Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

IEC 62304 vs IEC 82304-1 — IEC 62304 vs IEC 82304-1: Which Standard Does SaMD Need? (Complete 2026 Comparison)

IEC 62304 vs IEC 82304-1: Which Standard Does SaMD Need? (Complete 2026 Comparison)

IEC 62304 vs IEC 82304-1 is the comparison every software-as-a-medical-device team eventually has to make, and the reason is written into IEC 62304 itself. Its scope clause says the standard does not cover validation and final release of the medical device — even when the device consists entirely of software — and points to IEC 82304-1 for the system-level activities a software-only product needs before it can be placed into service.

So for a mobile app, a cloud diagnostic, a planning tool or any product where the software is the device, the two standards are not rivals: one governs the software life cycle, the other wraps the product around it. This guide sets out the IEC 62304 vs IEC 82304-1 relationship — what each covers, where the hand-offs are, and what a SaMD manufacturer typically needs from both.

What this guide covers

IEC 62304 vs IEC 82304-1 explained
IEC 62304 vs IEC 82304-1: the software life cycle and the health software product standard that wraps it for software-only devices.

IEC 62304 vs IEC 82304-1: the short answer

IEC 62304:2006+AMD1:2015 IEC 82304-1:2016
Full title Medical device software — Software life cycle processes Health software — Part 1: General requirements for product safety
Object The software: from software requirements to software release, plus maintenance, risk, configuration management and problem resolution The health software product: use requirements, system requirements, validation, identification, accompanying documents, post-market
Applies to Software that is a medical device or embedded in one Software-only health software products — medical device software included, but wider
Starts At software requirements, taking system requirements as input At the product’s intended use and use requirements
Ends At software release for use at system level (5.8) At product validation, release and post-market activities
Relationship Names IEC 82304-1 as the source of the system-level activities it excludes Requires the software to be developed and maintained under IEC 62304

Put simply: in the IEC 62304 vs IEC 82304-1 pairing, 82304-1 is the system standard for a product that has no hardware system standard of its own.

IEC 62304 vs IEC 82304-1: why IEC 62304 stops where it does

The IEC 62304 vs IEC 82304-1 boundary exists because IEC 62304 was written for software inside a medical device. For an electrical device, IEC 60601-1 supplies the system level: the programmable electrical medical system requirements of its clause 14, the device validation, the accompanying documents. IEC 62304 could therefore stop at the software boundary and let the product standard take over.

A software-only product has no IEC 60601-1. When IEC 62304 was amended in 2015, its scope notes acknowledged the gap directly — additional development activities are needed at the system level before software that is itself a device can be placed into service, and IEC 82304-1, then in preparation, is where they are found. IEC 82304-1 was published in 2016 to be exactly that.

IEC 62304 vs IEC 82304-1: what each standard asks for

What IEC 82304-1 adds above the software

  • Use requirements. Who uses the product, for what, in what environment, with what accompanying information — derived into requirements that cover safety, security and usability.
  • System requirements. The platform, IT network and hardware the software needs, and the minimum requirements users and their environment must meet.
  • The software life cycle. Developed and maintained in accordance with IEC 62304 — the whole of it.
  • Product validation. Planned and performed against the use requirements in the intended environment, and reported. This is the activity IEC 62304 excludes.
  • Identification and accompanying documents. Unambiguous product and version identification; instructions for use; a technical description including system requirements and security information.
  • Post-market activities. Monitoring the product in use, maintaining it, re-validating after change, and managing its retirement.

What IEC 62304 supplies underneath

Everything from software requirements to software release, at the software safety class assigned: planning, requirements analysis, architecture, detailed design, unit verification, integration and system testing, release; maintenance; software risk management as the software part of ISO 14971; configuration management including SOUP; and problem resolution. Our guide to software safety classification covers how the class is decided, because that decision governs how much of IEC 62304 applies.

IEC 62304 vs IEC 82304-1: the hand-offs between the two standards

The IEC 62304 vs IEC 82304-1 boundary is crossed at three points, and each is a place where a document produced under one standard is the input to the other.

Hand-off From To What crosses
Requirements IEC 82304-1 use and system requirements IEC 62304 clause 5.1.3 and 5.2.1 The product requirements become the “system requirements” IEC 62304 takes as input. For a software-only product the two documents may be one; the development plan records that decision
Release IEC 62304 clause 5.8 software release IEC 82304-1 product validation The released, verified software with its version and build record, residual anomalies documented, is what the product validation exercises
Post-market IEC 82304-1 post-market activities IEC 62304 clause 6 maintenance Field feedback and problems flow into the software maintenance and problem resolution processes; software changes are re-validated at product level

A fourth crossing is quieter. IEC 82304-1’s system requirements — platform, memory, operating system, network — are the same information IEC 62304 asks for in its own requirements content (computing environment, IT-network aspects, installation) and in its SOUP requirements (the hardware and software each SOUP item needs). Write it once, in the software requirements specification, and reference it from the accompanying documents.

Where the IEC 62304 vs IEC 82304-1 line matters for regulators

In the EU, IEC 62304 is the state of the art notified bodies expect for the software life cycle under the MDR and IVDR — though, checkably, EN 62304 is not on the Commission’s harmonised-standards lists for either regulation, so there is no presumption of conformity to claim (see our guide to MDR harmonised standards). Software-only devices still have to meet the general safety and performance requirements for software in Annex I section 17, including the minimum hardware, IT network and IT security requirements of 17.4, and demonstrate validation of the software as used in the finished device under Annex II section 6.1(b). IEC 62304 alone does not get you there; the product-level requirements IEC 82304-1 supplies do.

In the US, FDA recognises IEC 62304 as a consensus standard and its June 2023 software guidance sets out the documentation a submission contains. Product-level validation and the labelling for a software function are expected as well, and IEC 82304-1’s structure is a reasonable way to organise them. Our guide to the EU MDR covers the European side of the technical documentation in more depth.

IEC 62304 vs IEC 82304-1: does every device need both?

No — and this is where the IEC 62304 vs IEC 82304-1 question gets its practical answer.

  • Embedded software in an electrical device (an infusion pump, a monitor, an imaging system): IEC 62304 for the software, IEC 60601-1 for the system. IEC 82304-1 is not needed.
  • Software-only medical device (a diagnostic app, a treatment planning tool, a clinical decision support product): IEC 62304 for the software, IEC 82304-1 for the product. Both, plus ISO 13485 for the QMS and ISO 14971 for risk.
  • Health software that is not a medical device (a wellness app, an administrative tool): IEC 82304-1 applies as a product safety standard; IEC 62304 is the expected life cycle underneath it, though the regulatory pressure is lighter.

The decision belongs to regulatory affairs and is recorded per product: is it a software-only product, is it a medical device, and which standard supplies the system level.

IEC 62304 vs IEC 82304-1 in a SaMD documentation set

Combining the two sides of the IEC 62304 vs IEC 82304-1 pair, a software-only device’s technical documentation typically contains: the intended use and use requirements; the system requirements (platform, network, security); the software development plan and its supporting plans; the software requirements specification, architecture and, for Class C, detailed design; unit, integration and system test records; the software risk management outputs in the ISO 14971 file; the SOUP register; the release record with version, build and residual anomalies; the product validation plan and report; the instructions for use and technical description; and the post-market and maintenance plan. The first half comes from IEC 82304-1, the middle from IEC 62304, and the last from both.

The IEC 62304 Toolkit carries the IEC 62304 half in full — 97 templates across the standard’s clauses — together with a mapping document that shows how IEC 82304-1’s product-level requirements wrap the software life cycle for software-only products and which toolkit documents contribute to both. The product validation plan and the accompanying documents are IEC 82304-1 deliverables and sit outside the software toolkit by design. Both standards are licensed by the IEC.

Frequently asked questions

Is IEC 82304-1 a replacement for IEC 62304?

No. IEC 82304-1 requires the software inside a health software product to be developed and maintained under IEC 62304. It adds the product-level requirements above the software; it does not replace the life cycle beneath.

Does IEC 62304 vs IEC 82304-1 matter for embedded software?

Rarely. Embedded software in an electrical device gets its system level from IEC 60601-1 and its collateral standards. IEC 82304-1 is written for software-only products.

In IEC 62304 vs IEC 82304-1, which standard covers validation?

IEC 82304-1. IEC 62304 verifies the software against its requirements and releases it for use at system level; it excludes validation and final release of the device even when the device is entirely software. For a software-only product, IEC 82304-1’s product validation is that activity.

Are the two standards being revised together?

Yes, and the IEC 62304 vs IEC 82304-1 relationship will tighten. IEC 62304 Edition 2 is in development with a scope extended toward health software, and IEC 82304-1 is under revision alongside it. Neither revision was published at the time of writing; Edition 1.1 of IEC 62304 and the 2016 edition of IEC 82304-1 remain the editions in force — see our IEC 62304 Edition 2 status update.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.