Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

IEC 62304 FDA guidance — IEC 62304 FDA Guidance: Documentation Levels vs Safety Classes, Mapped (Clear 2026 Guide)

IEC 62304 FDA Guidance: Documentation Levels vs Safety Classes, Mapped (Clear 2026 Guide)

IEC 62304 FDA guidance questions usually come down to one confusion: the standard has three software safety classes, FDA’s submission guidance has two Documentation Levels, and they sound as if they should line up. They do not. A Class B system under IEC 62304 can require Enhanced documentation from FDA, and a manufacturer that derives one from the other will either under-document a submission or over-classify its software. This guide sets out how IEC 62304 and FDA’s June 2023 guidance actually relate — what the guidance asks for, where an IEC 62304 file already supplies it, and where the two determinations diverge.

What this guide covers

IEC 62304 FDA guidance explained
IEC 62304 FDA guidance: the two Documentation Levels of the June 2023 guidance are a separate determination from the three software safety classes.

The IEC 62304 FDA guidance landscape

Three FDA instruments make up the IEC 62304 FDA guidance picture for medical device software, and IEC 62304 sits under all of them.

Instrument What it does Relationship to IEC 62304
Recognised consensus standards FDA lists standards a manufacturer may declare conformity to in a submission IEC 62304 Edition 1.1 is a recognised consensus standard; a declaration of conformity can stand in for parts of the software documentation
Content of Premarket Submissions for Device Software Functions (final, 14 June 2023) Sets the documentation a 510(k), De Novo, PMA, HDE or BLA contains for device software functions, at Basic or Enhanced level Every element it lists is a deliverable an IEC 62304 life cycle already produces — the mapping is close to one-to-one
Quality Management System Regulation, 21 CFR Part 820 (effective 2 February 2026) Incorporates ISO 13485:2016 by reference as the US quality system requirement IEC 62304 assumes an ISO 13485-style QMS; the QMSR makes that the US baseline too

The 2023 guidance replaced FDA’s 2005 Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices and, with it, the three Levels of Concern — Minor, Moderate, Major — that a generation of submissions was organised around. Anyone whose IEC 62304 FDA guidance knowledge dates from before 2023 is working from the wrong framework.

IEC 62304 FDA guidance: Documentation Level is not software safety class

This is the heart of the IEC 62304 FDA guidance question, so it is worth being precise.

IEC 62304 software safety class FDA Documentation Level
Values A, B, C Basic, Enhanced
Decided on The worst-case hazardous situation the software could contribute to, after risk control measures external to the software are credited Whether a failure or flaw of a device software function could present a hazardous situation with a probable risk of death or serious injury — before mitigations are considered
Other triggers None Enhanced also applies to combination-product constituents; devices for testing blood donations or donor–recipient compatibility, automated blood cell separators and blood establishment software; and Class III devices
What it selects Which of the standard’s 98 requirements the manufacturer must perform How much of the software file goes into the submission
Who decides The manufacturer, recorded in the risk management file The sponsor, with rationale, as a submission element

The consequence: a software system whose worst-case failure could kill, but which sits behind a verified hardware interlock, may be Class B under IEC 62304 — the external control is credited — and still Enhanced for FDA, because the Documentation Level looks at the failure before mitigation. The reverse is rarer but possible for a Class III device with benign software. Record both determinations, with their rationales, and derive neither from the other. Our guide to software safety classification covers the IEC 62304 side of the decision.

What the IEC 62304 FDA guidance mapping looks like

The IEC 62304 FDA guidance mapping starts from the documentation elements the guidance lists for a submission. Each maps to a deliverable an IEC 62304 life cycle produces; the table shows the mapping and where Basic and Enhanced differ.

FDA element Basic Enhanced IEC 62304 deliverable that supplies it
Documentation Level evaluation Required Required A determination with rationale; references the hazard analysis of clause 7.1 and the class record, while keeping the two decisions distinct
Software description Required Required The intended-use and overview sections of the requirements specification and architecture
Risk management file Required Required The ISO 14971 file with the clause 7 software entries: hazard analysis, risk controls, verification, traceability
Software requirements specification Required Required Clause 5.2 output with its 5.2.6 verification
System and software architecture design Architecture diagram Architecture diagram Clause 5.3 architecture document
Software design specification Not in the submission (kept in the design history file) Required Clause 5.4 detailed design — which IEC 62304 requires only at Class C, so an Enhanced Class B system produces it for FDA even though the standard does not demand it
Software development, configuration management and maintenance practices Summary of processes, or a declaration of conformity to IEC 62304 covering specified clauses Complete plan documents, or a declaration of conformity to IEC 62304 covering a broader set of clauses including the whole of 5.1 The development plan and its supporting plans; the configuration management plan; the maintenance plan — or the IEC 62304 compliance statement
Software testing as part of verification and validation Summary descriptions plus system-level test protocols and reports Unit, integration and system-level protocols and reports Clauses 5.5–5.7 records; at Basic, the 5.7 system test records carry it
Software version history Required Required The released versions register and 5.8.4 release records
Unresolved software anomalies Required Required The 5.8.2 known residual anomalies list, with impact on safety and effectiveness and the rationale for not fixing each — 5.8.3’s evaluation at Class B and C

Two rows repay attention. The development-practices element is where the IEC 62304 FDA guidance relationship becomes explicit: FDA will accept a declaration of conformity to IEC 62304 in place of describing your processes, at either level, with the set of clauses declared depending on the level. That is the payoff for keeping a clean compliance statement. And the software design specification row shows the levels and the classes pulling apart: FDA wants detailed design at Enhanced regardless of class, while IEC 62304 requires it at Class C only.

IEC 62304 FDA guidance on cybersecurity: the fourth instrument

For a “cyber device” — one that includes software, connects to the internet and could be vulnerable to cybersecurity threats — section 524B of the Federal Food, Drug, and Cosmetic Act, in force for submissions from 29 March 2023, adds requirements the IEC 62304 FDA guidance mapping above does not cover: a plan to monitor, identify and address post-market vulnerabilities; processes providing reasonable assurance of cybersecurity; and a software bill of materials. FDA’s separate premarket cybersecurity guidance sets out the expected content — first finalised in September 2023, reissued on 27 June 2025 with a new section on 524B, and revised on 27 February 2026 to align with the QMSR.

IEC 62304 supplies the security requirements of 5.2.2 e) and the SOUP register that becomes the SBOM’s human-readable twin — see our guide to SOUP under IEC 62304 — but the threat model and security testing come from IEC 81001-5-1, which regulators treat as the recognised route.

The QMSR and the IEC 62304 FDA guidance stack

The last layer of the IEC 62304 FDA guidance stack is the quality system. From 2 February 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, with FDA-specific additions on records, complaint files and labelling controls. For a software manufacturer this closes a gap: IEC 62304 assumes an ISO 13485-shaped QMS around it, and the US quality system now is one. Our QMSR vs ISO 13485 comparison covers the additions; the IEC 62304 vs ISO 13485 guide covers where each software activity lands in the design controls.

Using the IEC 62304 FDA guidance mapping to assemble a submission

  1. Determine the Documentation Level against the four Enhanced triggers, record the rationale, and note the IEC 62304 class separately.
  2. Decide whether to declare conformity to IEC 62304 for the development-practices element. If so, the compliance statement and the internal audit behind it are the evidence; make sure the declared clauses match the level.
  3. Pull the elements from the development file in the order the guidance lists them; the software development file index is the contents page.
  4. At Enhanced, add what IEC 62304 may not have required: a detailed design specification if the class is B, and the unit and integration test protocols and reports.
  5. Write the unresolved anomalies list from the release record, with each anomaly’s impact on safety and effectiveness and the rationale for shipping with it.
  6. For a cyber device, add the 524B elements — threat model, SBOM, vulnerability management plan, security testing.

The IEC 62304 Toolkit carries a mapping document that takes each element of FDA’s June 2023 guidance to the toolkit deliverable that supplies it at Basic and Enhanced level, alongside the compliance statement template a declaration of conformity rests on, and the release records the version history and anomalies list are drawn from. The guidance’s availability notice is on the Federal Register; the guidance itself is on FDA’s website.

Frequently asked questions

Does FDA require IEC 62304?

No. FDA recognises it as a consensus standard, which means a declaration of conformity is an accepted way to satisfy parts of the software documentation — notably the development, configuration management and maintenance practices element. A manufacturer may instead describe its processes directly.

Is Enhanced Documentation the same as IEC 62304 Class C?

No. Enhanced is triggered by a probable risk of death or serious injury before mitigation, or by combination-product, blood-related or Class III status. Class C is decided after external risk controls are credited. They often coincide and often do not; record both.

Which IEC 62304 FDA guidance replaced the Level of Concern?

The June 2023 Content of Premarket Submissions for Device Software Functions, which superseded the May 2005 guidance and its Minor, Moderate and Major Levels of Concern with the two Documentation Levels.

Under the IEC 62304 FDA guidance mapping, does a Basic-level submission need unit test reports?

Not in the submission. Basic asks for summary descriptions plus system-level test protocols and reports; unit and integration protocols and reports are Enhanced. They still have to exist in the design history file where IEC 62304 requires them for the class.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.