 certify the complete medical device?
No. It defines software lifecycle processes and does not by itself provide CE marking, product approval or final validation and release of the complete device.
How does IEC 62304 relate to ISO 13485?
ISO 13485 provides the medical-device quality system. IEC 62304 defines the software lifecycle processes operating within that controlled system.
How does it relate to ISO 14971?
ISO 14971 provides medical-device risk management. IEC 62304 connects software development, maintenance and problem resolution to the relevant risk activities.
Is IEC 62304 relevant in the Netherlands and Germany?
Yes, when the product qualifies as medical device or IVD software for those markets. Dutch and German healthcare or reimbursement requirements may apply in addition.
How much does implementation cost?
Asteron delivers IEC 62304 through the Medical Device Track, starting from €30,000. Final scope depends on the product, safety class, existing evidence and regulatory route.
Are notified-body fees included?
No. External notified-body, certification-body and assessment fees are contracted and paid directly by the client.
Official references
- – IEC — IEC 62304:2006 with Amendment 1:2015
- – European Commission — MDCG 2019-11 rev.1 on medical device software qualification and classification
- – European Commission — MDR and IVDR
- – ISO — ISO 13485 medical-device quality management
- – ISO — ISO 14971 medical-device risk management
- – IEC — IEC 81001-5-1 health-software cybersecurity lifecycle
Last reviewed: July 2026
Asteron is not endorsed by or partnered with IEC, ISO, the European Commission, any competent authority or notified body.
Turn the existing development workflow into an auditable lifecycle
Share the intended use, software architecture, regulatory position and existing engineering records. Asteron will determine what can be reused and define the right IEC 62304 implementation scope.
