Device Area
Regulatory strategy and submissions for software as a medical device, AI/ML-enabled devices, clinical decision support, and connected devices subject to Section 524B.
This device area covers software as a medical device across clinical decision support tools, AI/ML-enabled diagnostic and triage software, and connected medical devices that exchange data over the internet, a local network, a wireless connection, or another product — the connectivity profile that brings a device within Section 524B's cybersecurity requirements.
FDA's review approach starts with the IMDRF SaMD risk framework — how significant the software's output is to a clinical decision, and how serious the underlying healthcare situation is — which in turn sets the expected software documentation level (Basic or Enhanced) for the submission. For AI/ML-enabled devices specifically, FDA looks for clinical validation evidence built on a population representative of the intended use, a properly separated train/test data split, and a Predetermined Change Control Plan when the algorithm is expected to evolve after clearance. For any device meeting the Section 524B cyber device definition, FDA expects a complete premarket cybersecurity package: threat model, machine-readable Software Bill of Materials, vulnerability management process, and a postmarket monitoring plan.
The Digital Health & Cybersecurity practice leads this device area. The Regulatory Submissions practice manages the 510(k) or De Novo filing itself, and the Clinical & IDE practice is engaged whenever a device needs a dedicated clinical validation study rather than a retrospective or literature-based evidence package.
Practice Director, Digital Health & Cybersecurity. Your practice director is named in the proposal and statement of work.
This is one of the fastest-moving areas of FDA device regulation — guidance on AI/ML, PCCPs, and cybersecurity has all been updated multiple times in the past few years, and a submission strategy built on a two-year-old understanding of FDA's expectations can be out of date before it's even filed. The practice stays current on FDA's published guidance and public workshop commentary specifically so that doesn't happen to a client's submission.
Common Questions
FDA’s risk framing follows the IMDRF SaMD risk categorization model — based on the significance of the information the software provides to a healthcare decision and the state of the healthcare situation (critical, serious, or non-serious). Higher-significance clinical decision support pushes toward a more rigorous review pathway and a correspondingly more detailed software documentation package.
FDA's software guidance defines Basic and Enhanced documentation levels based on the device's risk — Enhanced applies when a software failure or malfunction could directly result in serious injury or death to the patient or operator. The sponsor proposes the documentation level based on the device's risk profile, and FDA confirms or challenges that determination during review.
FDA expects evidence that the algorithm performs as intended on data representative of the intended use population, with a defined reference standard, a documented train/test data split preventing data leakage, and performance metrics appropriate to the clinical claim (sensitivity/specificity, AUC, or equivalent). Generic accuracy claims without population representativeness are a common deficiency.
A PCCP is relevant only if the device’s algorithm is expected to change after clearance based on new data — a locked algorithm with no retraining plan does not need one. A PCCP pre-specifies the anticipated modifications and the methodology for implementing them without requiring a new submission for each change.
Get Started
30 minutes to assess your SaMD classification and submission pathway.