SAMD
When software has a medical purpose, it's a medical device under the EU Medical Device Regulation (EU 2017/745). Qualification and classification follow MDCG 2019-11 and Rule 11 - which places most clinical software in Class IIa or above - and the EU AI Act now layers additional obligations onto AI-enabled devices.
At Taylored Consultancy Ltd, we make software compliance clear and stress-free. From qualification and classification to your technical documentation and AI Act readiness, we help you CE mark and meet EU requirements without unnecessary delays.
Clearing the path to market -
regulatory and quality expertise that gets your software safe, compliant, and ready for market.

We assess your software against MDCG 2019-11 and Rule 11 to confirm whether it's a medical device and which class applies.
We help you put a compliant software development lifecycle in place, with the documentation a Notified Body expects.
We help you compile clinical evidence and a Clinical Evaluation Report to support CE marking.
We build your risk management file, including software and AI/ML-specific risks.
We help you evidence usability and human-factors work for safe use.
For AI-enabled devices, we help you understand and prepare for the AI Act obligations that sit alongside EU MDR.
Non-EU manufacturers need an EU Authorised Representative and EUDAMED registration. We act as your EC REP and handle registration.
We help you prepare for and respond to Notified Body assessment of your technical documentation and QMS.
We help you implement a QMS to ISO 13485, the backbone of software medical device compliance.
Regulations can feel like a headache, but they don't have to be. We make sure you're covered, compliant, and ready to sell - without unnecessary delays or legal pitfalls.
EN 62304 / IEC 62304 - Medical device software lifecycle
IEC 82304-1 - Health software products
IEC 62366-1 - Usability / human factors engineering
ISO 14971 - Risk management for medical devices
ISO 13485 - Medical devices QMS
ISO/IEC 42001 - AI management systems
ISO 9001 - General quality management
Rule 11 of the EU MDR is written specifically for software, and it pushes most clinical software into class IIa, IIb or even III depending on the significance of the information it provides and the healthcare situation it's used in, far higher than manufacturers typically assume. Even simple diagnostic support tools can land in IIa or above. Getting this classification right from the start avoids a costly redesign of your technical documentation later.
Most software above class I under Rule 11 requires Notified Body involvement, meaning an accredited third-party organisation audits your technical documentation and quality system before you can CE mark. Only very low-risk class I software can self-certify. Notified Body capacity is limited and timelines can run long, so early engagement and a complete technical file matter more for software than for many other device types.
MDCG 2019-11 is the official EU guidance explaining how to qualify and classify software as a medical device under MDR, including worked examples that clarify borderline cases like wellness apps versus genuine clinical tools. It's the reference document Notified Bodies and regulators use to check your qualification logic, so your technical file needs to align with its reasoning, not just the wording of the regulation itself.
If your software uses AI for a medical purpose, it's very likely to be classed as high-risk under the EU AI Act and subject to its own conformity requirements, which run alongside, not instead of, your MDR obligations. The two frameworks need to be satisfied together, particularly around data governance, transparency and human oversight. We help clients map both requirements into one coherent technical file rather than duplicating the work.
IEC 62304 sets out the software development lifecycle process Notified Bodies expect to see evidenced, covering planning, requirements, architecture, verification, and change and problem-resolution processes, mapped to your software's safety classification (A, B or C). It's not paperwork for its own sake; auditors use it to judge whether your development process could reliably catch defects before they reach patients.
Yes. Any manufacturer without a registered place of business in the EU must appoint an EU Authorised Representative before placing software on the EU market, and that representative is legally responsible alongside you for compliance and EUDAMED registration. It's not a formality; choose one with genuine software and SaMD expertise, since generic device experience often misses the software-specific requirements.
It's generally a smooth administrative process rather than a regulatory hurdle. Your new EU Authorised Representative takes on your existing technical documentation and EUDAMED registration, confirms your software details are current, and updates the Authorised Representative information in the portal and on your labelling. We manage that handover directly with your previous provider, so your product stays compliant and on sale throughout the switch.
An EU Authorised Representative carries legal accountability for your software across the EU market, covering EUDAMED registration, holding technical documentation available for inspection, handling vigilance reporting, and acting as the contact point for national competent authorities if the product is ever questioned. It's a standing obligation for as long as the software is on sale, not something that ends once the initial registration is filed.
Yes, in most cases. EU MDR requires labelling and instructions for use, including in-app text that counts as IFU content, to be provided in the official language of the member state where the software is being made available, so a technical file built for one EU country typically needs local-language versions before it can be sold elsewhere. Your underlying technical documentation and classification stay the same; it's the user-facing content that needs handling market by market.
Still have questions? Contact us and we'll be happy to help.