Technological advances in health care have positioned software as an essential component of products and services for the diagnosis and analysis of clinical conditions and diseases. Although software has traditionally been included as part of medical devices, in recent years there has been an increased use of software as a medical device on its own. This situation has promoted the regulation of Software as a Medical Device (SaMD) by several regulatory agencies.
IMDRF Definition and Risk Framework for Software as a Medical Device
In 2013 the International Medical Device Regulators Forum (IMDRF) SaMD Working Group issued a document called Software as a Medical Device (SaMD): Key Definitions with the aim of creating a common definition for the software when it is considered a medical device.
According to point 5.0 of the above-mentioned document, the term “Software as a Medical Device” (SaMD) is defined as: software intended to be used for one or more medical purposes that perform these purposes without being part of a hardware medical device.
Later in 2014, the IMDRF issued another document called Software as a Medical Device: Possible Framework for Risk Categorization and Corresponding Considerations with the objective of introducing a harmonized vocabulary and considerations for manufacturers, regulators, and users of SaMD.
On January 2021, the IMDRF IVD Working group released the document titled Principles of In Vitro Diagnostic (IVD) Medical Devices Classification, in which SaMD is considered when it is used to process the output from an IVD Medical Device.
Lastly, in January 2025, the IMDRF SaMD Working Group issued the final document Characterization Considerations for Medical Device Software and Software-Specific Risk. This document builds on the previous SaMD concepts by providing considerations for the characterization of medical device software and software-specific risk. It is not intended to replace the 2014 IMDRF risk categorization framework, but to supplement it with additional considerations applicable to a broader scope of medical device software, including software that meets the definition of SaMD.
The 2025 IMDRF document highlights the importance of describing the intended use or intended purpose, software inputs and outputs, intended users, use environment, degree of autonomy, explainability, and change management characteristics. These elements may support risk assessment, regulatory decision-making, and the determination of device risk classifications according to each jurisdiction’s regulations
These documents have been considered by IMDRF medical devices members as a basis for developing their own regulations, risk classification schemes, and requirements.
Mexico SaMD Regulation: COFEPRIS, Mexican Pharmacopoeia, and NOM-241-SSA1-2025
There has been a significant development in the Mexican regulatory framework concerning SaMD. An update was made to one of the supplements of the Mexican Pharmacopoeia, which was published on the Official Journal of the Federation on May 5, 2023. This update marked the first official stance regarding Software as a Medical Device taken by Mexico.
The latest edition of the Supplement for Medical Devices, Fifth Edition, of the Mexican Pharmacopoeia, ratifies the inclusion of SaMD as a category within Medical Devices: an instrument, apparatus, utensil, machine, including software for its operation, implantable product or material, diagnostic agent, material, substance, or similar product, to be used alone or in combination, directly or indirectly, in human beings for medical purposes.
Furthermore, the update provides a specific definition for SaMD:
“Software as a Medical Device (SaMD) refers to software used with one or more medical purposes, characterized by the fact that it does not need to be part of the hardware of a medical device to fulfill its intended medical purpose. SaMD is capable of functioning on general computerized platforms and can be used independently or in combination with other products (e.g., as a module, with another medical device, etc.). Mobile apps that fit within this definition are also considered SaMD. Software that facilitates the functioning of a medical device is excluded from this definition.”
In addition, a new rule for classifying medical devices has been implemented to address SaMD. Its classification criteria are based on the software’s involvement with a patient, and whether it is critical to the patient’s health condition or parameter determination. The classification for SaMD can range from class I to III, depending on the specifications outlined in this rule.
In 2025, NOM-241-SSA1-2025, related to Good Manufacturing Practices for Medical Devices, also incorporated the term SaMD (ScDM in Spanish). According to this standard, SaMD refers to software used with one or more medical purposes, characterized by the fact that it does not need to be part of the hardware of a medical device to fulfill its intended medical purpose. It is capable of functioning on general computerized platforms and may be used independently or in combination with other products, such as modules or other medical devices. Mobile applications that meet this definition are also considered SaMD, while software that operates a physical medical device is excluded from this definition.
NOM-241-SSA1-2025 also notes that SaMD may provide means and suggestions to mitigate a disease; provide information to determine compatibility, detection, diagnosis, monitoring, or treatment of physiological conditions, health states, diseases, or congenital deformities; and serve as an aid in diagnosis, detection, monitoring, determination of predisposition, prognosis, prediction, or determination of physiological status.
USA SaMD Regulation: FDA Guidance for Device Software Functions and Mobile Medical Applications
The FDA has been a pioneer agency in developing multiple guidance documents for SaMD regulation
Along with those documents, FDA has implemented policies and programs like the Digital Health Software Precertification (Pre-Cert) Pilot Program to help in the development of a future regulatory model for software-based medical devices by monitoring real-world performance of the products in the market.
Europe: EU MDR, EU IVDR, and MDCG Guidance on Medical Device Software
According to the Medical Device definition described in Article 2 of the Regulation (EU) 2017/745 on Medical Devices (MDR), software is subject to this regulation when it is used alone or in combination for medical purposes.
On the other hand, Article 2 of Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) also considers that software is subject to this regulation when used alone or in combination for in-vitro examination of specimens derived from the human body.
In October 2019, the Medical Device Coordination Group (MDCG) of the European Commission issued the document MDCG 2019-11 Guidance on Qualification and Classification of Software in Regulation (EU) 2017/745 – MDR and Regulation (EU) 2017/746 – IVDR. The purpose of this document is to define the criteria for the classification of software within the scope of the MDR and IVDR and to provide guidance for placing Medical Device Software on the market, including applications for mobile phones or other platforms.
Two important definitions are mentioned in this document:
- Software: set of instructions that process input data and create output data.
- Medical Device Software (MDSW): software intended to be used, alone or in combination, for a purpose as specified in the definition of a “medical device” in the MDR or IVDR, regardless of whether the software is independent or driving or influencing the use of a device. MDSW may be independent, by having its own intended medical purpose and thus meeting the definition of a medical device or in vitro diagnostic medical device on its own.
Canada SaMD Regulation: Health Canada Guidance on SaMD
In 2019, Health Canada issued a Guidance Document called Software as a Medical Device (SaMD): Definition and Classification. The objective of this document is to clarify how SaMD fits into Health Canada’s regulatory framework for medical devices, based on the current interpretation of the definition of “medical device” in the Medical Devices Regulations and the Food and Drugs Act.
Using the term Software as a Medical Device (SaMD) defined by the IMDRF, Health Canada considers that software is a medical device when:
- It is intended to be used for one or more medical purposes as outlined in the definition of device in the Act, and
- It performs these purposes without being part of a hardware medical device (i.e., it is not necessary for a hardware medical device to achieve its intended medical purpose).
The interpretation of the intended use is a key consideration in the determination of SaMD.
Frequently Asked Questions (FAQ)
- When is software considered Software as a Medical Device?
Software may be considered Software as a Medical Device (SaMD) when it is intended to be used for one or more medical purposes and performs those purposes without being part of a hardware medical device. This means that the intended use of the software is a key element to determine whether it falls within the scope of medical device regulation.
- What should manufacturers consider when defining the intended use of SaMD?
Manufacturers should clearly define the medical purpose of the software, the disease or condition involved, the intended patient population, the intended users, the use environment, and the software inputs and outputs. These elements help characterize the software and support risk assessment, classification, labelling, and regulatory decision-making. The IMDRF 2025 document also highlights elements such as degree of autonomy, explainability, input sources, output type, and change management as relevant considerations for medical device software characterization.
- Can mobile applications be considered SaMD?
Yes. Mobile applications may be considered SaMD when they meet the applicable definition and are intended to be used for one or more medical purposes. For example, software that runs on a mobile platform and performs a medical device function may be regulated depending on its intended use, functionality, and potential risk to patients. FDA’s policy for device software functions explains that regulatory oversight is focused on the software function rather than the platform on which it runs.
- What should manufacturers consider before placing SaMD in the USA, Europe, Canada, or Mexico?
Manufacturers should first determine whether the software has a medical purpose and whether it meets the applicable definition of a medical device or SaMD in the target jurisdiction. They should also assess the software’s risk classification, clinical evaluation or evidence expectations, quality management requirements, labelling, cybersecurity, software lifecycle processes, and post-market obligations. In Mexico, the regulatory framework now recognizes SaMD in the Supplement for Medical Devices of the Mexican Pharmacopoeia and also includes it in NOM-241-SSA1-2025.
Conclusion
SaMD is a growing category of medical devices involving new health care technologies. Therefore, regulatory agencies worldwide are recognizing the importance of establishing regulations and guidelines for the safety and effectiveness of software. This is especially important when software is intended to be used as a standalone product for medical purposes.
If you are planning to bring your Software as a Medical Device or other medical device to the Mexican market, partner with Veraque.
Last updated: August 2026