Medical Devices Regulation, Software Development, Information Security and IT Security Information Requirements
Regulation (EU) 2017/745, Annex I, sections 17.2, 17.4 and 23.4(ab)
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- Security, Disclosure
As of .
What it requires
- It reaches you if you are a manufacturer that places on the EU market, or puts into service, a medical device, which includes software intended by the manufacturer to be used for human beings for a specific medical purpose, whether the software is incorporated in a device or is a device in itself (Articles 2, point (1), 5(2) and 10(1)).
- Develop and manufacture the software in accordance with the state of the art, taking into account the principles of development life cycle, risk management, including information security, verification and validation (Annex I, section 17.2).
- Where the software is intended to be used in combination with mobile computing platforms, design and manufacture it taking into account the specific features of the mobile platform and the external factors related to their use (section 17.3).
- Set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorized access, necessary to run the software as intended (section 17.4).
- Include those minimum requirements in the instructions for use of a device that incorporates electronic programmable systems, including software, or of software that is a device in itself (section 23.4, point (ab)).
- A device with a valid certificate issued under Directive 90/385/EEC or Directive 93/42/EEC may be placed on the market or put into service until the dates fixed in Article 120(3a) and (3b) only if the conditions of Article 120(3c) are met.
Who enforces it
Enforcement body
The competent authorities of the Member States, which perform market surveillance checks on devices under Article 93.
What this law does
Article 1(1) applies the Medical Devices Regulation to the placing on the market, making available on the market or putting into service of medical devices for human use and accessories for such devices in the Union.
Article 2, point (1), defines a medical device as any instrument, apparatus, appliance, software, implant, reagent, material or other article intended by the manufacturer to be used, alone or in combination, for human beings for specific medical purposes such as diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease.
Article 2, point (30), defines a manufacturer as a natural or legal person who manufactures or fully refurbishes a device or has a device designed, manufactured or fully refurbished, and markets that device under its name or trademark. Article 5(2) requires a device to meet the general safety and performance requirements set out in Annex I which apply to it, taking into account its intended purpose.
Under Article 10(1), a manufacturer placing a device on the market or putting it into service must ensure that it has been designed and manufactured in accordance with the requirements of the Regulation.
Section 17.2 of Annex I requires software that is a device in itself, or that is incorporated in a device, to be developed and manufactured in accordance with the state of the art, taking into account the principles of development life cycle, risk management, including information security, verification and validation.
Section 17.3 adds that such software intended to be used in combination with mobile computing platforms must be designed and manufactured taking into account the specific features of the mobile platform and the external factors related to their use. Section 17.4 requires manufacturers to set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorized access, necessary to run the software as intended.
Section 23.4, point (ab), requires the instructions for use of a device that incorporates electronic programmable systems, including software, or of software that is a device in itself, to contain those minimum requirements concerning hardware, IT networks characteristics and IT security measures. Article 1(8) of Regulation (EU) 2020/561 replaced the date of application in Article 123(2) with .
Article 120, as replaced by Regulation (EU) 2023/607, lets devices with a valid certificate issued under Directive 90/385/EEC or Directive 93/42/EEC be placed on the market or put into service until dates fixed in that Article by device class, provided the conditions of its paragraph 3c are met. Article 113 leaves the rules on penalties to the Member States, which the Article requires to be effective, proportionate and dissuasive.
Article 93(1) requires the competent authorities to perform appropriate checks on the conformity characteristics and performance of devices.
When LexLint raises it
When your app profile says your app distributes a software product or ships a mobile app.