Software & Cybersecurity (IVDR)
BPG reference: Team-NB BPG-IVDR V2 (Software, approx. pp. 26–30)
Process standard: IEC 62304; cybersecurity per applicable guidance (incl. MDCG 2019-16 spirit)
Qualification/classification: MDCG 2019-11
Checklist
- [ ] Qualification as IVD software (vs MDR) documented
- [ ] IEC 62304 safety class and SDLC documentation (plans, requirements, architecture, detailed design, unit/integration/system tests)
- [ ] Versioning, configuration management and known anomaly list controlled
- [ ] Software V&V covers claimed functions and risk controls
- [ ] Cybersecurity: threat modelling, controls, update/patch strategy, SBOM where applicable, residual-risk communication in IFU
- [ ] SOUP / third-party component inventory and assessment
- [ ] Compatibility matrix and regression strategy when used with instruments/reagents
- [ ] Software-related analytical/clinical performance claims supported in performance evaluation

