The publication of a revised version of IEC 62304 was initially expected in April 2027 according to the IEC forecast from 2025, but has been significantly delayed: Numerous comments were received on the 2025 Committee Draft.

So far, only the second Committee Draft has been released. The IEC currently lists 26 October 2028 as the expected publication date. In April 2025, it was still 30 April 2027. In the EU, however, the new version only becomes binding once it is listed as a harmonised standard in the Official Journal. The current version is still not listed under the MDR. As things stand today, the new version is not expected to become binding in practice before 2030. In the medium term, therefore, the classification rules will continue to apply as described in our guide.

It’s still worth taking a look at the planned changes, because IEC 62304 Edition 2 introduces fundamental changes:

  • The three existing safety classes (A/B/C) will be replaced by two process rigor levels (I/II).
  • In addition, there are explicit requirements for AI/ML lifecycles. Cybersecurity, however, is not regulated in the standard itself. Instead, the standard is to refer to other standards such as IEC 81001-5-1.
  • The scope is being expanded to include all health-related software and is no longer limited to medical devices.

A fair amount also changes for the previous SSC A: according to the latest public draft, Level I adds requirements that previously applied only to SSC B and C, for example on architectural design and integration. Software previously in SSC B falls under Level II. Here, the requirements have been raised to the new Level II, which is closely modeled after the previous SSC C.

For an overview of the entire standard and its requirements, see our article: IEC 62304: Software life cycle processes for medical devices