C11
Software lifecycle and cybersecurity assessment
Assessment of the software lifecycle, the safety classification, and security work. Mostly a review activity rather than a bench test.
If the product is software, this may require software lifecycle and cybersecurity assessment.
This is the only category that always applies when the software is itself the medical product.
- IEC 62304Not harmonised under the MDR
Lifecycle requirements for medical device software, including the safety classification.
Universally applied, universally expected, and not harmonised under the MDR. Most of the work is assessment rather than bench testing, which is why few laboratories hold it in an accredited scope.
Why? S052
Consolidated MDR harmonised-standards list, Implementing Decision (EU) 2021/1182 as amended, CELEX 02021D1182-20260617: absence re-verified 2026-08-17
26 laboratories in our register reference IEC 62304 in their published scope text (counted 2026-08-18). Search the register
A laboratory can hold capability that its published scope text does not itemize. Absence from these counts is not evidence of absence.