SAMD
Software medical devices are regulated differently across the world, but most frameworks share the same DNA - the IMDRF SaMD model, a quality-managed software lifecycle, and reliance on CE or FDA approvals to open doors elsewhere.
At Taylored Consultancy Ltd, we help you build a robust, internationally-minded foundation - your lifecycle, risk and clinical evidence - then advise you closely on each market you're targeting so your software travels with the least friction.
Clearing the path to market -
regulatory and quality expertise that gets your software safe, compliant, and ready for market - wherever you launch.

We help you plan a route to market across multiple countries, prioritising the approvals that unlock the most markets.
We assess your software against the internationally harmonised IMDRF SaMD framework adopted in varying forms worldwide.
We help you build a compliant, internationally-recognised software development lifecycle.
We build your risk management file (ISO 14971) and help you address AI-specific governance (ISO/IEC 42001, Good Machine Learning Practice).
We help you leverage CE or FDA approvals through the reliance routes many markets offer.
Almost every market requires a local representative. We help you understand and arrange the right one.
We help you implement a QMS to ISO 13485 - the universal baseline for software medical devices.
Every market has its own rules, and the detail matters. Get in touch for a free consultation and we'll map out exactly what your product needs, wherever you're headed.
EN 62304 / IEC 62304 - Medical device software lifecycle
IEC 82304-1 - Health software products
IEC 62366-1 - Usability / human factors engineering
ISO 14971 - Risk management for medical devices
ISO 13485 - Medical devices QMS
ISO/IEC 42001 - AI management systems
ISO 9001 - General quality management
The IMDRF framework categorises SaMD from I to IV based on two factors. These are the significance of the information your software provides to a healthcare decision, and the seriousness of the healthcare situation it's used in. Most national regulators, from the UK to Australia to the UAE, build their own classification rules on this same underlying logic, so understanding your IMDRF category early gives you a reliable baseline before adapting to each market.
Often, yes, at least partially. Many jurisdictions, including the UAE and parts of the GCC, offer recognition or reliance pathways that accept prior CE marking or FDA clearance as supporting evidence for faster local registration. It's rarely a straight pass-through though; you'll typically still need market-specific technical documentation, labelling and local representation. Sequencing your target markets around where you already have approvals can save real time and cost.
There's no single right answer. It depends on where your priority customers are, but many companies start with the market that gives them the most reusable evidence, since a strong technical file built to one major framework's standard usually transfers well to others sharing IMDRF's underlying logic. We help clients sequence markets strategically rather than tackling each one from scratch, which is where most of the wasted time in global expansion actually comes from.
Yes, and it catches a lot of founders out. Even though most frameworks share IMDRF's core logic, the specific classification thresholds, categories and evidence requirements are set independently by each regulator, so software that's low-risk in one jurisdiction can be classified significantly higher in another. Planning your classification market by market, rather than assuming one result applies everywhere, avoids delays late in your expansion timeline.
At minimum, you need a robust software lifecycle file built to IEC 62304, a risk management file under ISO 14971, and clinical evidence proportionate to your IMDRF risk category. This core package forms the backbone that most jurisdictions' local requirements build on top of. Getting this foundation right once, rather than rebuilding it per country, is what actually makes multi-market expansion efficient.
Yes. AI-based software faces an extra layer of jurisdiction-specific requirements on top of standard SaMD rules, from the EU AI Act's high-risk provisions to FDA's Good Machine Learning Practice expectations, and these don't always align neatly with each other. Building AI governance evidence, such as alignment with ISO/IEC 42001, into your core technical file early makes it much easier to adapt as you enter each new market.
Not always from scratch. Your clinical evaluation and verification and validation evidence is often reusable across markets provided the software, its intended use and its algorithm stay the same, and some regulators will lean on an existing CE mark or FDA clearance rather than demanding entirely new evidence. What does still need addressing per market is local technical documentation and registration, plus any market-specific requirements such as the UK's DTAC for NHS software. We review what you already have before recommending any new work.
Yes. Claims compliance doesn't stop at your product listing, so we review marketing wherever it appears, including your website, social media, paid advertising and influencer or affiliate content, since regulators treat all of these as regulated marketing for a medical device. It's often overlooked material like a website claim or a paid ad headline that creates risk, even when the technical file itself is solid.
Yes, horizon scanning is part of our ongoing support. We track upcoming changes to UK MDR, EU MDR, the EU AI Act and other regional software-specific requirements across the markets you sell in, so you hear about a change that affects your product before it becomes a compliance problem, rather than finding out after the fact. It's built into our ongoing compliance service rather than something you need to ask for separately.
We're members of PAGB, the trade association for the UK consumer healthcare industry, which represents OTC medicines, self-care medical devices and food supplements. That connection keeps us close to how digital health and software regulation is actually developing, which feeds directly into the advice we give clients.
Still have questions? Contact us and we'll be happy to help.