Software Development for Medical Device Manufacturers

Course Summary

Participants will learn to develop cost-effective processes and procedures that will enable their organizations to deliver high quality software-based medical devices that comply with FDA regulations and international standards: FDA QSR, QMSR, EU MDR, ISO 13485, IEC 62304, ISO 14971, AAMI SW 96, IEC 62366-1.

Upcoming Events

Event Details

16 hours
This course will be presented with a live instructor using interactive web-meeting software.
Course notes and access to an extensive collection of reference documents are provided.

Description

The regulatory landscape for medical device software development is changing dramatically. Beginning in February 2026, device manufacturers must comply with the new FDA Quality Management System Regulation (QMSR) which is based on the ISO 13485 Medical Device Quality Management System Standard. In addition, a recently adopted standard for security risk management (AAMI SW96) adds additional requirements for cybersecurity.

This course provides insight into these changes as well as requirements for safety risk management as defined in ISO 14971 Medical Device Risk Management and IEC 62304 Medical Device Software – Software Life Cycle Process. Also discussed is IEC 62366-1 Medical Devices – Application of Usability Engineering.

This intensive two-day course reflects both current FDA regulations as well as the new FDA QMSR due to take effect in February 2026.

Who Should Attend

This course is intended for software engineers, project managers, quality managers, software quality professionals, RA/QA staff, and anyone who is interested in learning about cost-effective processes and procedures that will enable their organizations to deliver high quality software-based medical devices that comply with FDA regulations and international standards. This course is also appropriate for people who are new to the medical device industry. Course notes and access to an extensive collection of reference documents are provided.

Learning Objectives

Through training participants will learn to develop cost-effective processes and procedures that will enable their organizations to deliver high quality software-based medical devices that comply with FDA regulations and international standards.

Course Outline

The course content will be covered in 2 full-day sessions as outlined below. Sessions will be from 8am-5pm ET with two short breaks and a half-hour lunch break.

DAY 1 – Medical Device Software Design and Development
Duration ~8 hours
8am-5pm ET

This session will cover key regulatory requirements for medical device software in the US and EU as well as corresponding software development requirements from IEC 62304

  • Introduction
    • The new Quality Management System Regulation (QMSR)
  • Regulatory Roadmap
    • FDA QSR, QMSR, Part 11 and EU MDR
    • Medical Device Definitions – FDA and EU
  • Guidance Documents and International Standards:
    • Software-specific and Human Factors
    • ISO 13485:2016 Medical Devices – Quality Management Systems
    • IEC 62304: 2015 Medical Device Software – Software Lifecycle Processes
    • ISO 14971: 2019 Application of Risk Management to Medical Devices (Day 2)
    • IEC 62366-1:2020 Application of Usability Engineering to Medical Devices
    • ANSI/AAMI SW96:2023 Security Risk Management for Device Manufacturers (Day 2)
  • Related Regulatory Topics
    • Types of Software Regulated by FDA – SaMD and SiMD
    • FDA View of Research and Development
    • QMS Documentation Pyramid
    • ALL Software is Defective
  • Design and Development Planning (ISO-13485 7.3.2)
    • Software Development Procedure and Plan
    • Software Development Life Cycle Model
    • IEC 62304 Requirements
  • Design and Development Inputs (ISO-13485 7.3.3)
    • IEC 62304 Requirements
  • Design and Development Outputs (ISO-13485 7.3.4)
    • Architecture and Design
    • IEC 62304 Requirements
  • Design and Development Reviews (ISO-13485 7.3.5)
    • Planning and conducting Design Reviews
  • Design Controls – Verification Activities (ISO-13485 7.3.6)
    • Verification Planning
    • Technical Reviews
    • Unit, Integration and System Testing
    • Static Analysis
    • Requirements, Architecture, Design Verification
    • Unit, Integration and System Test Verification
  • Design Controls – Validation Activities (ISO-13485 7.3.7)
    • Design Validation and Software Validation
    • Comparison of Software Verification and Software Validation
    • Software Validation Planning
    • Software Testing Overview
  • Design Controls – Design Transfer (ISO-13485 7.3.8)
    • Releasing and Archiving Software
  • Control of Design and Development Changes (ISO-13485 7.3.9)
    • Engineering Change Procedure
  • Design and Development Files (ISO-13485 7.3.10)
    • MDF, DHR, DMR, RMF, UEF
  • Summary and Q&A
  • Appendix
    • FDA Quality Management System Regulation Changes
    • Good Documentation Practices
    • AI and Machine Learning Software as a Medical Device (SaMD)

DAY 2 – RISK MANAGEMENT, WRITING SOFTWARE REQUIREMENTS AND TOOL VALIDATION
Duration ~8 hours
8am–5pm ET

The morning session will cover key regulatory requirements for both Safety and Security Risk Management. Newly adopted requirements for Safety and Security Risk Management are discussed along with relevant international standards and guidance documents.

The afternoon session will cover the challenges of writing requirements for software and will discuss alternative methods for expressing requirements. The session will conclude with a discussion of Tool Validation including software development tools and software tools used in Manufacturing and QMS.

RISK MANAGEMENT OVERVIEW

Safety Risk Management Process as defined by ISO 14971:2019

  • Context for Safety Risk Management
  • Recent Device Recalls
  • Terms and Concepts
  • Risk Analysis
  • Risk Evaluation
  • Risk Control
  • Software-specific Issues
  • Risk Management Tools and Techniques – Fault Tree Analysis
  • Production and Post-production Activities
  • Documentation Repositories

Summary and Q&A 

Security Risk Management Process as defined by ANSI/AAMI SW96:2023, TIR 57:2016 2023, FDA and EU Guidance documents

  • Context for Security RM
  • Recent Security Events
  • Security Risk Analysis
  • Security Risk Evaluation
  • Security Risk Control
  • Evaluation of Security Risk Acceptability
  • Security Risk Management Review
  • Production and Post-Product Activities
  • Documentation Repositories

Summary and Q&A

APPENDIX

  • MITRE View of Threat Modeling
  • EU View of Security 

WRITING REQUIREMENTS FOR MEDICAL DEVICE SOFTWARE 

Introduction

  • Requirements – Hardest Part of Product Development
  • Requirements Family Tree
  • Types of Requirements

Challenges Expressing Requirements

  • Ambiguity and Assumptions
  • Impact of Poor Requirements

Techniques to Reduce Ambiguity

  • Start with BIG PICTURE
  • Technical Writing Best Practices
  • Alternatives to English
  • Effective Document Reviews
  • Requirements Management

Summary and Q&A

TOOL VALIDATION – Software Development Tools, Software used in Manufacturing and QMS

Regulatory Requirements

Validation Approach for Validation of: 

  • Software Development Tools
  • Software used in Manufacturing
  • Software used in Quality Management Systems

Summary and Q&A

Prerequisites

None

Instructors

FAQ

None

Customer Reviews

0
    Your Cart
    Your cart is emptyReturn to Shop
    Reap the benefits

    Login with your Membership Credentials

    Not Yet a Member? Request Membership Now

    Interested in this course for the Future?

    Thanks for letting us know!
    Please fill in the information below so that we can keep you informed.

    Name
    I'm not registering yet because
    This field is for validation purposes and should be left unchanged.



    GRANT FUNDING FOR TRAINING.

    Enhansing Skills, Advancing Quality!

    QSG has secured over $20M in training grants for companies across the USA. We specialize in expert grant writing and comprehensive support, creating tailored training solutions for organizations in states like in Massachusetts, Connecticut, Florida, Ohio, Michigan, and beyond!

    Thank you for visiting QSG!

    If you have any questions, would like more information, or would like to speak with a QSG representative, please contact us at any time!