Back to New Zealand Overview
IEC 62304 & Digital Health

SaMD, Software, AI & Cybersecurity (New Zealand)

Software Strategy Begins With the Medical Purpose. Software may itself be a medical device or may form part of a hardware medical device. The New Zealand pathway should begin with intended medical purpose and function, followed by classification, sponsor/WAND implications, technical evidence, cybersecurity and lifecycle change control.

When This Support Is Needed

Standalone software (SaMD), mobile medical apps, or cloud-based clinical platforms entering New Zealand
Incorporating Artificial Intelligence (AI) or Machine Learning (ML) algorithms for diagnostic or predictive purposes
Releasing a significant software update, algorithmic revision, or cybersecurity firmware patch
Compiling cybersecurity risk management documentation and Software Bill of Materials (SBOM) for sponsor records

What We Challenge Before Submission

Does the software provide medical decision support that qualifies it as a regulated medical device in NZ?
Is the software risk class commensurate with the severity of clinical impact resulting from an erroneous output?
Are all software system requirements bidirectionally traceable to verification test cases and risk controls?
Is the released software build version accurately documented across sponsor records and WAND entries?
Could an ongoing AI model retraining pipeline trigger a mandatory notification update in WAND?

Our Software & AI Support Scope

Software medical-device qualification and intended-medical-purpose assessment under the Medicines Act
SaMD / software risk classification strategy based on Schedule 2 rules and IMDRF framework
WAND notification strategy and GMDN coding for standalone software
IEC 62304 software lifecycle documentation compilation (architecture, unit, integration, system testing)
Software architecture diagrams, data-flow models, and external interface descriptions
Software of Unknown Provenance (SOUP) and third-party library vulnerability management
Software hazard analysis and risk management under ISO 14971
Software verification and validation (V&V) test report authoring and traceability matrix
Cybersecurity risk management file, threat modelling, and vulnerability penetration evidence
Clinical performance validation for software-driven diagnostic or treatment recommendations
AI/ML algorithmic transparency, training data provenance, and model-change control protocols
Bilingual e-IFU alignment, release notes, and software version tracking
Post-market software defect tracking, patch management, and vigilance procedures

Medical Function Focus:

We connect the software medical function, classification, failure modes, cybersecurity controls, validation evidence and clinical/performance claims. This avoids treating software documentation as a standalone technical exercise disconnected from the device supplied in New Zealand.

Notify and Substantiate SaMD & AI Health Software in New Zealand

Our digital health regulatory engineers prepare IEC 62304 lifecycles, cybersecurity risk files, and WAND notifications.

Book a Consultation