See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!
See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!

FDA Software Playbook

From idea to 510(k) clearance: a practical guide to developing and regulating Software as a Medical Device in the US.

BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

Book Your Free Demo

See how it works for your team. We reply within 24 hours.

  • We respond within 24 hours.
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

Trusted by startups and global leaders

BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

Does the FDA Regulate Your Software?

Not all healthcare software is FDA-regulated — the key factor is intended use. Software that analyzes medical images to detect cancer or recommends a diagnosis is SaMD; scheduling or general health apps are not.

FDA SaMD classification — understanding Software as a Medical Device regulation

What Is SaMD

Software as a Medical Device serves medical purposes without being part of a hardware device. The same AI algorithm can be unregulated wellness software or a high-risk Class III device depending on the clinical claims made.

What the 21st Century Cures Act Exempted

The 21st Century Cures Act exempted administrative support, healthy-lifestyle apps, EHRs, and basic lab tests from FDA regulation. Understanding these boundaries is essential before investing in QMS infrastructure.

Class I: General Controls

Class I devices present minimal harm and are subject only to general controls — registration, device listing, and GMP. Most Class I SaMD is exempt from premarket notification.

Class II: 510(k) Premarket Notification

Class II devices present moderate risk and typically require a 510(k) showing substantial equivalence to a legally marketed predicate. Most first-time SaMD clearances use this pathway.

Class III: Premarket Approval

Class III devices present the highest risk and require premarket approval (PMA) with clinical evidence of safety and effectiveness. Rare for pure SaMD, PMA demands far more extensive review than the 510(k).

The Regulatory Benchmarks That Shape SaMD Development

The frameworks and timelines that determine how FDA-regulated software is built, cleared, and maintained.

The Development Process for FDA-Regulated Software

Quality by design means regulatory decisions are made before development begins — not retrofitted after. These five steps define what that looks like in practice.

The 510(k) Submission Process

A 510(k) is the most common pathway to FDA clearance for Class II SaMD. It must demonstrate substantial equivalence to a legally marketed predicate — same intended use, and technological characteristics that raise no new safety or effectiveness questions.

Device Description and Intended Use

The submission opens with a precise device description and intended use statement — the same one locked before development. This is the foundation the FDA reviewer uses to evaluate everything else.

Predicate Comparison

The predicate comparison is the core of the 510(k). It must show the same intended use and demonstrate that any differences in technological characteristics don't raise new safety or effectiveness questions.

Software Documentation

All SaMD submissions require a Software Description Document and SDLC summary. Documentation depth scales with software safety class — Class C requires the most complete design, testing, and risk management records.

Performance Testing and Cybersecurity

Performance data and FDA-compliant cybersecurity documentation are required for all SaMD. AI diagnostic algorithms also need clinical performance study data — sensitivity, specificity, and other metrics against a reference standard.

Post-Market Obligations: What Clearance Does Not End

FDA clearance begins post-market regulatory obligations that continue for the life of the product.

  • Complaint Handling and MDR Reporting

    Complaint Handling and MDR Reporting

    Complaint Handling and MDR Reporting

    Serious events must be reported to the FDA as Medical Device Reports — within 30 days, or 5 for urgent cases. Complaint handling SOPs are among the first things reviewed during an FDA inspection.

  • Change Control

    Change Control

    Change Control

    Changes affecting safety, intended use, or labeling may require a new 510(k). Whether a change is significant is itself a regulated decision documented within the QMS.

  • Annual and Periodic Reports

    Annual and Periodic Reports

    Annual and Periodic Reports

    Annual reports summarizing complaint data, MDRs, and field corrective actions must be submitted to the FDA on schedule — regardless of whether adverse event data exists.

  • AI/ML Post-Market Performance Monitoring

    AI/ML Post-Market Performance Monitoring

    AI/ML Post-Market Performance Monitoring

    The FDA expects ongoing monitoring of real-world AI/ML SaMD performance against 510(k) claims. Significant degradation must be investigated and reported.

  • Predetermined Change Control Plan

    Predetermined Change Control Plan

    Predetermined Change Control Plan

    A PCCP lets companies pre-specify AI algorithm modifications that can proceed without a new 510(k), within performance boundaries accepted at clearance.

Navigating SaMD Regulation the Right Way

The most consequential SaMD decisions are made before a line of code is written. These are the five areas where regulatory strategy either prevents problems or creates them.

Book a Free Regulatory Strategy Consultation
Intended Use
Lock the intended use statement before development — it drives classification, study design, labeling, and claims. A vague statement creates costly submission problems later.
Predicate
Predicate selection is the foundation of a 510(k). A strong predicate enables a clean comparison; a weak one raises the risk of an additional information request. For novel SaMD without a predicate, De Novo is the route.
De Novo
De Novo provides clearance for moderate-risk devices without a predicate. Review takes 12–24 months but establishes a new device type others can cite as a predicate.
QMS Timing
The QMS must be in place before development, not assembled afterward. Retroactive documentation is one of the most common and expensive SaMD problems — even a minimal QMS established first prevents it.
Clinical Study
For AI diagnostics, study design is the most consequential decision: representative population, defensible reference standard, and a pre-specified analysis plan. Evidence gaps are the top reason for additional information requests.

What Most Teams Get Wrong Before Submission Risk Areas

The most common and expensive SaMD submission problems are predictable — and preventable with the right regulatory strategy from the start.

Classification

Getting Classification Wrong

Underrating a device's risk class derails a submission mid-review. It takes careful analysis of product codes, predicates, and FDA SaMD guidance.

  • Intended use scope
  • Predicate scan
  • FDA guidance review
  • Pre-sub confirmation
QMS Gaps

QMS Built After the Product

A backfilled QMS is a top red flag — design control records can't be created after the fact. It must be active before the first design input.

  • Establishment timeline
  • Risk-appropriate SOPs
  • Document management
  • Design control activation
Software Docs

Inadequate Software Documentation

The FDA judges your development process, not just test results. Common gaps: weak traceability, undocumented architecture, and tests not linked to requirements.

  • SDD completeness
  • Traceability matrix
  • Risk management docs
  • Anomaly records
Cybersecurity

Cybersecurity Documentation Gaps

FDA rules for SaMD now mandate a management plan, SBOM, threat modeling, and penetration testing evidence. Gaps drive many information requests.

  • SBOM
  • Threat modeling
  • Penetration testing
  • Vulnerability disclosure
AI Evidence

Insufficient Clinical Evidence for AI Claims

For AI diagnostic algorithms, the clinical performance study underpins your intended use claims. A weak population, reference standard, or analysis plan can trigger a new study.

  • Population representativeness
  • Reference standard
  • Statistical analysis plan
  • IRB and consent
Post-Market

Post-Market Infrastructure Not Ready at Clearance

Complaint handling, MDR reporting, and change control must be live on clearance day. A complaint before the process exists is an immediate compliance problem.

  • Complaint handling SOP
  • MDR reporting
  • Change control procedure
  • Annual report calendar
Building Software the FDA Will Regulate? Start the Regulatory Strategy Before You Start the Code.

We guide SaMD teams from intended use through 510(k) clearance — QMS setup, predicate selection, clinical validation, and submissions. Our regulatory and engineering teams work together because the documentation and the code are inseparable.

Schedule a Free Regulatory Consultation
AI Readiness

Award-Winning AI Development & Consulting

2025

100 Fastest Growth Companies

2025

Global Spring Winner

2025

Top App Development Company

2024

AWS Partner Network

2024

Google Cloud Partner

2025

Highly Rated on Trustpilot

2024

Verified Agency

2024

Top App Development Company

2024

ASSOCHAM Member

FDA Software Development Playbook: Frequently Asked Questions

[ 1 ]

How much does it cost to get a 510(k) clearance for a SaMD product?

Costs vary with device complexity, clinical study requirements, and QMS maturity. Straightforward SaMD clearances typically run $200,000–$500,000; AI diagnostics requiring prospective validation can reach $1M–$5M or more. Budget for regulatory affairs from day one.

[ 2 ]

Can a software product be both HIPAA-regulated and FDA-regulated?

Yes — many digital health products fall under both frameworks. A SaMD handling PHI must meet HIPAA's Security Rule and FDA's QMS and premarket notification requirements. The two create cumulative obligations, so teams need expertise in both domains.

[ 3 ]

What is the regulatory pathway for AI software that learns from new data after deployment?

The FDA's predetermined change control plan lets manufacturers pre-specify how an algorithm may evolve and get those modifications accepted at clearance. The framework is still developing — engage the FDA's Digital Health Center of Excellence early.

Global presence

Two offices. One team.

Hi, I'm ARIA. Ask me anything about Bonami's AI agents.