Requirements in the MDR – where can they be found?
Anyone wishing to place software on the market under the MDR should read the relevant sections of the regulation very carefully. The most important sections are:
Annex I, which sets out the general safety and performance requirements. For software, the requirements regarding the development process, risk management, information security, validation, and IT environment are particularly relevant here.
Annex II and Annex III govern the technical documentation as well as the requirements for post-market surveillance. For software, this also includes evidence of software verification and validation as part of the product documentation.
Annex VIII, in particular Rule 11, is central to the classification of medical software. The 2019-11 MDCG, revised in 2025, explains the three basic principles of Rule 11: software that provides information for diagnostic or therapeutic decisions; software that monitors physiological processes; and “all other software.” Depending on clinical relevance, the classification can range from Class I to Class III.
Article 52 and Annexes IX through XI describe the conformity assessment. For Class I devices, the declaration of conformity is generally issued by the manufacturer itself; for Class IIa and higher, the involvement of a Notified Body is required.
Annex XIV, finally, is the central reference for clinical evaluation and Post-Market Clinical Follow-Up (PMCF). Especially with software, this is an area that is often established systematically too late.
What's next: the EU Commission's proposed revision to Rule 11 (draft, December 2025). On 16 December 2025, the European Commission published a draft amendment to the MDR that would revise Rule 11. Early indications suggest the proposal would make Class I the default classification for medical device software unless specific higher-risk criteria are met — a response to years of criticism that Rule 11 as it stands pushes nearly all software into Class IIa or higher, regardless of actual risk.
Important: this is a draft proposal, not adopted law, and — as with earlier MDR amendment discussions — the text may well change before it is finalized, if it is finalized at all. Manufacturers should continue to classify under the current Rule 11 and MDCG 2019-11 Rev. 1 guidance today, while watching this proposal closely. DQS MED will keep this article updated as it moves through the EU legislative process.
The most important standards for medical software
The MDR specifies the regulatory requirements. In practical implementation, however, some standards are particularly important because they define the “state of the art.”
IEC 62304 is the core standard for the software lifecycle of medical software. It describes processes for the development and maintenance of software when the software itself is a medical device or an integral part of a medical device.
ISO 14971 is the reference standard for the risk management of medical devices, explicitly including Software as a Medical Device.
ISO 13485 is the central quality management standard for medical devices across the entire product lifecycle. For manufacturers seeking to establish a robust MDR-compliant organization, it serves as the practical operational foundation.
IEC 62366-1 covers usability engineering. This is particularly relevant for software because incorrect operation, misleading user guidance, or unclear alarms can have immediate safety consequences.
IEC 82304-1 is particularly relevant for health software on general IT platforms, i.e., for products without dedicated hardware. The standard addresses safety and security at the product level and is therefore of great importance for many standalone software products or Software as a Medical Device (SaMD). It is particularly noteworthy that IEC 82304-1 defines specific requirements for the validation of SaMD and is simultaneously referenced in IEC 62304, which is harmonized under the MDR.