SOUP is software of unknown provenance: every library, SDK, framework, runtime and ML model your team didn't write. Under IEC 62304 each one carries a regulatory obligation.
Teams see a dependency list. Regulators see a risk artifact.
What stalls submissions
- No SOUP registry.
- Version drift between what was assessed and what is running.
- An AI blind spot: models and AI services nobody classified.
What good looks like
- Versions are pinned and assessed.
- Vendors are qualified under ISO 13485 clause 7.4, not just reviewed.
- AI and ML components are treated as SOUP from day one.
SOUP management is not a quality task. It is an architectural boundary decision.
Seen this differently?
Questions, corrections and counterexamples are welcome.


