<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="https://blog.cm-dm.com/feed/rss2/xslt" ?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Software in Medical Devices, by MD101 Consulting      - Comments</title>
    <link>https://blog.cm-dm.com/</link>
    <atom:link href="https://blog.cm-dm.com/feed/rss2/comments" rel="self" type="application/rss+xml" />
    <description>Blog about software medical devices and their regulatory compliance. Main subjects are software validation, IEC 62304, ISO 13485, ISO 14971, CE mark 93/42 directive and 21 CFR part 820.</description>
    <language>en</language>
    <pubDate>Mon, 08 Jun 2026 19:42:43 +0200</pubDate>
    <copyright>Property of Cyrille Michaud CC-BY-ND license</copyright>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>Dotclear</generator>
                        <item>
          <title>Proposal for MDR/IVDR changes and Rule 11 - software classification - David Grainger</title>
          <link>https://blog.cm-dm.com/post/2025/12/19/Proposal-for-MDR/IVDR-changes-and-rule-11-software-classification#c979282</link>
          <guid isPermaLink="false">urn:md5:6bb21326566252cd871b6b1ce9414935</guid>
          <pubDate>Sat, 20 Dec 2025 06:37:12 +0100</pubDate>
          <dc:creator>David Grainger</dc:creator>
          <description>&lt;p&gt;I agree. It introduces a different level of confusion :-(&lt;/p&gt;</description>
        </item>
                              <item>
          <title>How to bring legacy software into line with IEC 62304? - part 1 - Mitch</title>
          <link>https://blog.cm-dm.com/post/2013/02/06/How-to-bring-legacy-software-into-line-with-IEC-62304-part1#c976181</link>
          <guid isPermaLink="false">urn:md5:eed3c8b89b828dc8f7d10531b20b40cd</guid>
          <pubDate>Mon, 07 Apr 2025 08:36:25 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Elily
Your software isn't a legacy device, since you've applied IEC 62304 in an older version. Plan B is the plan to follow.
Your software would be legacy if you didn't have any documentation.</description>
        </item>
                              <item>
          <title>How to bring legacy software into line with IEC 62304? - part 1 - Elily</title>
          <link>https://blog.cm-dm.com/post/2013/02/06/How-to-bring-legacy-software-into-line-with-IEC-62304-part1#c975922</link>
          <guid isPermaLink="false">urn:md5:0569af35a3f25c760c55d60b5f7a732b</guid>
          <pubDate>Fri, 28 Mar 2025 04:07:41 +0100</pubDate>
          <dc:creator>Elily</dc:creator>
          <description>&lt;p&gt;Hi Mitch:&lt;/p&gt;


&lt;p&gt;Our software is developmented under IEC 62304:2006 but not IEC 62304:2006+A1:2015, is it definied as legacy sw?&lt;br&gt;
Which plan do you recommend if we want to comply with the IEC 62304:2006+A1:2015?&lt;/p&gt;


&lt;p&gt;Plan A: Do gap analysis according to the IEC 62304 clause 4.4.2-4.4.5; or&lt;br&gt;
Plan B: Review our development documents and modify them if needed to comply with clause 5 to clause 9 in IEC 62304:2006+A1:2015.&lt;/p&gt;


&lt;p&gt;In plan A, we must define the SW as legacy, right? But in plan B, we can claim the SW does not appliy to clause 4.4, right?&lt;/p&gt;


&lt;p&gt;Thanks.&lt;/p&gt;</description>
        </item>
                              <item>
          <title>When Web meets SOUP - Mitch</title>
          <link>https://blog.cm-dm.com/post/2021/03/26/When-Web-meets-SOUP#c969528</link>
          <guid isPermaLink="false">urn:md5:f8fe5a6ba59da47634809a9098af93d5</guid>
          <pubDate>Tue, 03 Sep 2024 20:23:41 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Solene&lt;br/&gt;
Thank-you for your comment and support.&lt;/br&gt;
To give a quick answer: this article is still applicable, event if new FDA guidances have been published since this article.&lt;/br&gt;
About solution 3: you may hear the sarcasm behind the wording I used in this solution. This is a quick way to park all SOUPs in the same &quot;place&quot; in the architecture. Something that may not be representative of the real architecture. Thus, I don't recommend it. This is a shortcut when you can't do otherwise.</description>
        </item>
                              <item>
          <title>When Web meets SOUP - Solenne</title>
          <link>https://blog.cm-dm.com/post/2021/03/26/When-Web-meets-SOUP#c969275</link>
          <guid isPermaLink="false">urn:md5:f73c60bbd05a0b19126f84511e0f0c90</guid>
          <pubDate>Fri, 30 Aug 2024 13:11:02 +0200</pubDate>
          <dc:creator>Solenne</dc:creator>
          <description>&lt;p&gt;Hi Mitch,&lt;br&gt;
A few years later, but thanks for this very interesting article. For SOUP management, I am not sure to understand the third solution you propose here. Would you explain it a bit further please ?&lt;br&gt;
Also, is this still applicable if we look at FDA guidelines (I read your more recent post about it as well) ?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Transition or not, your MDD SaMD may die in 2025, not 2028 - Rajesh</title>
          <link>https://blog.cm-dm.com/post/2024/04/19/Transition-or-not%2C-MDD-SaMD-will-die-in-2025%2C-not-2028#c967893</link>
          <guid isPermaLink="false">urn:md5:a15444cc852167defce399d5ba4aa0dc</guid>
          <pubDate>Sun, 02 Jun 2024 16:54:45 +0200</pubDate>
          <dc:creator>Rajesh</dc:creator>
          <description>&lt;p&gt;The end-of-support date for Windows Server 2019 depends on the type of support:&lt;/p&gt;


&lt;p&gt;Mainstream Support: This phase includes regular updates, security patches, and feature enhancements. For Windows Server 2019, mainstream support ended on January 9, 2024.&lt;br&gt;
Extended Support: During this phase, only security updates are provided. The extended support period for Windows Server 2019 extends until January 9, 2029.&lt;/p&gt;


&lt;p&gt;Yet some claim that the extended support may end in October 2029.&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Maintained software, Supported software, Required software, and SOUP - Mitch</title>
          <link>https://blog.cm-dm.com/post/2023/02/20/Maintained-software%2C-Supported-software%2C-Required-software%2C-and-SOUP#c967729</link>
          <guid isPermaLink="false">urn:md5:44a0293582940709566712f50b40758c</guid>
          <pubDate>Thu, 23 May 2024 13:56:59 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Seb&lt;br/&gt;
I've seen both cases with some manufacturers including the OS in SOUP list and some others excluding it.&lt;br/&gt;
I think IEC 81001-5-1 sheds a new light on the concept of SOUP: supported software is a software not maintained by the manufacturer. Thus purchased / installed / maintained by the user of the SaMD. This is the case of the OS for a PC or mobile software.&lt;br/&gt;
The definition of SOUP includes the word &lt;i&gt;being incorporated&lt;/i&gt;. This is not the case with a SaMD: it is installed on top of the OS. The OS isn't incorporated in the SaMD. It is a prerequisite provided by the user.&lt;br/&gt;
&lt;br/&gt;
Thus, OS isn't SOUP, in the case on SaMD.&lt;br/&gt;
Remark: if the manufacturer provides the user with the PC / mobile hardware, and the OS preinstalled in the right version, then it is questionnable to exclude the OS from SOUP.</description>
        </item>
                              <item>
          <title>Maintained software, Supported software, Required software, and SOUP - Seb</title>
          <link>https://blog.cm-dm.com/post/2023/02/20/Maintained-software%2C-Supported-software%2C-Required-software%2C-and-SOUP#c967708</link>
          <guid isPermaLink="false">urn:md5:ec375a1b5737dafe20ac154014229d9b</guid>
          <pubDate>Tue, 21 May 2024 17:36:53 +0200</pubDate>
          <dc:creator>Seb</dc:creator>
          <description>&lt;p&gt;Hi Mitch,&lt;br&gt;
You say here that OS is a supported software for mobile app (or PC application) but is it also to be considered as a SOUP regarding the IEC 62304 ?&lt;/p&gt;


&lt;p&gt;And second question : where do you place the database system (like SQL Server or other like that) ?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Final 2023 FDA Premarket Cybersecurity guidance released - Mitch</title>
          <link>https://blog.cm-dm.com/post/2023/10/06/Final-2023-FDA-Premarket-Cybersecurity-guidance-released#c967479</link>
          <guid isPermaLink="false">urn:md5:b3f068173ea47928e2752c05ab5eb972</guid>
          <pubDate>Mon, 06 May 2024 11:19:55 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Jacopo,&lt;br/&gt;
Thanks for your feedback!&lt;br/&gt;
IEC 81001-5-1 is now the reference for cybersecurity in MD. But it is a bit short for the implementation on a cybersecurity risk management process.&lt;br/&gt;
My recommendation is to use IEC 81001-5-1 together with AAMI SW96:2023, if you want to have a topnotch cybersecurity risk management process. Otherwise, you can use AAMI TIR57 as s good source of info to implement a cybersecurity risk management process.&lt;br/&gt;
IEC 29119-1:2022 can be applied to have better infos on sw testing (compared to IEC 62304). And AAMI 2700-2-1:2022 can be applied to have better infos on interoperability. It's worth noting there's an interoperability section in the FDA eSTAR submission template.</description>
        </item>
                              <item>
          <title>Cybersecurity standards: IEC 81001-5-1 and IEC/TR 60601-4-5 - Mitch</title>
          <link>https://blog.cm-dm.com/post/2021/07/09/Cybersecurity-standards%3A-IEC-81001-5-1-and-IEC/TR-60601-4-5#c967478</link>
          <guid isPermaLink="false">urn:md5:69773f55dc75f3f90419489967820fa6</guid>
          <pubDate>Mon, 06 May 2024 11:11:32 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Justine,&lt;br/&gt;
That should be ok, we're still in a transition phase.</description>
        </item>
                              <item>
          <title>Transition or not, your MDD SaMD may die in 2025, not 2028 - Mitch</title>
          <link>https://blog.cm-dm.com/post/2024/04/19/Transition-or-not%2C-MDD-SaMD-will-die-in-2025%2C-not-2028#c967477</link>
          <guid isPermaLink="false">urn:md5:5302c9841fda6c908a2190726c25dfa9</guid>
          <pubDate>Mon, 06 May 2024 11:03:53 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Houssk,&lt;br/&gt;
You're absolutely right! I didn't catch that one.&lt;br/&gt;
In this case, the manufacturer shall notify their customers to purchase the extended support, in order to continue using their SaMD.</description>
        </item>
                              <item>
          <title>IEC 81001-5-1 Right Here Right Now - Mitch</title>
          <link>https://blog.cm-dm.com/post/2024/02/23/IEC-81001-5-1-Right-Here-Right-Now#c967476</link>
          <guid isPermaLink="false">urn:md5:e4ba645f5a00fcc559911b60c5980e3b</guid>
          <pubDate>Mon, 06 May 2024 11:00:01 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Mohamed,&lt;br/&gt;
No official document has been published yet.&lt;br/&gt;
These are just feedbacks from people participating to the MDCG working groups on harmonization. Since we are close to the dealdline, it's probable that these rumors are true.</description>
        </item>
                              <item>
          <title>Medical Device lifetime and SaMD - Mitch</title>
          <link>https://blog.cm-dm.com/post/2022/02/25/Medical-Device-lifetime-and-SaMD#c967475</link>
          <guid isPermaLink="false">urn:md5:4151168d3cf01389eabc0d83c41751fd</guid>
          <pubDate>Mon, 06 May 2024 10:56:34 +0200</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>Hi Amit,&lt;br/&gt;
Unfortunately not. If it were the case, I'd have mentioned it!</description>
        </item>
                              <item>
          <title>Transition or not, your MDD SaMD may die in 2025, not 2028 - Houssk</title>
          <link>https://blog.cm-dm.com/post/2024/04/19/Transition-or-not%2C-MDD-SaMD-will-die-in-2025%2C-not-2028#c967431</link>
          <guid isPermaLink="false">urn:md5:0f307943eb35ee82de6baed805201ec6</guid>
          <pubDate>Thu, 02 May 2024 15:10:15 +0200</pubDate>
          <dc:creator>Houssk</dc:creator>
          <description>&lt;p&gt;You aren't taking into account the extended end date for Windows Server ? for example, Windows Server 2019 ending on January 9, 2029. &lt;a href=&quot;https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2019&quot; title=&quot;https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2019&quot; rel=&quot;ugc nofollow&quot;&gt;https://learn.microsoft.com/en-us/l...&lt;/a&gt;&lt;/p&gt;</description>
        </item>
                              <item>
          <title>IEC 81001-5-1 Right Here Right Now - Mohamed</title>
          <link>https://blog.cm-dm.com/post/2024/02/23/IEC-81001-5-1-Right-Here-Right-Now#c967384</link>
          <guid isPermaLink="false">urn:md5:169bcea56edfe85ab3435a6ff0b9a8f8</guid>
          <pubDate>Sat, 27 Apr 2024 09:56:36 +0200</pubDate>
          <dc:creator>Mohamed</dc:creator>
          <description>&lt;p&gt;Hi,&lt;br&gt;
Could you provide a link of the source stating that harmonization plans are postponed, please?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Medical Device lifetime and SaMD - Amit Pal</title>
          <link>https://blog.cm-dm.com/post/2022/02/25/Medical-Device-lifetime-and-SaMD#c967366</link>
          <guid isPermaLink="false">urn:md5:ff5e054bb5969c006b701bb774826876</guid>
          <pubDate>Wed, 24 Apr 2024 17:53:08 +0200</pubDate>
          <dc:creator>Amit Pal</dc:creator>
          <description>&lt;p&gt;Any one please guide how to calculate software lifetime?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>IEC 81001-5-1 Right Here Right Now - Mitch</title>
          <link>https://blog.cm-dm.com/post/2024/02/23/IEC-81001-5-1-Right-Here-Right-Now#c966680</link>
          <guid isPermaLink="false">urn:md5:cfd95641de5fc681162e09d6dc86c587</guid>
          <pubDate>Wed, 28 Feb 2024 17:30:06 +0100</pubDate>
          <dc:creator>Mitch</dc:creator>
          <description>&lt;p&gt;HI Peter,&lt;br /&gt;
Thanks for your feedback.&lt;br /&gt;
Yes, it was supposed to be harmonized by May 2024. But the MDCG WG on standards held a meeting the 19 January 2024. This report states that it is being postponed to 2028. There is no official information. But you can find it on lnkn.&lt;/p&gt;</description>
        </item>
                              <item>
          <title>IEC 81001-5-1 Right Here Right Now - Peter Olsson</title>
          <link>https://blog.cm-dm.com/post/2024/02/23/IEC-81001-5-1-Right-Here-Right-Now#c966654</link>
          <guid isPermaLink="false">urn:md5:72d333446a9a6d0339d5ef7a968874b2</guid>
          <pubDate>Mon, 26 Feb 2024 13:56:48 +0100</pubDate>
          <dc:creator>Peter Olsson</dc:creator>
          <description>&lt;p&gt;Hi,&lt;/p&gt;


&lt;p&gt;Interesting article! I have a consideration about the harmonzation of 81001-5-1 during 2028. I thought that 81001-5-1 was supposed to be harminized May 27th this year (2024)?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Cybersecurity standards: IEC 81001-5-1 and IEC/TR 60601-4-5 - Justine PRADELS</title>
          <link>https://blog.cm-dm.com/post/2021/07/09/Cybersecurity-standards%3A-IEC-81001-5-1-and-IEC/TR-60601-4-5#c964907</link>
          <guid isPermaLink="false">urn:md5:06c1388db20c5fbd0600412d97acd3ff</guid>
          <pubDate>Thu, 07 Dec 2023 18:12:02 +0100</pubDate>
          <dc:creator>Justine PRADELS</dc:creator>
          <description>&lt;p&gt;Hello,&lt;/p&gt;


&lt;p&gt;If we have a software version on the market without implementation of specifications of these standards, but we have a software version in development that includes the specifications relative to these 2 standards at May 2024 is it OK?&lt;/p&gt;</description>
        </item>
                              <item>
          <title>Final 2023 FDA Premarket Cybersecurity guidance released - Jacopo</title>
          <link>https://blog.cm-dm.com/post/2023/10/06/Final-2023-FDA-Premarket-Cybersecurity-guidance-released#c964069</link>
          <guid isPermaLink="false">urn:md5:475ea627b8e6e6e48c06ef2cb2b2aaf1</guid>
          <pubDate>Thu, 09 Nov 2023 19:36:25 +0100</pubDate>
          <dc:creator>Jacopo</dc:creator>
          <description>&lt;p&gt;Hi Mitch, great post as always!&lt;br /&gt;
What's your take on the the latest Recognized Consensus Standards from the FDA in regards to the Premarket Cybersecurity guidance?&lt;br /&gt;
It looks like AAMI SW96:2023 is now in the recognized consensus table, as well as IEC 29119-1:2022 and AAMI 2700-2-1:2022.&lt;br /&gt;
Would this change your view on applying IEC 81001-5-1 for SDLC (as well as security risk management) to a medical device development process?&lt;br /&gt;
Thanks and keep up with the great blog!&lt;br /&gt;
J.&lt;/p&gt;</description>
        </item>
            </channel>
</rss>
