support@psrcompliance.com +91 87961 04190 WhatsApp

Blog Details

CDSCO Medical Device Software Guidance 2026 explaining AI requirements, software risk classification, cybersecurity, and SaMD compliance in India
CDSCO Update

Thu, Jul 23 2026

Raju Karn

CDSCO Issues First Guidance Document for Medical Device Software in India (2026)

The healthcare industry in India is rapidly adopting digital technologies, including artificial intelligence (AI), machine learning (ML), cloud-based healthcare platforms, mobile health applications, and Software as a Medical Device (SaMD). While innovation has accelerated over the past few years, the absence of dedicated regulatory guidance for medical device software has often created uncertainty for manufacturers, developers, importers, and healthcare technology companies.

To address this gap, the Central Drugs Standard Control Organization (CDSCO) under the Ministry of Health and Family Welfare (MoHFW) has released India's first dedicated Guidance Document on Medical Device Software (MDSW) under the Medical Devices Rules (MDR), 2017. The guidance provides a structured framework for the classification, development, validation, documentation, cybersecurity, regulatory approval, and lifecycle management of software used as medical devices.

This landmark guidance is expected to improve regulatory clarity, strengthen patient safety, encourage responsible AI innovation, and align India's medical device software ecosystem with global best practices. If your company develops, imports, manufactures, or distributes medical device software in India, understanding this guidance is essential for future compliance.

What is the New CDSCO Medical Device Software Guidance?

The newly released guidance document provides comprehensive recommendations for Medical Device Software (MDSW) regulated under the Medical Devices Rules, 2017. Unlike previous regulations that focused mainly on physical medical devices, this document specifically addresses software used for medical purposes, including standalone software and software integrated into medical devices.

The guidance explains how software should be classified, documented, validated, maintained, and monitored throughout its lifecycle. It also outlines the documentation expected during licensing, import, manufacturing, clinical investigations, software updates, and post-market compliance.

Rather than introducing a completely new law, the document provides practical guidance to help applicants comply with the existing Medical Devices Rules, 2017.

Why is This Guidance Important?

Medical software is becoming an essential part of modern healthcare. Applications that assist doctors in diagnosis, monitor patients remotely, analyse medical images, or support treatment decisions can directly impact patient health.

Without a dedicated regulatory framework, manufacturers often faced uncertainty regarding documentation, risk classification, software validation, cybersecurity expectations, and regulatory submissions.

The new CDSCO guidance aims to:

  • Improve patient safety.
  • Create uniform regulatory expectations.
  • Support innovation in digital healthcare.
  • Provide greater clarity for software manufacturers.
  • Strengthen confidence in AI-powered healthcare technologies.
  • Simplify regulatory submissions under MDR-2017.

This is particularly significant for India's rapidly growing digital health ecosystem.

Who Should Follow This Guidance?

The guidance is relevant for a wide range of stakeholders involved in the healthcare technology sector.

It applies to:

  • Medical Device Software manufacturers
  • Software as a Medical Device (SaMD) developers
  • Artificial Intelligence healthcare companies
  • Machine Learning healthcare platforms
  • Medical device importers
  • Healthcare technology startups
  • Hospital software developers
  • Diagnostic software manufacturers
  • Digital therapeutics companies
  • Regulatory consultants
  • Quality assurance professionals
  • Medical device compliance teams

Even companies planning to launch innovative healthcare software in the future should become familiar with these requirements.

Major Highlights of the New CDSCO Guidance

The guidance introduces several important concepts that were previously not explained in detail under Indian medical device regulations.

1. Clear Risk Classification Framework

One of the biggest improvements is the introduction of a structured approach for classifying medical device software according to the level of healthcare risk.

Instead of considering only the software itself, the guidance evaluates:

  • The healthcare situation where the software will be used.
  • The importance of the information generated by the software.
  • The impact of the software on clinical decisions.
  • The potential consequences if the software provides incorrect information.

This makes the classification process much more transparent for manufacturers and regulatory authorities.

2. Healthcare Situation Determines Risk

The guidance explains that software risk depends largely on the healthcare situation in which it is intended to operate.

These situations generally include:

Critical Healthcare Situations

Software used where incorrect information could immediately threaten life or cause irreversible harm.

Examples include:

  • Intensive Care Units (ICUs)
  • Emergency medicine
  • Life-support monitoring
  • Critical surgical procedures

Serious Healthcare Situations

Software supporting diagnosis or treatment of serious medical conditions where delayed or incorrect decisions could significantly affect patient health.

Examples include:

  • Cancer management
  • Cardiology
  • Neurology
  • High-risk pregnancy care

Non-Serious Healthcare Situations

Software intended for routine healthcare management where incorrect outputs are less likely to cause immediate serious harm.

Examples include:

  • Wellness monitoring
  • Lifestyle applications
  • Routine health assessments
  • General health tracking

This classification approach helps manufacturers determine the appropriate regulatory pathway for their products.

The Role of Software in Clinical Decision-Making

Another important aspect clarified by CDSCO is that software classification is not based only on the disease being managed but also on how the software contributes to clinical decisions.

The guidance considers whether the software:

Treats or Diagnoses Patients

Software that directly diagnoses diseases, recommends treatment, or performs clinical analysis generally carries higher regulatory responsibility.

Drives Clinical Decisions

Some software significantly influences healthcare professionals by recommending treatments or identifying abnormalities that directly affect patient management.

Such software may fall into a higher risk category because healthcare decisions rely heavily on its outputs.

Informs Clinical Decisions

Certain software provides information that assists healthcare professionals but does not independently determine treatment.

Examples include:

  • Clinical reference tools
  • Medical image review assistance
  • Decision support systems
  • Patient monitoring dashboards

Understanding this distinction is crucial because it influences the software's overall risk classification and the level of regulatory scrutiny expected during approval. The guidance specifically requires applicants to explain the software's intended users, intended environment, analytical methodology (including AI/ML where applicable), inputs, outputs, and its contribution to healthcare interventions and clinical decision-making.

AI and Machine Learning (AI/ML) Software Receives Special Regulatory Attention

One of the most significant aspects of the new guidance is its dedicated focus on Artificial Intelligence (AI) and Machine Learning (ML) based medical device software. As AI-driven healthcare solutions become increasingly common in diagnostics, clinical decision support, and patient monitoring, CDSCO has introduced additional expectations to ensure these technologies remain safe, reliable, and transparent.

Manufacturers developing AI or ML-enabled medical device software are expected to provide detailed information about the analytical methodology used, including whether the software relies on AI, machine learning, neural networks, rule-based systems, or adaptive algorithms.

Training Data Quality

The guidance emphasizes that manufacturers should use appropriate and representative training datasets while developing AI-based medical software. A diverse dataset helps improve software accuracy across different patient populations and clinical settings.

Bias Evaluation

Developers should evaluate potential algorithmic bias to reduce the possibility of inaccurate or discriminatory clinical outcomes. This is especially important for software intended for diagnosis, prediction, or treatment recommendations.

Algorithm Change Management

Unlike traditional software, AI models may evolve over time. The guidance therefore expects manufacturers to establish proper software change management procedures, documenting how updates are implemented, validated, and controlled throughout the software lifecycle.

Software Documentation Requirements

The guidance significantly expands the documentation expected from manufacturers applying for approval of Medical Device Software.

Applicants should clearly describe:

  • Intended purpose of the software
  • Software architecture
  • Programming language and development platform
  • Operating system compatibility
  • Software Development Lifecycle (SDLC)
  • Intended users
  • Intended patient population
  • Healthcare environment where the software will be used
  • Analytical methodology
  • Software inputs and outputs
  • Interoperability with other devices or systems
  • Data flow within the software
  • Degree of software autonomy
  • Cloud deployment (if applicable)

Providing complete technical documentation enables regulators to understand how the software functions and whether it meets applicable safety and performance requirements.

Greater Focus on Usability and Human Factors

The CDSCO guidance also recognises that software safety is influenced by how healthcare professionals and patients interact with it.

Manufacturers are expected to ensure that usability validation reflects Indian clinical workflows and operational conditions. Factors such as language accessibility, operator training, varying levels of clinical expertise, and infrastructure constraints should be considered during software design and validation.

This approach encourages software that is not only technically sound but also practical for use in India's diverse healthcare settings.

Cybersecurity and Cloud-Based Medical Software

With more healthcare software being deployed through cloud platforms and Software-as-a-Service (SaaS) models, cybersecurity has become an important regulatory focus.

The guidance recommends that manufacturers:

  • Assess risks associated with cloud-hosted software.
  • Implement baseline security controls to protect safety-related data.
  • Maintain confidentiality, integrity, and availability of patient information.
  • Evaluate local infrastructure risks for on-premises deployments.
  • Maintain secure update and backup mechanisms.

These recommendations support the development of secure digital healthcare systems while reducing cybersecurity risks.

Demonstrating Substantial Equivalence

Where applicable, manufacturers may demonstrate that their software is substantially equivalent to an existing predicate Medical Device Software.

The comparative assessment should cover parameters such as:

  • Intended use
  • Risk classification
  • Software architecture
  • Algorithm type
  • Platform
  • Input and output characteristics
  • Target users
  • Intended use environment
  • AI/ML training methodology
  • Standards compliance
  • Performance metrics
  • Cybersecurity controls

Where differences exist, scientific justification should be provided to demonstrate that safety, effectiveness, and performance are not adversely affected.

What Does This Mean for Medical Device Manufacturers?

For manufacturers, this guidance represents a major step toward a more transparent and predictable regulatory environment.

Companies developing Software as a Medical Device (SaMD) should now:

  • Review existing software against the new guidance.
  • Update technical documentation where required.
  • Strengthen software validation processes.
  • Implement formal software change management.
  • Enhance cybersecurity controls.
  • Document AI and ML methodologies.
  • Prepare for more structured regulatory submissions.

Taking these steps early can help reduce delays during licensing and improve long-term compliance.

Practical Compliance Checklist

Before submitting an application, manufacturers should review the following checklist:

Compliance RequirementStatus
Software risk classification completed
Intended use clearly documented
Technical documentation prepared
Software Development Lifecycle documented
AI/ML methodology documented (if applicable)
Usability validation completed
Cybersecurity measures implemented
Software change management established
Cloud/SaaS risk assessment completed
Clinical performance evidence prepared

Why This Guidance is a Milestone for India's Digital Healthcare Sector

The publication of India's first dedicated Medical Device Software guidance reflects the country's growing focus on digital health innovation and patient safety.

By providing clearer regulatory expectations, CDSCO is encouraging responsible innovation while ensuring that software used in healthcare meets consistent standards of quality, safety, and effectiveness. This guidance is likely to support the growth of AI-driven healthcare technologies, improve regulatory confidence, and strengthen India's position in the global medical device industry.

How PSR Compliance Can Help

Medical Device Software regulations involve detailed technical documentation, software classification, regulatory submissions, and ongoing compliance. Understanding these requirements can be challenging, particularly for startups and companies introducing innovative digital health solutions.

PSR Compliance offers professional support for:

Our experts help manufacturers, importers, and healthcare technology companies navigate India's evolving medical device regulations with confidence.

Conclusion

The release of CDSCO's first Guidance Document on Medical Device Software marks a significant milestone for India's healthcare regulatory framework. It provides long-awaited clarity on software classification, AI and machine learning, technical documentation, cybersecurity, usability, and software lifecycle management under the Medical Devices Rules, 2017.

As digital health technologies continue to evolve, manufacturers should proactively align their products and documentation with this guidance to ensure regulatory compliance and improve patient safety. Early preparation will not only simplify future approvals but also strengthen trust among healthcare professionals, regulators, and patients.

Frequently Asked Questions (FAQs)

What is the CDSCO Medical Device Software Guidance?

It is India's first dedicated guidance document explaining regulatory expectations for Medical Device Software under the Medical Devices Rules, 2017.

Who should follow this guidance?

Medical device software manufacturers, AI healthcare companies, importers, software developers, and healthcare technology startups.

Does the guidance apply to AI-based medical software?

Yes. It includes specific expectations for AI and ML-based software, including documentation, validation, and software change management.

What is Software as a Medical Device (SaMD)?

SaMD refers to software intended for medical purposes that performs its function without being part of a hardware medical device.

Why is software risk classification important?

Risk classification determines the regulatory requirements and level of evidence needed for approval.

Does the guidance include cybersecurity requirements?

Yes. It recommends security controls, cloud risk assessments, and measures to protect safety-related data.

What is substantial equivalence?

It is a structured comparison showing that a proposed software device is similar to an existing predicate device in terms of safety and performance.

Will this guidance affect imported medical device software?

Yes. Importers should ensure that imported Medical Device Software complies with the applicable CDSCO guidance and MDR-2017 requirements.

Is this guidance legally binding?

The guidance supports compliance with the Medical Devices Rules, 2017, by explaining CDSCO's regulatory expectations for applicants.

Can PSR Compliance assist with Medical Device Software compliance?

Yes. PSR Compliance provides end-to-end assistance with CDSCO registration, software classification, regulatory documentation, and compliance support for Medical Device Software.

Contact Us

Start a New Case? Contact
Our Experts

Just send us your questions or concerns by starting a new case &
we will give you the help you need. Start Here...

Have a Question?

+91-8796104190
  • Monday - Saturday:
  • 10AM - 7PM
  • Sunday & Public Holidays (Closed)
Request a Call Back
Call Now WhatsApp