SAMD

Software as a Medical
Device, Demystified

When software has a medical purpose, it's a medical device. In Great Britain that means the UK Medical Devices Regulations 2002 (as amended), overseen by the MHRA, with UKCA marking (CE marking still recognised under transitional arrangements) - plus the DTAC standard if you're deploying into the NHS.

At Taylored Consultancy Ltd, we make software compliance clear and stress-free. From qualification and classification to your software lifecycle and clinical evidence, we help you meet UK requirements and keep pace with the MHRA's evolving software and AI framework.

Clearing the path to market -
regulatory and quality expertise that gets your software safe, compliant, and ready for market.

Client healthcare and skincare products with a stethoscope

What We Do

Qualification & Classification

Is your software a medical device, and if so, what class? We assess intended purpose against UK rules and the IMDRF SaMD framework to confirm your regulatory status.

Software Lifecycle (IEC 62304)

We help you put a compliant software development lifecycle in place, with the documentation auditors expect.

Clinical Evaluation

We help you compile clinical evidence demonstrating your software's safety and performance.

Risk Management (ISO 14971)

We build your risk management file, including software-specific and (where relevant) AI/ML risks.

Usability Engineering (IEC 62366-1)

We help you evidence usability and human-factors work to show your software is safe to use.

DTAC Support

Deploying into the NHS? We help you meet the Digital Technology Assessment Criteria covering clinical safety, data protection, usability and interoperability.

AI & Machine Learning Support

For AI-enabled software, we help you address change management, bias and good machine learning practice - and explore routes like the MHRA AI Airlock.

UK Responsible Person & Registration

Non-UK manufacturers need a UK Responsible Person and MHRA registration. We act as your RP and handle registration.

QMS Creation (ISO 13485)

We help you implement a QMS to ISO 13485, the backbone of software medical device compliance.

No Drama, Just Compliance That Works

Regulations can feel like a headache, but they don't have to be. We make sure you're covered, compliant, and ready to sell - without unnecessary delays or legal pitfalls.

Areas of Expertise

Need expert help? Not sure where to start?

Get in touch

Frequently Asked Questions

Is my health app a medical device under UK law?

If your software has a medical purpose, meaning diagnosing, treating, monitoring or managing a condition, it likely qualifies as a medical device under the UK Medical Devices Regulations 2002 (as amended), regardless of whether it's an app, a clinical algorithm or NHS-facing software. The determining factor is intended purpose, not delivery format. We help founders pin this down early, since getting qualification wrong is the biggest cause of delayed launches.

Do I need UKCA marking or can I still use CE marking in the UK?

CE marking is still recognised in Great Britain under transitional arrangements, but UKCA marking is the UK's own conformity assessment route and will eventually become mandatory. Most software companies selling into the UK plan for UKCA now rather than treating it as a future problem, since the transitional window won't last indefinitely and MHRA continues to tighten expectations around UK-specific evidence.

What is DTAC and do I need it to sell software to the NHS?

DTAC (Digital Technology Assessment Criteria) is the NHS's baseline standard covering clinical safety, data protection, technical security, interoperability and usability. You need it to be considered for NHS procurement and deployment, and it sits alongside, not instead of, your MHRA medical device registration if your software qualifies as a device. Many clients underestimate how much technical documentation DTAC actually demands.

What is the MHRA Software and AI as a Medical Device Change Programme?

It's MHRA's ongoing work to update UK medical device regulation specifically for software and AI, covering qualification, classification and cybersecurity guidance tailored to how modern digital health products actually behave. It signals that UK regulation is evolving faster for software than for traditional hardware devices, so staying current with MHRA guidance matters more here than in many other product categories.

Who can be my UK Responsible Person if I'm not based in Britain?

A UK Responsible Person is a UK-based organisation acting on behalf of an overseas manufacturer to handle registration, technical documentation and regulatory correspondence with MHRA, required if you don't have a UK legal presence. It's a formal legal role, not just an admin function, so the appointee needs genuine regulatory competence. We act as UK Responsible Person for software clients so this doesn't become a bottleneck to launch.

How is AI-based clinical decision support software regulated in the UK?

AI-driven clinical decision support is regulated as a medical device if it's intended to inform diagnosis, treatment or care decisions, and MHRA applies the same qualification and classification logic as for any SaMD, plus extra scrutiny on algorithm transparency, bias and change management. ISO/IEC 42001 for AI management systems is increasingly useful evidence to have in place alongside your technical file.

How easy is it to switch UK Responsible Person to a new provider?

It's usually a straightforward administrative handover rather than a regulatory hurdle. Your new UK Responsible Person takes on your existing MHRA registration and technical documentation, confirms nothing about the software has changed, and updates the RP details attached to your registration. We manage that transition directly with your outgoing provider, so there's no gap in your compliance cover while the switch takes place.

What does a UK Responsible Person actually do for software as a medical device?

A UK Responsible Person is legally accountable for your software's compliance in Great Britain, which covers holding and maintaining technical documentation, registering the product with the MHRA, handling vigilance reporting for any incidents, and acting as the point of contact for the MHRA if a question arises. It's an ongoing legal responsibility for as long as the software is on the market, not a one-off registration task.

Can you help with ASA compliance for SaMD advertising and marketing?

Yes, we review software and app marketing against the UK Advertising Standards Authority's CAP Code, covering claims wording and the evidence you'd need to defend an ad if it were challenged. This sits alongside, not instead of, your wider regulatory claims obligations, so we review both together rather than treating advertising as a separate compliance track.

Still have questions? Contact us and we'll be happy to help.

Need expert help? Not sure where to start?

Get in touch