Back to UAE Overview
IEC 62304 & Digital Health

SaMD, Software, AI & Cybersecurity (UAE MOHAP)

Software Strategy Begins With the Intended Medical Function. Software may be regulated as a medical device or form part of a hardware device. The UAE strategy should start with intended medical purpose and claims, then connect classification, software lifecycle evidence, cybersecurity, clinical/performance substantiation and post-market change control.

When This Support Is Needed

Standalone software (SaMD), mobile medical apps, or cloud-based clinical platforms entering the UAE
Incorporating Artificial Intelligence (AI) or Machine Learning (ML) algorithms for diagnostic or predictive purposes
Releasing a significant software update, algorithmic revision, or cybersecurity firmware patch
Compiling cybersecurity risk management documentation and Software Bill of Materials (SBOM) for MOHAP review

What We Challenge Before Submission

Does the software provide medical decision support that qualifies it as regulated medical equipment in the UAE?
Is the software risk class commensurate with the severity of clinical impact resulting from an erroneous output?
Are all software system requirements bidirectionally traceable to verification test cases and risk controls?
Is the released software build version accurately documented across application forms and technical files?
Could an ongoing AI model retraining pipeline trigger a mandatory regulatory variation with MOHAP?

Our Software & AI Support Scope

Software regulatory-status and intended-medical-purpose assessment under MOHAP guidelines
SaMD / software risk classification strategy based on IMDRF framework and UAE rules
IEC 62304 software lifecycle documentation compilation (architecture, unit, integration, system testing)
Software architecture diagrams, data-flow models, and external interface descriptions
Software of Unknown Provenance (SOUP) and third-party library vulnerability management
Software hazard analysis and risk management under ISO 14971
Software verification and validation (V&V) test report authoring and traceability matrix
Cybersecurity risk management file, threat modelling, and vulnerability penetration evidence
Data integrity, cloud security, and UAE health data privacy interface considerations
Usability and human factors engineering documentation (IEC 62366-1)
Clinical performance validation for software-driven diagnostic or treatment recommendations
AI/ML algorithmic transparency, training data provenance, and change-control protocols
Bilingual English/Arabic e-IFU alignment, release notes, and software version tracking
Post-market software defect tracking, patch management, and vigilance procedures

Medical Function Focus:

We review software as a medical function, not merely as code. The evidence must connect the clinical or diagnostic claim to the software requirements, risks, validation and ongoing change-control strategy.

Authorize SaMD and AI Medical Software in the UAE

Our digital health regulatory engineers prepare IEC 62304 documentation, cybersecurity risk files, and MOHAP registrations.

Book a Consultation