IEC 62304 FDA guidance questions usually come down to one confusion: the standard has three software safety classes, FDA’s submission guidance has two Documentation Levels, and they sound as if they should line up. They do not. A Class B system under IEC 62304 can require Enhanced documentation from FDA, and a manufacturer that derives one from the other will either under-document a submission or over-classify its software. This guide sets out how IEC 62304 and FDA’s June 2023 guidance actually relate — what the guidance asks for, where an IEC 62304 file already supplies it, and where the two determinations diverge.
What this guide covers
- The IEC 62304 FDA guidance landscape
- IEC 62304 FDA guidance: Documentation Level is not software safety class
- What the IEC 62304 FDA guidance mapping looks like
- IEC 62304 FDA guidance on cybersecurity: the fourth instrument
- The QMSR and the IEC 62304 FDA guidance stack
- Using the IEC 62304 FDA guidance mapping to assemble a submission
- Frequently asked questions

The IEC 62304 FDA guidance landscape
Three FDA instruments make up the IEC 62304 FDA guidance picture for medical device software, and IEC 62304 sits under all of them.
| Instrument | What it does | Relationship to IEC 62304 |
|---|---|---|
| Recognised consensus standards | FDA lists standards a manufacturer may declare conformity to in a submission | IEC 62304 Edition 1.1 is a recognised consensus standard; a declaration of conformity can stand in for parts of the software documentation |
| Content of Premarket Submissions for Device Software Functions (final, 14 June 2023) | Sets the documentation a 510(k), De Novo, PMA, HDE or BLA contains for device software functions, at Basic or Enhanced level | Every element it lists is a deliverable an IEC 62304 life cycle already produces — the mapping is close to one-to-one |
| Quality Management System Regulation, 21 CFR Part 820 (effective 2 February 2026) | Incorporates ISO 13485:2016 by reference as the US quality system requirement | IEC 62304 assumes an ISO 13485-style QMS; the QMSR makes that the US baseline too |
The 2023 guidance replaced FDA’s 2005 Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices and, with it, the three Levels of Concern — Minor, Moderate, Major — that a generation of submissions was organised around. Anyone whose IEC 62304 FDA guidance knowledge dates from before 2023 is working from the wrong framework.
IEC 62304 FDA guidance: Documentation Level is not software safety class
This is the heart of the IEC 62304 FDA guidance question, so it is worth being precise.
| IEC 62304 software safety class | FDA Documentation Level | |
|---|---|---|
| Values | A, B, C | Basic, Enhanced |
| Decided on | The worst-case hazardous situation the software could contribute to, after risk control measures external to the software are credited | Whether a failure or flaw of a device software function could present a hazardous situation with a probable risk of death or serious injury — before mitigations are considered |
| Other triggers | None | Enhanced also applies to combination-product constituents; devices for testing blood donations or donor–recipient compatibility, automated blood cell separators and blood establishment software; and Class III devices |
| What it selects | Which of the standard’s 98 requirements the manufacturer must perform | How much of the software file goes into the submission |
| Who decides | The manufacturer, recorded in the risk management file | The sponsor, with rationale, as a submission element |
The consequence: a software system whose worst-case failure could kill, but which sits behind a verified hardware interlock, may be Class B under IEC 62304 — the external control is credited — and still Enhanced for FDA, because the Documentation Level looks at the failure before mitigation. The reverse is rarer but possible for a Class III device with benign software. Record both determinations, with their rationales, and derive neither from the other. Our guide to software safety classification covers the IEC 62304 side of the decision.
What the IEC 62304 FDA guidance mapping looks like
The IEC 62304 FDA guidance mapping starts from the documentation elements the guidance lists for a submission. Each maps to a deliverable an IEC 62304 life cycle produces; the table shows the mapping and where Basic and Enhanced differ.
| FDA element | Basic | Enhanced | IEC 62304 deliverable that supplies it |
|---|---|---|---|
| Documentation Level evaluation | Required | Required | A determination with rationale; references the hazard analysis of clause 7.1 and the class record, while keeping the two decisions distinct |
| Software description | Required | Required | The intended-use and overview sections of the requirements specification and architecture |
| Risk management file | Required | Required | The ISO 14971 file with the clause 7 software entries: hazard analysis, risk controls, verification, traceability |
| Software requirements specification | Required | Required | Clause 5.2 output with its 5.2.6 verification |
| System and software architecture design | Architecture diagram | Architecture diagram | Clause 5.3 architecture document |
| Software design specification | Not in the submission (kept in the design history file) | Required | Clause 5.4 detailed design — which IEC 62304 requires only at Class C, so an Enhanced Class B system produces it for FDA even though the standard does not demand it |
| Software development, configuration management and maintenance practices | Summary of processes, or a declaration of conformity to IEC 62304 covering specified clauses | Complete plan documents, or a declaration of conformity to IEC 62304 covering a broader set of clauses including the whole of 5.1 | The development plan and its supporting plans; the configuration management plan; the maintenance plan — or the IEC 62304 compliance statement |
| Software testing as part of verification and validation | Summary descriptions plus system-level test protocols and reports | Unit, integration and system-level protocols and reports | Clauses 5.5–5.7 records; at Basic, the 5.7 system test records carry it |
| Software version history | Required | Required | The released versions register and 5.8.4 release records |
| Unresolved software anomalies | Required | Required | The 5.8.2 known residual anomalies list, with impact on safety and effectiveness and the rationale for not fixing each — 5.8.3’s evaluation at Class B and C |
Two rows repay attention. The development-practices element is where the IEC 62304 FDA guidance relationship becomes explicit: FDA will accept a declaration of conformity to IEC 62304 in place of describing your processes, at either level, with the set of clauses declared depending on the level. That is the payoff for keeping a clean compliance statement. And the software design specification row shows the levels and the classes pulling apart: FDA wants detailed design at Enhanced regardless of class, while IEC 62304 requires it at Class C only.
IEC 62304 FDA guidance on cybersecurity: the fourth instrument
For a “cyber device” — one that includes software, connects to the internet and could be vulnerable to cybersecurity threats — section 524B of the Federal Food, Drug, and Cosmetic Act, in force for submissions from 29 March 2023, adds requirements the IEC 62304 FDA guidance mapping above does not cover: a plan to monitor, identify and address post-market vulnerabilities; processes providing reasonable assurance of cybersecurity; and a software bill of materials. FDA’s separate premarket cybersecurity guidance sets out the expected content — first finalised in September 2023, reissued on 27 June 2025 with a new section on 524B, and revised on 27 February 2026 to align with the QMSR.
IEC 62304 supplies the security requirements of 5.2.2 e) and the SOUP register that becomes the SBOM’s human-readable twin — see our guide to SOUP under IEC 62304 — but the threat model and security testing come from IEC 81001-5-1, which regulators treat as the recognised route.
The QMSR and the IEC 62304 FDA guidance stack
The last layer of the IEC 62304 FDA guidance stack is the quality system. From 2 February 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, with FDA-specific additions on records, complaint files and labelling controls. For a software manufacturer this closes a gap: IEC 62304 assumes an ISO 13485-shaped QMS around it, and the US quality system now is one. Our QMSR vs ISO 13485 comparison covers the additions; the IEC 62304 vs ISO 13485 guide covers where each software activity lands in the design controls.
Using the IEC 62304 FDA guidance mapping to assemble a submission
- Determine the Documentation Level against the four Enhanced triggers, record the rationale, and note the IEC 62304 class separately.
- Decide whether to declare conformity to IEC 62304 for the development-practices element. If so, the compliance statement and the internal audit behind it are the evidence; make sure the declared clauses match the level.
- Pull the elements from the development file in the order the guidance lists them; the software development file index is the contents page.
- At Enhanced, add what IEC 62304 may not have required: a detailed design specification if the class is B, and the unit and integration test protocols and reports.
- Write the unresolved anomalies list from the release record, with each anomaly’s impact on safety and effectiveness and the rationale for shipping with it.
- For a cyber device, add the 524B elements — threat model, SBOM, vulnerability management plan, security testing.
The IEC 62304 Toolkit carries a mapping document that takes each element of FDA’s June 2023 guidance to the toolkit deliverable that supplies it at Basic and Enhanced level, alongside the compliance statement template a declaration of conformity rests on, and the release records the version history and anomalies list are drawn from. The guidance’s availability notice is on the Federal Register; the guidance itself is on FDA’s website.
Frequently asked questions
Does FDA require IEC 62304?
No. FDA recognises it as a consensus standard, which means a declaration of conformity is an accepted way to satisfy parts of the software documentation — notably the development, configuration management and maintenance practices element. A manufacturer may instead describe its processes directly.
Is Enhanced Documentation the same as IEC 62304 Class C?
No. Enhanced is triggered by a probable risk of death or serious injury before mitigation, or by combination-product, blood-related or Class III status. Class C is decided after external risk controls are credited. They often coincide and often do not; record both.
Which IEC 62304 FDA guidance replaced the Level of Concern?
The June 2023 Content of Premarket Submissions for Device Software Functions, which superseded the May 2005 guidance and its Minor, Moderate and Major Levels of Concern with the two Documentation Levels.
Under the IEC 62304 FDA guidance mapping, does a Basic-level submission need unit test reports?
Not in the submission. Basic asks for summary descriptions plus system-level test protocols and reports; unit and integration protocols and reports are Enhanced. They still have to exist in the design history file where IEC 62304 requires them for the class.