Table of Contents
Although software intended for Medical purposes has been regulated in India since the implementation of MDR, 2017 Rules. CDSCO’s Guidance Document on Medical Device Software (Doc No. CDSCO/MD/GD/MDSW/01/2026), issued on 21 July 2026, represents the first comprehensive regulatory guidance dedicated specifically to software-based medical technologies. Through Circular F. No. MED-16028/2/2025-office, CDSCO clarified regulatory expectations relating to classification, safety, performance, technical documentation, quality management, cybersecurity, and post-market obligations for Medical Device Software under the Medical Devices Rules, 2017 (MDR-2017).
India’s current regulatory approach does not establish a separate legal framework for Software as a Medical Device (SaMD). Instead, standalone diagnostic, monitoring, and clinical decision-support software products are regulated as Medical Device Software within the broader MDR-2017 framework. As a result, manufacturers must demonstrate compliance using regulatory requirements originally developed for Medical Devices in general, while also addressing software-specific considerations. The 2026 guidance is therefore a significant milestone, providing much-needed clarity on how CDSCO interprets and applies existing regulatory requirements to software throughout its lifecycle, from classification and validation to post-market surveillance and change management.
CDSCO regulates the software intended for medical purposes under MDR,2017 applying risk based approach to software products — asking what clinical decision the software informs or makes, and how much harm could follow from an incorrect output.
In line with the Guidance Document on Medical Device Software (CDSCO/MD/GD/MDSW/01/2026), software intended to diagnose, monitor, predict, screen for, or directly inform treatment decisions is subject to greater regulatory scrutiny than software intended solely for administrative, lifestyle, or general wellness functions. This reflects the broader risk-based philosophy of MDR-2017 while adapting its application to software-based products.
This means two SaMD products with very different technical architectures — say, a rules based diagnostic algorithm and an adaptive machine-learning model — may currently be evaluated through a similar classification lens focused primarily on clinical intended use, without the framework explicitly accounting for differences in how each type of software behaves, updates, or fails. While the 2026 guidance introduces software-specific considerations relating to validation, cybersecurity, and lifecycle management, the classification framework does not yet differentiate extensively between software technologies based on how they learn, evolve, update, or fail.
Global regulators have advanced further toward dedicated Software as a Medical Device (SaMD) frameworks. The IMDRF risk categorization model classifies SaMD based on the significance of the information provided to a healthcare decision and the state of the healthcare situation or condition involved. As a result, software supporting a critical clinical decision may be regulated differently from software supporting a non-critical decision, even when the underlying technology is similar. The FDA and the European Union have supplemented their Medical Device frameworks with software-specific guidance addressing areas such as software lifecycle management, cybersecurity, Clinical validation, and change management for iterative software updates. These approaches recognize that software products often evolve more rapidly than traditional hardware-based Medical Devices.
India’s regulatory approach broadly aligns with international risk-based principles but regulates Software as a Medical Device (SaMD) within the existing framework of the Medical Devices Rules, 2017 rather than through a standalone SaMD regulation. The issuance of CDSCO’s Guidance Document on Medical Device Software (CDSCO/MD/GD/MDSW/01/2026) marked a significant step by providing dedicated guidance on software classification, validation, cybersecurity, lifecycle management, technical documentation, and post-market obligations. However, unlike the IMDRF framework, India’s classification approach continues to be driven primarily by intended use and clinical risk, with limited differentiation based on software architecture, learning capability, update mechanisms, or algorithmic behaviour. As a result, manufacturers must combine compliance with general Medical Device requirements under MDR-2017 with the software-specific expectations outlined in the 2026 guidance.
For companies introducing SaMD products into India, early regulatory assessment remains essential. While the 2026 CDSCO guidance provides greater clarity on software-specific expectations, classification outcomes are still heavily influenced by intended use, clinical claims, and risk profile. Manufacturers should ensure that their documentation adequately addresses software validation, lifecycle management, cybersecurity, version control, change management, and clinical performance, alongside the traditional requirements applicable to Medical Devices. Organizations that align their quality and development processes with both CDSCO expectations and internationally recognized SaMD principles will be better positioned to support regulatory submissions, future software updates, and ongoing compliance.
CliniExperts advises digital health and SaMD companies on India market entry strategy, classification positioning, and regulatory documentation tailored to software-based products
India’s Biological Regulatory landscape is at an inflection point. The country that pioneered affordable Biosimilar access, built one of the world’s largest vaccine manufacturing ecosystem..
A Recall is one of the few regulatory events where speed of response directly influences both patient safety outcomes and a company’s regulatory standing. Yet many manufacturers only consider their ..
India
Global
Sales: +91 7672005050
Reception: +91-11-45214546
9 am to 6 pm (Monday to Friday)