HomeServicesBrazilSoftware & SaMD
Back to Brazil Overview
RDC 657/2022 Digital Health

SaMD, Software, AI & Cybersecurity Regulatory Support (Brazil)

Software as a Medical Device is specifically regulated under RDC 657/2022. The first regulatory question is whether the software is a medical device and, if so, how its intended medical purpose, risk and functionality determine classification and regularization. Software changes also require disciplined lifecycle assessment because a new algorithm, claim or risk-control function can affect the approved regulatory basis.

When This Support Is Needed

Standalone software (SaMD), digital health platform, or software-enabled medical device entering Brazil
Artificial intelligence (AI) / Machine Learning (ML) functionality is being incorporated for clinical use
A software update or patch alters clinical diagnostic functionality, output metrics, or risk controls
Cybersecurity risk evidence and SBOM documentation must be strengthened for ANVISA dossier submission

What We Challenge Before Submission

Does the claimed software function create a regulated medical-device intended purpose under ANVISA rules?
Is the software risk class properly aligned to the clinical consequence of an erroneous output?
Are software requirements fully traceable to verification tests and risk mitigation controls?
Is the released software build version clearly identified in the submission forms and technical evidence?
Could an algorithm parameter adjustment or cybersecurity update trigger a mandatory regulatory variation?

Our Software & Cybersecurity Support Scope

SaMD qualification and regulatory-status assessment under RDC 657/2022
Intended clinical use, algorithmic purpose, and marketing claims review
Risk classification strategy for software-based medical devices
RDC 657/2022 regularization pathway determination (Notificação vs Cadastro)
Software architecture, data-flow diagrams, and system description compilation
IEC 62304-oriented software lifecycle documentation review (architecture, unit, integration, system testing)
Software hazard analysis and risk management (ISO 14971)
SOUP, third-party component, and open-source library vulnerability management
Software verification and validation (V&V) test report review
Cybersecurity risk-management evidence and threat modelling documentation
Clinical and analytical performance evidence for software-driven diagnostic or treatment claims
Version numbering and software configuration control governance
Software change impact assessment for updates, patches, and AI model retraining
Post-market software vigilance and defect tracking systems setup

SaMD Assessment Philosophy:

We assess the software as a regulated medical function, not just an IT product. We connect clinical purpose, classification, risk controls, software architecture, V&V, cybersecurity and post-market change management.

Regularize Your SaMD and AI Medical Software in Brazil

Our software regulatory experts structure IEC 62304 lifecycles, prepare cybersecurity documentation, and navigate RDC 657/2022 requirements.

Book a Consultation