Doc No. CDSCO/MD/GD/MDSW/01/2026  |  Circular F. No. MED-16028/2/2025-eoffice dated 21.07.2026

The Central Drugs Standard Control Organization (CDSCO), Medical Devices Division, has notified the final Guidance Document on Medical Device Software (MDSW), signed by Dr. Rajeev Singh Raghuvanshi, Drugs Controller General (India). It follows the draft circulated on 21.10.2025 for public comments and aims to align India’s regulatory expectations for MDSW — including In-vitro Diagnostic (IVD) MDSW — with globally harmonised practices under the Medical Devices Rules, 2017 (MDR-2017).

Key takeaway: CDSCO has clarified this document is clarificatory in nature and does not introduce new regulatory control over MDSW — it consolidates existing MDR-2017 expectations into a single reference.

1. What Qualifies as MDSW

MDSW covers software intended for any medical purpose (Section 4.9, MDR-2017) — whether standalone or “part of”/driving a hardware medical device. This explicitly includes:

  • Mobile apps, cloud/network-based software, and SaaS
  • AI/ML-based tools (diagnostic, triage, CAD-based systems)
  • Commercial-Off-The-Shelf (COTS) software, where it serves a medical purpose

Excluded from MDR-2017: General wellness apps, HIS/CIS, LIS, and Image Management Systems — unless they acquire an additional diagnostic or clinical decision-making function, in which case they fall back under regulation.

2. Risk Classification

Classification continues under Rule 4 and the First Schedule (Classes A–D). For standalone MDSW, a dedicated matrix cross-references:

  • Significance of information provided — treatment/diagnosis, drive clinical management, or inform clinical management
  • Criticality of the healthcare situation — critical, serious, or non-serious
Important
Standalone MDSW used by non-clinical users in a “serious” situation without specialist support may be escalated to “critical” classification — a nuance manufacturers should not overlook when drafting intended use statements.

3. Regulatory Pathway and Licensing Authorities

The established sequence remains:

  1. Test Licence — Form MD-12/MD-13 (manufacture) or MD-16/MD-17 (import), via the NSWS portal
  2. Clinical Investigation/Clinical Performance Evaluation permission — required only for MDSW qualifying as an Investigational Medical Device (IMD) or New IVD (Forms MD-22 to MD-29)
  3. Manufacturing/Import Licence — Forms MD-3 to MD-10, MD-14/MD-15, via the CDSCO MD Online portal

Licensing split: Class A & B → State Licensing Authority (manufacturing); Class C & D, all imports, and all IMD/New IVD permissions → Central Licensing Authority.

4. Technical Documentation Requirements

Section 12.4.2 details software-specific technical file expectations, including:

  • Software/firmware description, intended user/patient population, and degree of autonomy (autonomous, supervised, non-autonomous)
  • Inputs/outputs and their role in the clinical workflow
  • Substantial equivalence with a predicate MDSW, via a structured comparative table (intended use, risk class, algorithm type, platform, performance metrics, standards compliance)
Critical Point
Where no predicate MDSW exists, the applied software is automatically treated as an IMD or New IVD, triggering mandatory CLA permission under Chapters VII and VIII before any commercial licensing can proceed.

5. Risk Management, Cybersecurity, and AI-Specific Provisions

Lifecycle risk management must align with IS/ISO 14971, IS/ISO 62304, and IS/IEC 82304-1. New/notable elements include:

  • Algorithm Change Protocol (ACP) for AI/ML-based MDSW — covering data management, performance monitoring, retraining, software updates, and rollback plans
  • Mandatory disclosure of training/validation dataset composition (demographic, geographic, clinical diversity), with justification where models are trained/validated outside India
  • Explicit regulatory recognition of algorithmic “hallucination” as a risk category requiring monitoring
  • Secure-by-design expectations — threat modelling, SBOM maintenance, and baseline cloud/on-premises security controls under the Fifth Schedule QMS framework

6. Digital Health Ecosystem Alignment

MDSW handling patient health information is now expected to align with the Ayushman Bharat Digital Mission (ABDM) framework:

  • Standards-based interoperability
  • Consent-driven data access, compliant with the DPDP Act, 2023
  • Traceability via ABHA, HFR, and HPR integration, where applicable

7. Post-Market Obligations

  • Post Approval Change (PAC) notifications under the Sixth Schedule — major changes need LA approval; minor changes require notification only
  • Continuous performance monitoring for AI drift and bias
  • Adverse event/FSCA reporting within 15 days, with voluntary reporting encouraged via the Materiovigilance Programme of India (MvPI)

Practical Takeaway for Industry

This guidance consolidates classification logic, intended-use drafting principles, predicate comparison formats, and lifecycle documentation into a single authoritative reference. Given its explicit AI/ML, SaaS, and cybersecurity provisions, manufacturers and importers of digital health products, radiology AI tools, and IVD software platforms should reassess technical files and risk management documentation against this framework before their next submission on the CDSCO MD Online portal.