HomeServicesAustraliaSoftware & SaMD
Back to Australia Overview
SaMD, AI & Cybersecurity

Software, SaMD, AI & Cybersecurity Regulatory Support

Australian software regulation begins with regulatory-status assessment. Some software meets the medical-device definition and requires ARTG inclusion; other software may be excluded or exempt. For regulated software, the intended medical function drives classification, evidence and lifecycle obligations.

When This Support Is Needed

New SaMD, digital health platform, or medical mobile application launch
AI / machine-learning algorithms with diagnostic or therapeutic medical purposes
Software update or algorithmic modification that may change clinical function or risk profile
Connected medical device with cloud infrastructure and cybersecurity exposure
Software previously classified as non-device or wellness tool in another jurisdiction
Integration of third-party software, open-source libraries, or SOUP into a medical device

What We Challenge Before Submission

Clinical claims added through routine software sprint releases without regulatory impact assessment
Cybersecurity treated separately from patient safety and device risk management
Software Bill of Materials (SBOM) disconnected from QMS configuration control
Verification and validation testing performed on non-production-equivalent build environments
Machine learning / AI model parameter adjustments implemented without assessing ARTG, labelling, or evidence impact

Our Support Includes

Software regulatory-status assessment (Therapeutic Goods Medical Devices Regulations)
Intended purpose, clinical algorithm, and marketing claims review
Classification rules application for software-based medical devices
Exclusion and exemption assessment under Australian digital health reforms
Essential Principles evidence strategy for software
IEC 62304-oriented lifecycle documentation review (architecture, unit, integration, system testing)
Software risk management and hazard analysis (ISO 14971)
Cybersecurity risk management, threat modelling, and SBOM documentation
System architecture, cloud interfaces, and data-flow documentation
SOUP / third-party software controls and vulnerability tracking
Software verification and validation (V&V) test report review
Clinical and analytical performance evidence for software-driven diagnostic claims
UDI implications for downloadable and cloud-hosted software
Software change control, patch management, and lifecycle versioning strategy

Senior Regulatory Question:

Does the software change alter the intended medical function, performance claim or risk profile in a way that affects classification, evidence or the ARTG basis?

Authorize Your Digital Health and SaMD Innovation in Australia

Our software regulatory engineers structure IEC 62304 lifecycles, prepare cybersecurity threat files, and assess TGA software exemptions.

Book a Consultation