IEC 62304 Edition 2 has been “coming soon” for the better part of a decade, and in 2026 it slipped again. If you are deciding whether to wait for it, build to it, or ignore it, the useful facts are these: the edition in force is still IEC 62304:2006 + Amendment 1:2015 (Edition 1.1); the second edition is at committee-draft stage; publication is not expected before 2028; and a regulatory transition of two to three years would follow publication. Nothing you build today should cite Edition 2 as a requirement.
This guide sets out the IEC 62304 Edition 2 timeline as it stood on 13 September 2026, what the draft is understood to change, what will not change, and what a manufacturer should actually do about it now.
What this guide covers
- IEC 62304 Edition 2 timeline: where it stands
- What IEC 62304 Edition 2 is understood to change
- What Amendment 1 already did — and why it matters for IEC 62304 Edition 2
- Why IEC 62304 Edition 2 keeps slipping
- What this means for a manufacturer today
- How to check the IEC 62304 Edition 2 status yourself
- Frequently asked questions

IEC 62304 Edition 2 timeline: where it stands
| Date | Event | Status |
|---|---|---|
| May 2006 | IEC 62304 first edition published | Done |
| June 2015 | Amendment 1 published; consolidated as Edition 1.1 — added the legacy software route (4.4) and the risk-based classification wording | Done — the edition in force |
| 2015 onward | Second edition in development by the joint IEC SC 62A / ISO TC 210 working group on medical device software; earlier drafts did not proceed to publication | Restarted |
| 2025 | Committee Draft (CD) circulated for comment; drew a very large number of comments — around 1,500 by the accounts of committee participants | Done |
| 2026 | Second Committee Draft (CD2) prepared following comment resolution | In progress at the time of writing |
| 2028 or later | Final Draft International Standard (FDIS) — the vote-only stage before publication | Forecast |
| October 2028 | IEC’s published forecast publication date at the time of writing; committee participants have suggested 2029 is possible | Forecast |
| Publication + 2–3 years | Regulatory transition — FDA recognition of the new edition, notified bodies moving their state-of-the-art expectation to it and, in time, any EN listing under the MDR/IVDR | Expected pattern, not yet scheduled |
Two things about that IEC 62304 Edition 2 table are worth pausing on. First, a claim circulated in 2025 and early 2026 that Edition 2 would publish in August 2026; it did not, and the source of that claim has since corrected it. Second, the IEC’s own listing for the current consolidated version carries a stability date of 2028 — the IEC’s statement that the text is not expected to change before then. Both point the same way.
What IEC 62304 Edition 2 is understood to change
The draft text is not public, and everything below comes from committee participants and from the working-group summaries published by consultancies close to the process — chiefly the Johner Institute, which has tracked the drafts in detail. Treat it as a description of direction, not of final wording.
| Area | Edition 1.1 today | IEC 62304 Edition 2 direction |
|---|---|---|
| Scope | Medical device software — software that is a device or embedded in one | Extended toward health software generally, aligning with IEC 82304-1; fitness and wellness applications and other standalone health software come within reach |
| Risk management | An ISO 14971 process is mandatory (clause 4.2) | ISO 14971 becomes the default rather than the only route; a manufacturer may justify an alternative approach — subject, in practice, to what regulators and notified bodies accept |
| Security | Security appears only as a content area of the software requirements (5.2.2 e)) | A security threat management concept sits alongside safety risk management; requirements address safety and security together |
| Usability | Points to IEC 62366-1 for user-interface requirements | Risks from lack of fitness for purpose are managed explicitly; IEC 62366 is no longer a mandatory dependency, which is what lets the standard apply beyond medical devices |
| Structure | Clauses 4–9: general, development, maintenance, risk, configuration management, problem resolution | Broadly retained; the life cycle process model is expected to survive |
What is not expected to change is the thing most teams worry about: the three software safety classes and the process-selection logic behind them. Our guide to software safety classification describes the Edition 1.1 rules, and nothing in the public account of IEC 62304 Edition 2 suggests a different scheme.
What Amendment 1 already did — and why it matters for IEC 62304 Edition 2
Some of what people expect from IEC 62304 Edition 2 arrived in 2015. Amendment 1 added the legacy software route in clause 4.4, so that software already on the market could be brought into compliance through a gap analysis rather than a reconstructed life cycle; it rewrote the classification wording so that risk control measures outside the software are credited before the class is decided, and made Class C the default for any system not yet classified; and it added the requirement for a procedure identifying common software defects for the programming technology in use.
A manufacturer that has not absorbed those changes is behind Edition 1.1, never mind Edition 2 — and our guide to SOUP under IEC 62304 covers one area where the consolidated edition is routinely under-applied.
Why IEC 62304 Edition 2 keeps slipping
Three reasons, all structural. The scope extension to health software means the standard has to work for products with no regulator and no ISO 13485 QMS behind them, which strains every clause that currently assumes one. The addition of security means reconciling a new life cycle concept with IEC 81001-5-1, which was published in 2021 to do exactly that job on top of Edition 1.1. And the standard is developed jointly by IEC and ISO committees, so every resolution has to satisfy two parent bodies. Around 1,500 comments on a single committee draft is the visible symptom.
What this means for a manufacturer today
Build and claim compliance to Edition 1.1
Edition 1.1 is the edition FDA recognises and the edition notified bodies expect as state of the art under the EU MDR and IVDR — note that EN 62304 is not on the Commission’s harmonised lists under either regulation, so it is applied as state of the art rather than for a presumption of conformity (see our guide to MDR harmonised standards). A compliance statement in a technical file cites it. Citing a draft is not an option: drafts have no standing, and their text changes.
Expect a long overlap, not a cliff
When a new edition of a standard regulators rely on is published, the previous edition normally remains acceptable for a transition period — commonly two to three years — during which either may be cited; where a standard is harmonised, the Official Journal sets a date of cessation, and where it is applied as state of the art, notified bodies and FDA signal the change. Devices already on the market have not, in previous transitions, been required to redo their software file on publication day. Our guide to the EU MDR covers the conformity mechanics.
Do the two things the draft points at anyway
Both of the substantive IEC 62304 Edition 2 directions — security and health software scope — already have standards you can apply now. IEC 81001-5-1:2021 supplies a security life cycle that mirrors IEC 62304’s clause structure, and regulators on both sides of the Atlantic already expect it for connected devices. IEC 82304-1:2016 supplies the product-level requirements for software-only products; our IEC 62304 vs IEC 82304-1 comparison covers how it wraps the software life cycle. A manufacturer applying both today is doing most of what Edition 2 is expected to ask for.
Put the watch in one document
The failure mode with a moving target is scattering dated claims across a hundred files. Keep a single regulatory currency record that states the edition in force, the Edition 2 stage and forecast, the harmonisation and recognition position, and the date each was last checked against its primary source — then update one document, not the pack.
How to check the IEC 62304 Edition 2 status yourself
- IEC webstore, publication page for IEC 62304:2006+AMD1:2015 CSV — the stability date and any “replaced by” notice appear here first.
- IEC project database — the project stage for the Edition 2 work item (CD, CDV, FDIS) and its forecast dates.
- Official Journal of the EU — whether a new EN edition has been listed under the MDR and IVDR, and the date of cessation for the old one.
- FDA Recognized Consensus Standards database — which edition FDA recognises and any transition note.
- Committee-adjacent commentary — the Johner Institute’s running account is the most detailed public source on the drafts; read it as informed commentary, and confirm dates against the IEC.
The IEC 62304 Toolkit is written to Edition 1.1 and says so in every document; its Regulatory Currency Supplement carries the IEC 62304 Edition 2 status, the harmonisation and recognition position and a release-day checklist for confirming each against the primary source, so the pack’s currency is a checked fact rather than an assumption. It also ships mappings to IEC 81001-5-1 and IEC 82304-1 — the two standards that already cover the ground Edition 2 is heading for.
Frequently asked questions
When will IEC 62304 Edition 2 be published?
Not before 2028, on the public evidence as at September 2026. The second edition is at committee-draft stage; the IEC’s forecast publication date at the time of writing was October 2028, and committee participants have suggested 2029 is possible. Check the IEC project database for the current stage.
Should I wait for IEC 62304 Edition 2 before starting a project?
No. Edition 1.1 is the edition in force, the edition FDA recognises and the state of the art notified bodies expect under the MDR and IVDR. A project started today will most likely release, and be assessed, under it — and a transition period would follow publication in any case.
Will Edition 2 change the software safety classes?
Nothing in the public account of the drafts suggests it. The classes and the process-selection logic are expected to survive; the changes described are to scope, security and the risk management dependency.
Does IEC 62304 Edition 2 replace IEC 81001-5-1?
No. IEC 81001-5-1 was published in 2021 to add security activities on top of IEC 62304’s life cycle, and remains the security standard regulators point at. Edition 2 is expected to reference security threat management, not to absorb the security standard.