If you are seeking SaMD certification, you are almost certainly asking a practical question: what do I need to do to make my medical software official so that clinicians will trust it, payers will reimburse it, and regulators will allow it on the market? It is the right question. The word certification, though, points in a slightly wrong direction, and the difference matters more than it first appears.
This page explains what teams really mean by SaMD certification, how Software as a Medical Device actually reaches the market, and the one place where certification genuinely applies. For the full overview of the category, see our complete guide to Software as a Medical Device.
Is SaMD Certified? What “SaMD Certification” Really Means
Software as a Medical Device (SaMD) is not certified in the way many teams expect. There is no single certificate, badge, or stamp that a regulator issues to declare a piece of medical software approved. Instead, SaMD reaches the market through a regulatory clearance process, which looks different from the certification model people borrow the word from.
The confusion is understandable. In many industries, a product becomes legitimate by earning a certification against a published standard. Medical software does not work that way. In the United States, the FDA does not certify SaMD at all. It clears, grants, or approves it through one of several pathways, depending on the software’s risk. Saying a SaMD is FDA-certified is not just loose wording; it describes something that does not exist, and regulators and sophisticated buyers notice the error immediately.
There is one place where the word certification is exactly right, and it is worth holding on to, because it is the source of most of the confusion. The company that develops the SaMD can operate under a certified quality management system, most commonly ISO 13485. That certification applies to the developer’s quality system, to how the organization works, not to the software product itself. So the honest, precise answer to “is my SaMD certified” is this: the software is cleared through a regulatory pathway, and it is built under a certified quality system. Keeping those two ideas separate is the first step to understanding the whole process.
How SaMD Actually Reaches the Market: The Regulatory Clearance Process
SaMD reaches the market through a regulatory clearance process rather than a certification. In the United States, that process runs through the FDA, and the route a given product takes depends largely on its risk and whether something similar already exists. The vocabulary is specific, and using it correctly signals to regulators and partners that a team understands the landscape.
Pathway | What the FDA does | When it applies |
510(k) | Clears the software | A similar, legally marketed device (a predicate) already exists |
De Novo | Grants the request | The software is novel and low-to-moderate risk, with no predicate |
PMA | Approves the software | The software is high risk and requires the strongest evidence |
Notice that each pathway uses a different verb. The FDA clears a 510(k), grants a De Novo request, and approves a PMA. None of them certifies. The pathway a product follows is determined by its risk classification, which is why understanding classification early is so important. Our guide to SaMD regulatory pathways details each route, including the required evidence and timelines.
The picture changes outside the United States, and this is where certification-like language does appear. In the European Union, SaMD is placed on the market through a conformity assessment, often involving a notified body, that results in a CE marking. That process is closer to what people imagine when they say “certification,” but it is still an assessment of conformity with regulatory requirements, not a product certificate in the everyday sense. Teams selling into multiple regions have to plan for each system separately. Our overview compares the differences between US and EU SaMD regulations.
The Role of the ISO 13485-Certified Quality Management System
SaMD is developed under a quality management system, and this is where certification genuinely applies. ISO 13485 is the international standard for a medical device quality management system, and an organization can be audited and certified against it by an accredited body. That certification is real; it is renewed periodically, and it is one of the most meaningful signals a development partner can hold.
The key point is what the certification covers. ISO 13485 certification tells you that the organization’s processes for designing, developing, and maintaining medical device software meet a recognized quality standard. It certifies the way the company works. It does not certify any individual product, nor does it replace the regulatory clearance the software itself still needs. A company can hold ISO 13485 certification and still have to take each of its SaMD products through the appropriate FDA pathway.
Regulators expect SaMD to be developed under a quality system for a straightforward reason: a disciplined, documented, auditable process is how you demonstrate that safety and effectiveness were engineered in, not hoped for. Development under a certified or conforming quality system produces the design history, risk records, and traceability that form the basis of a regulatory submission. When those artifacts already exist because the process created them, the submission becomes a matter of compilation rather than reconstruction.
Sequenex builds SaMD engineered under the rigor of an ISO 13485-certified quality management system, so the software and its supporting documentation are produced under a recognized quality standard from the start. You can read more about developing SaMD in conformance with ISO 13485 and the benefits of an ISO 13485-certified QMS.
What SaMD Compliance Actually Requires
SaMD compliance is built from several standards and controls working together, not a single certificate. When a team asks how to get certified, what they usually need is a clear picture of the compliance stack that a regulated SaMD is expected to satisfy. Each element addresses a different part of building safe, effective medical software.
- IEC 62304 governs the software development lifecycle, defining how SaMD is planned, developed, verified, and maintained, with rigor scaled to the software’s safety risk.
- ISO 14971 governs risk management, identifying and controlling hazards across the entire lifecycle rather than at a single checkpoint.
- ISO 13485 governs the quality management system that holds the whole process together and makes it auditable.
- Verification and validation produce the evidence that the software does what it is intended to do and is safe for its intended use.
- Cybersecurity and data protection controls secure sensitive health information across the system, with a HIPAA-ready design that handles protected health information in the United States.
None of these is awarded as a badge. Compliance is demonstrated through documentation and process: the requirements written before code, the risks identified and controlled, the tests run and recorded, the changes managed under a defined procedure. A regulator reviewing a submission is looking for that evidence trail, which is why compliance is something a team builds continuously rather than obtains at the end.
Clinical evaluation is part of the same picture. Demonstrating that a SaMD is safe and effective for its intended use often requires clinical evidence, generated and documented to support the regulatory submission. It is a substantial topic in its own right, and one that teams should plan for early rather than treat as a final hurdle.
Frequently Asked Questions
Is SaMD certified by the FDA?
No. The FDA does not certify SaMD. Depending on risk, it clears the software through a 510(k), grants a De Novo request, or approves a Premarket Approval. Certification is not part of the FDA’s vocabulary for software; clearance, grant, and approval are.
What certification does a SaMD company need?
A SaMD company typically works toward ISO 13485 certification, which certifies its quality management system. That certification covers how the company develops and maintains its software, not the software product itself, which still follows a regulatory pathway to market.
What is the difference between SaMD certification and SaMD clearance?
SaMD clearance is the regulatory decision that allows software to enter the market, issued by a regulator such as the FDA through a defined pathway. SaMD certification, as the term is loosely used, usually refers to the ISO 13485 certification of the developer’s quality system. One applies to the product’s market access, the other to the organization’s processes.
Is ISO 13485 mandatory for SaMD?
ISO 13485 is not a law, but regulators widely expect SaMD to be developed under a conformant quality management system, and certification to the standard is the common way to demonstrate it. In practice, development under an ISO 13485-aligned or certified QMS is expected for regulated medical software.
How long does SaMD regulatory clearance take?
SaMD clearance timelines depend heavily on the pathway and the product’s risk. A 510(k) with a clear predicate is faster than a De Novo, and both are faster than a Premarket Approval. The evidence a pathway requires is the largest driver of the timeline.
If your team is trying to understand what it takes to bring a SaMD to market, the vocabulary is the right place to start: not certification, but clearance through a regulatory pathway, supported by development under a certified quality system. Sequenex builds Software as a Medical Device under an ISO 13485-certified quality management system, engineered and documented to support your regulatory submission while the classification, intended use, and submission remain yours. Explore our medical device software development services to see how we help startup medical device companies get there.

