SAMD
In the US, software with a medical purpose is regulated by the FDA as a medical device, typically via the 510(k) or De Novo pathway. The FDA has built a clear approach to digital health and AI/ML, including Predetermined Change Control Plans (PCCPs) that let you pre-authorise certain software changes.
At Taylored Consultancy Ltd, we make software compliance clear and stress-free. From the right premarket pathway to your software lifecycle and AI change-control plan, we help you meet FDA requirements without unnecessary delays.
Clearing the path to market -
regulatory and quality expertise that gets your software safe, compliant, and ready for market.

We help you determine the right route - 510(k), De Novo, or PMA - and prepare your submission.
We assess whether your software is a regulated device function and how the FDA is likely to treat it.
We help you put a compliant software development lifecycle and documentation in place.
We build your risk management file, including software and AI/ML-specific risks.
For AI-enabled software, we help you prepare a Predetermined Change Control Plan so you can update your model within agreed limits, and align with Good Machine Learning Practice.
We review your labelling against FDA requirements for software devices.
We handle FDA registration and listing, and help foreign manufacturers appoint a US Agent.
We help you implement a QMS that meets the FDA QMSR and ISO 13485.
Regulations can feel like a headache, but they don't have to be. We make sure you're covered, compliant, and ready to sell - without unnecessary delays or legal pitfalls.
EN 62304 / IEC 62304 - Medical device software lifecycle
IEC 82304-1 - Health software products
IEC 62366-1 - Usability / human factors engineering
ISO 14971 - Risk management for medical devices
ISO 13485 - Medical devices QMS
ISO/IEC 42001 - AI management systems
ISO 9001 - General quality management
It depends on whether your CDS software meets all four criteria in the 21st Century Cures Act carve-out, namely not intended to acquire, analyse or process a signal from a device, displaying independently reviewable medical information, and not intended to be the sole basis for a clinical decision. Meet all four and you may be exempt from FDA regulation; miss even one and you're likely a regulated device requiring 510(k) or another pathway.
It depends on whether a legally marketed predicate device exists for comparison: 510(k) applies when you can demonstrate substantial equivalence to one, De Novo suits novel low-to-moderate risk software with no predicate, and PMA is reserved for the highest-risk devices requiring full clinical evidence. Choosing the right pathway early shapes your entire evidence-generation timeline, so it's worth an informed assessment before you build your submission strategy.
A Predetermined Change Control Plan (PCCP) lets you pre-authorise specific future modifications to your AI/ML software, like retraining on new data, within your original FDA submission, so you don't need a new filing every time your algorithm updates. It isn't mandatory, but for adaptive AI products it's often the difference between agile iteration and a resubmission every release cycle.
It's the FDA division dedicated to digital health, including SaMD and AI/ML-based software, coordinating policy and providing resources specifically for software developers navigating device regulation. It doesn't replace the standard review pathways, but it signals that FDA increasingly expects software submissions to speak a more software-native language around updates, cybersecurity and real-world performance than a traditional hardware submission would.
Good Machine Learning Practice (GMLP) is FDA's set of expectations for how AI/ML medical software should be developed and validated, covering data quality, model training transparency, performance monitoring and bias evaluation. Aligning your development process with GMLP principles strengthens your submission and supports any Predetermined Change Control Plan you're relying on for future model updates.
Yes. If your software qualifies as a medical device, you still need FDA establishment registration and device listing even though there's nothing physical to manufacture or ship. It's a common surprise for software-only companies who assume registration is only for hardware makers. We help software teams handle this alongside their premarket submission so nothing falls through the cracks at launch.
Still have questions? Contact us and we'll be happy to help.