Medical software certification: everything you need to know about CE marking

As a healthcare CIO, how can you be sure that the medical software deployed across your information system genuinely meets the requirements of CE marking?

With so many vendors on the market, the complexity of the European MDR and the liability your healthcare facility bears, identifying truly compliant solutions is a real challenge. The good news: you’ve come to the right place. In this article, we explain what this certification involves, why it is essential to securing your technology choices, and how it protects you, your users and your patients.

CE certification of medical software is a mandatory regulatory quality process in the European Union. It attests that medical device software meets the safety, performance and quality requirements set out in the European Medical Device Regulation (MDR) 2017/745. Where required, it is issued following assessment by a notified body (NB), confirming that the product meets the applicable MDR safety and performance requirements.

Whether a notified body is involved depends on the device class: it is not required for Class I, but becomes mandatory from Class IIa upwards.

Depending on its intended purpose and the associated level of risk, your software will be classified as Class I, IIa, IIb or III. This classification directly determines the regulatory requirements to be met, the level of assessment required and whether or not a notified body must be involved. The comparison table below highlights the differences between these classes:

CriterionClass IClass IIaClass IIbClass III
Risk levelLowModerateHighCritical
Software examplesArchiving of non-critical data, medical administrative managementSimple diagnostic decision support, monitoring of clinical parametersTreatment planning (radiotherapy, surgery), complex diagnostic supportSoftware directly influencing critical therapeutic decisions that could cause serious harm to the patient
Notified bodyNot required (self-certification)RequiredRequiredMandatory (enhanced assessment)
Clinical evaluationRequired (proportionate to risk)RequiredRequired (enhanced level)Required (in-depth level)
ISO 13485 quality management systemQMS required by the MDR (ISO 13485 strongly recommended)MDR-compliant QMS, generally based on ISO 13485MDR-compliant QMS, generally based on ISO 13485MDR-compliant QMS, generally based on ISO 13485
Risk analysis (ISO 14971)MandatoryMandatoryEnhancedComprehensive
Technical documentationRequiredRequiredRequired (enhanced level)Required (in-depth level)
Post-market surveillanceRequiredRequired + PSUR at least every 2 yearsRequired + PSUR at least annuallyRequired + PSUR at least annually

Patient safety is the very foundation of any regulatory approach in the medical field. Digital medical devices, whether clinical monitoring tools, diagnostic support systems or patient data analysis platforms, have a direct impact on health. A single software error can lead to a misdiagnosis, delayed treatment or an inappropriate clinical decision.

The MDR requires a rigorous risk analysis process throughout the software lifecycle. You must identify potential hazards, assess their severity and define appropriate control measures. This approach, governed by the ISO 14971 standard, ensures that every software function meets the applicable safety requirements. This is how you protect both your users and your organisation.

Placing a medical device on the market in the European Union is strictly regulated. The European medical device regulations (notably MDR 2017/745) require CE marking for any software that:

  • supports diagnosis or clinical decision-making,
  • monitors or analyses health data,
  • provides therapeutic recommendations or alerts.

Without this regulatory compliance, placing your software on the market is quite simply illegal. Depending on your device’s class (I, IIa, IIb or III), a notified body will need to validate your technical documentation. Anticipating these obligations from the development stage onwards will save you costly delays when bringing your product to market.

CE certification is not just an administrative rubber stamp: it attests that your software meets general quality requirements throughout its lifecycle. To obtain the marking, you must implement and maintain a quality management system compliant with ISO 13485, the essential benchmark for medical device manufacturers.

This notably involves:

  • robust, documented development processes,
  • full traceability of every change made to the software,
  • comprehensive technical documentation (design file, validation plan, etc.),
  • proactive management of incidents and user feedback.

Far from being a burden, these requirements form the foundation of a reliable, high-performing and durable product, capable of meeting the demanding needs of healthcare professionals. They also ensure the continuous improvement of your device, an essential element in a constantly evolving regulatory landscape.

In a market saturated with digital tools, healthcare professionals are looking above all for safe, proven solutions. CE marking of software is a recognised indicator of regulatory compliance. It demonstrates that your product has been assessed against strict criteria by an independent notified body, and that it meets European safety and performance requirements.

For a doctor, hospital or clinic, adopting CE-marked software means being confident of using a compliant, controlled and regularly updated tool.

For you as a software vendor, it is a decisive commercial argument: certification reassures prospects, shortens sales cycles and facilitates adoption of your solution. In a sector where professional liability is at stake, this regulatory guarantee is often a deciding factor when choosing a product.

There is no mandatory update frequency: updates are carried out as controlled changes are made and in line with post-market surveillance.

CE marking is much more than a formality: it is a genuine passport to the entire European market, with no need to adapt your software to each Member State’s specific regulations. A single certification opens the door to all 27 EU countries, a market of over 440 million people.

Better still, CE certification is widely recognised beyond EU borders. Many countries (Switzerland and some countries in Asia and the Middle East) accept CE marking as a basis for assessment, which makes international expansion easier. By obtaining CE marking, you are not only securing regulatory access: you are building a reputation as a serious vendor, capable of meeting the market’s most demanding standards.

Contrary to popular belief, CE certification does not hold back innovation: on the contrary, it is a powerful catalyst for it. By building regulatory requirements in from the design phase, you adopt a structured approach to development that fosters features that are innovative, safe and genuinely useful.

This process makes you ask the right questions: what is this function really for? What risks could it create? How can you guarantee an optimal user experience? By answering these questions early on, you avoid the technical and regulatory pitfalls that could jeopardise your project. Certification thus becomes a valuable methodological framework, aligning your teams around a common goal: delivering an innovative, high-performing medical device that fully complies with European regulatory requirements.

You now know why CE marking of digital medical devices is an essential step in guaranteeing the safety, quality and compliance of your product in the EU. It is a structuring process that demands rigour and forward planning, but it opens up real growth opportunities for your organisation. To find out more, explore our other articles on European regulatory requirements, the ISO 13485 standard and the key stages of the certification process.

For over 20 years, we have been supporting healthcare professionals in transforming the critical care pathway. A French company and European leader in its field, Bow Medical has made improving and securing critical care its core mission.

Bow Medical’s expertise focuses on one specific challenge: the digitalisation of critical care. This particular segment of the electronic patient record (EPR) requires in-depth knowledge of clinical practice and operational constraints. The Class IIb certification of the Diane platform delivers real added value in terms of performance, reliability, safety and optimisation of medical time.

The figures speak for themselves: more than 450 healthcare institutions trust our software for anaesthesia and ICU care. Diane Consult handles 5 million anaesthesia consultations a year, around 70% of all computerised consultations in France. In operating theatres, 3,000 rooms rely on Diane Op, while more than 1,200 ICU beds use Diane Rea to optimise the care pathway for the most critically ill patients.

Contact us :

Read more:

Share This