Kaamos

Framework reference

MDR / IVDR for EU B2B software companies.

MDR and IVDR apply when software qualifies as medical-device software or in vitro diagnostic software in the EU. Digital health companies need to connect product risk, cybersecurity, clinical claims, quality processes, and evidence from early product development onward.

Kaamos support
Information only
Category
Binding EU regulations
Obligation
Binding
Last updated

The obligation, in the act's words

Manufacturers shall set out minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorised access, necessary to run the software as intended.

Annex I, Section 17.4, Regulation (EU) 2017/745 (MDR); same wording at Annex I, Section 16.4, Regulation (EU) 2017/746 (IVDR)

Security requirements are part of the device's general safety and performance requirements, so they travel with the technical documentation.

Who it applies to

  • Medical-device software and standalone clinical or diagnostic applications.
  • Digital health companies placing regulated software on the EU market.
  • Suppliers supporting regulated medical-device workflows.

What you need to do

  • Product classification, quality management, risk management, technical documentation, and post-market surveillance.
  • Cybersecurity and software lifecycle evidence.
  • Traceability between product risk, controls, testing, and changes.

How to use this entry

  • Use this page to understand the buyer or regulatory pressure before it becomes a deadline.
  • Run the regulation checker to see whether this area is likely to matter for your company now.
  • If it becomes relevant, Kaamos can help you scope the gap and turn it into prioritized security work.

Sources

Information bank

MDR / IVDR is included as an information-bank entry. Use it to understand the pressure, then run the checker to see whether it should enter your roadmap.