Software as a Medical Device (SaMD): Classification Pitfalls
SaMD classification under EU MDR creates regulatory exposure developers discover post-launch. Marketing claims often inadvertently determine regulatory status.
Software becomes a medical device on the strength of its intended purpose, and the claim in a marketing brochure can decide a classification the engineering team never planned for. From that point the MDR expects clinical evidence built for algorithms, post-market surveillance that keeps pace with software that changes after release, and cybersecurity obligations that reach past the device into the hospital network. The commercial layer is moving as fast as the regulatory one: Germany reimburses digital therapeutics through the DiGA directory on outcome-based prices, and Switzerland offers a regulatory sandbox for digital health built on guidance rather than statute. The analyses below follow a US digital-health product from classification through evidence, vigilance, security and reimbursement, with the AI Act's second layer where the software learns.
8 insights · latest May 2026
SaMD classification under EU MDR creates regulatory exposure developers discover post-launch. Marketing claims often inadvertently determine regulatory status.
SaMD clinical evidence under EU MDR requires analytical validation, clinical validation, and real-world evidence (burdens many software developers underestimate).
SaMD post-market surveillance extends beyond incident reporting. Algorithm monitoring, vigilance, and PSUR requirements create ongoing compliance burdens.
Machine learning algorithms that evolve post-market challenge traditional regulatory frameworks built for static devices. What happens when your device learns after approval?
SaMD cybersecurity under the EU MDR, IEC 81001-5-1 and the Swiss ISG: vulnerability management, incident reporting and security updates beyond standard IT.
AI-enabled medical software reaches high-risk status through the AI Act's Annex I product route rather than Annex III, so obligations attach in 2027 and are assessed as a second layer inside MDR conformity assessment.
Switzerland's regulatory sandbox for digital health offers flexibility through guidance rather than statute. What this means for market entry strategy and timing.
Germany's Digital-Gesetz rewrote § 134 SGB V so that from 2026 at least 20 percent of a DiGA's negotiated price turns on measured outcomes, and the BfArM directory now admits Class IIb software on stricter evidence terms.
Counsel on this topic: Digital health compliance counsel.
Good questions deserve specific answers.
Get in Touch