CDSCO Releases Final Guidance on Medical Device Software under MDR 2017: What You Need to Know
Published: July 2026
On 21 July 2026, the Central Drugs Standard Control Organisation (CDSCO) rolled out the “Guidance Document on Medical Device Software under MDR-2017.” This final guidance replaces the draft issued in October 2025 and gives India’s medical software sector a much clearer set of rules to follow. Now, manufacturers, importers, software developers, and regulatory pros finally have a detailed roadmap for compliance.
This guidance lines up India with international standards and tightens expectations and requirements for software-based medical devices, from planning to post-market monitoring.
Why This Guidance Matters
Healthcare is getting more digital by the day. Software is everywhere—from diagnosis and patient monitoring to clinical decision-making and treatment planning. This guidance settles a lot of confusion. It spells out exactly which kinds of software fall under India’s Medical Devices Rules (MDR) 2017 and what companies need to do to stay on the right side of the law.
Key Highlights from the CDSCO Guidance
1. SiMD vs SaMD: What’s the Difference?
CDSCO makes a clear distinction between:
Software in a Medical Device (SiMD): This is software that’s baked into or controls hardware—like infusion pumps, MRI machines, or patient monitors.
Software as a Medical Device (SaMD): This is standalone medical software—think of AI-based diagnostic tools, clinical decision support programs, or mobile apps that analyze medical images.
Both types are regulated, but the requirements—especially around risk assessment—can be different.
2. It’s All About the Intended Medical Purpose
Just being “software” doesn’t make something a regulated medical device. If your software is meant for diagnosis, screening, clinical decision support, therapy, or treatment planning—it’s in scope. But if it’s just for general wellness, appointment booking, or simple data storage (unless it makes medical claims), it’s probably outside the MDR rules.
3. Risk-Based Classification
The guidance sticks with the MDR classification: Class A, B, C, or D, depending on things like:
— How the software is used clinically
— How critical its info is to patient care
— What happens if the software fails
— How much it drives clinical decisions
— How severe the condition it manages is
If your software is high risk, get ready for stricter oversight and more documentation.
4. Lifecycle Regulation from Start to Finish
This is a big shift—CDSCO now expects manufacturers to follow quality and compliance processes at every stage: planning, designing, development, verification, validation, release, maintenance, updates, security, and post-market tracking. It’s not just about getting approval—it’s about staying compliant as your software evolves.
5. Quality Management System (QMS)
A solid QMS isn’t optional. The guidance points to international standards like ISO 13485, IEC 62304, ISO 14971, IEC 62366, and IEC 82304-1. Manufacturers need to follow structured development, manage risks and usability, and keep thorough records.
6. Heavy Documentation
Now companies need detailed technical documentation—architecture, requirements, design, verification, validation, risk management, traceability, cybersecurity, config and update records—the works. These rules bring India in line with top global regulators.
7. Clinical Evaluation and Evidence
Clinical proof depends on your risk classification. You’ll need evaluations, possibly clinical investigations, real-world performance data, or literature supporting your claims. The riskier the software, the stronger the evidence you must show.
8. Big Emphasis on Cybersecurity
CDSCO treats cybersecurity seriously. You need formal processes for secure development, vulnerability management, managing logins and access, integrity controls, patching, updating, and ongoing risk assessment across the full lifecycle.
9. Addressing AI and Machine Learning (ML)
AI/ML-enabled software isn’t set apart in its own category—it’s regulated like any other medical software but you need to show validation, performance, risk management, and control over algorithms and updates. Transparency is key.
10. Licensing Pathways Explained
The guidance lays out how to get manufacturing, import, and test licences, plus clinical investigation permissions. It also spells out who’s in charge for each licensing step.
11. Stronger Post-Market Surveillance
Manufacturers are now expected to set up systems for complaint handling, adverse event reporting, CAPA, safety actions, regular performance reviews, and regulatory-compliant software updates. Keeping an eye on how your software performs in the real world is no longer optional.
What Does This Mean for the Industry?
A few things stand out:
— Standalone medical software (SaMD) is now clearly regulated under MDR 2017.
— Following international engineering standards isn’t just recommended—it’s expected.
— Documentation requirements are tougher and more detailed.
— Cybersecurity and end-to-end lifecycle management are getting more attention.
— AI-enabled medical software will be regulated based on use and risk, not as a totally separate category.
Really, it’s not a brand new scheme, but the CDSCO now spells out what’s expected—so companies can comply with less guesswork.
How ACPL Helps
At Accredited Consultants Pvt. Ltd. (ACPL), we cover the whole spectrum of regulatory consulting for medical device software—whether it’s SiMD or SaMD, or something with AI under the hood.
Our services include:
— Medical Device Classification
— CDSCO Licensing Support
— Regulatory Strategies for SaMD and SiMD
— Preparing Technical Documentation
— ISO 13485 Compliance
— ISO 14971 Risk Management Docs
— Clinical Evaluation
— Software Lifecycle Docs (IEC 62304)
— Cybersecurity Records
— Licence Help—Import & Manufacturing
— Gap Assessment
— Post-Market Compliance Support
If you’re developing anything from diagnostic software and mobile health apps to embedded systems, our experts guide you to compliance with confidence.
Contact ACPL
Accredited Consultants Pvt. Ltd. (ACPL)
Noida, Uttar Pradesh, India
Website: https://www.acplgroupindia.co.in
Email: info@acplgroupindia.co.in
Phone: +91-9310336522
Need help with CDSCO registration or compliance for medical device software? Get in touch with ACPL for tailored, expert support.