In Vitro Diagnostic Medical Devices Regulation, Software Development, Information Security and IT Security Information Requirements
Regulation (EU) 2017/746, Annex I, sections 16.2, 16.4 and 20.4.1(ah)
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- Security, Disclosure
As of .
What it requires
- It reaches you if you are a manufacturer that places on the EU market, or puts into service, an in vitro diagnostic medical device, which includes software intended by the manufacturer to be used in vitro for the examination of specimens derived from the human body, whether the software is incorporated in a device or is a device in itself (Articles 2, point (2), and 10(1)).
- Develop and manufacture the software in accordance with the state of the art, taking into account the principles of development life cycle, risk management, including information security, verification and validation (Annex I, section 16.2).
- Where the software is intended to be used in combination with mobile computing platforms, design and manufacture it taking into account the specific features of the mobile platform and the external factors related to their use (section 16.3).
- Set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorized access, necessary to run the software as intended (section 16.4).
- Include those minimum requirements in the instructions for use of a device that incorporates electronic programmable systems, including software, or of software that is a device in itself (section 20.4.1, point (ah)).
- A device with a valid certificate issued under Directive 98/79/EC, or one declared to conform under that Directive without a notified body, may be placed on the market or put into service until the dates fixed in Article 110(3a) and (3b) only if the conditions of Article 110(3c) are met.
Who enforces it
Enforcement body
The competent authorities of the Member States, which perform market surveillance checks on devices under Article 88.
What this law does
Article 1(1) applies the In Vitro Diagnostic Medical Devices Regulation to the placing on the market, making available on the market or putting into service of in vitro diagnostic medical devices for human use and accessories for such devices in the Union.
Article 2, point (2), defines an in vitro diagnostic medical device as any medical device which is a reagent, reagent product, calibrator, control material, kit, instrument, apparatus, piece of equipment, software or system, intended by the manufacturer to be used in vitro for the examination of specimens derived from the human body, solely or principally to provide information on listed matters.
Article 2, point (23), defines a manufacturer as a natural or legal person who manufactures or fully refurbishes a device or has a device designed, manufactured or fully refurbished, and markets that device under its name or trademark. Under Article 10(1), a manufacturer placing a device on the market or putting it into service must ensure that it has been designed and manufactured in accordance with the requirements of the Regulation.
Section 16.2 of Annex I requires software that is a device in itself, or that is incorporated in a device, to be developed and manufactured in accordance with the state of the art, taking into account the principles of development life cycle, risk management, including information security, verification and validation.
Section 16.3 adds that such software intended to be used in combination with mobile computing platforms must be designed and manufactured taking into account the specific features of the mobile platform and the external factors related to their use. Section 16.4 requires manufacturers to set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorized access, necessary to run the software as intended.
Section 20.4.1, point (ah), requires the instructions for use of a device that incorporates electronic programmable systems, including software, or of software that is a device in itself, to contain those minimum requirements concerning hardware, IT networks characteristics and IT security measures. Article 113(2) provides that the Regulation applies from .
Article 110, as amended by Regulation (EU) 2024/1860, lets devices with a valid certificate issued under Directive 98/79/EC, and certain devices declared to conform under that Directive without a notified body, be placed on the market or put into service until dates fixed in that Article, provided the conditions of its paragraph 3c are met. Article 106 leaves the rules on penalties to the Member States, which the Article requires to be effective, proportionate and dissuasive.
Article 88(1) requires the competent authorities to perform appropriate checks on the conformity characteristics and performance of devices.
When LexLint raises it
When your app profile says your app distributes a software product or ships a mobile app.