ISO 13485 governs the entire development process, the outer structure every software activity has to live inside.
Clause 7.3 demands design controls: inputs, outputs, verification and change control. It says nothing about how to execute them for software. That gap is where IEC 62304 begins.
What 62304 adds
- Decomposition. Software items classified by safety risk, with every decision traceable to the DHF.
- SOUP management. Third-party libraries, AI models and LLM SDKs each need documented risk justification.
- CAPA (clause 9). Closed-loop problem resolution. Observability and traceability have to be built in from day one.
What is changing
- FDA QMSR (February 2026). ISO 13485 is embedded as the US regulatory baseline.
- EU AI Act, high risk (August 2026). AI dependencies need documented instructions for use and bias monitoring.
- IEC 62304 Edition 2. Class A/B/C is expected to give way to PAL I and II, with AI/ML lifecycle requirements.
- FDA eSTAR pre-check. Structural checks run before a human reviewer sees a 510(k). If DHF artifacts aren't mapped and traceable, gaps surface there first.
The architect who understands this connection writes code that survives an audit.
Seen this differently?
Questions, corrections and counterexamples are welcome.


