CE Marking of Medical Device Software: A Guide for Hospital Decision-Makers in Critical Care

How can you be sure that the software deployed in your critical care unit fully meets the CE marking requirements for medical devices? As a healthcare CIO or healthcare professional, such as an anaesthetist or ICU physician, every technology choice you make affects both patient safety and your healthcare facility’s liability. With a demanding and constantly evolving European regulatory framework, identifying the right criteria is essential. You have come to the right place: this article gives you the tools to assess the compliance of critical care software with confidence.

Key Takeaways: What you need to know

  • What is CE marking for medical software? : CE marking certifies that a medical device, including software, meets the essential safety and performance requirements set out in European Regulation 2017/745 (MDR).
  • Assessing risk management and patient safety: In a critical care unit, every piece of information processed by software can influence a life-or-death decision. Risk management is therefore at the core of any assessment of medical device software.
  • Anticipating technical integration and day-to-day compliance: Beyond initial certification, CE marking of medical device software commits both the manufacturer and the user healthcare facility to an ongoing compliance process.

CE marking certifies that a medical device, including software, meets the essential safety and performance requirements set out in European Regulation 2017/745 (MDR). Obtained following assessment by a notified body (except for Class I software), it confirms that the manufacturer has followed a rigorous process of risk management, clinical evaluation and technical documentation. Read on to discover the practical criteria to check before choosing your software tool.

Before any purchasing decision, it is essential to identify the class of the software on offer. European Regulation 2017/745 defines four classes of medical devices (I, IIa, IIb, III) according to the level of risk to the patient.

A device’s class determines the level of regulatory requirements and the degree of assurance for your patients. In critical care, most medical software falls into Class IIa, IIb or even III, due to its direct impact on therapeutic decisions. The higher the class, the stricter the regulatory requirements: in-depth risk analysis, enhanced clinical evaluation and continuous post-market surveillance.

Always ask for the device’s exact class and the certificate issued by the notified body, or a declaration of conformity for Class I devices.

A transparent manufacturer will readily provide this information, along with the associated technical documentation. This check allows you to assess immediately how seriously the regulatory process has been taken and the level of assurance offered to patients.

The manufacturer must demonstrate that the software achieves its claimed performance and has an acceptable benefit/risk profile. The European regulation places this requirement at the heart of the assessment, to guarantee the safety and reliability of the software for clinical teams.

Clinical evaluation demonstrates that the software achieves its stated performance under real-world conditions of use. In critical care, this may include clinical studies conducted in partner healthcare facilities, analysis of real-world data or comparative trials. The clinical evaluation report is an integral part of the medical device’s technical file.

In a critical care unit, every piece of information processed by software can influence a life-or-death decision. Risk management is therefore at the core of any assessment of medical device software.

ISO 14971 governs the identification, evaluation and control of risks throughout the software lifecycle: design, use and withdrawal from the market. The risk analysis must be documented, regularly updated and incorporate clinical feedback.

Ask to see a summary of the risk analysis and the post-market surveillance plan. Question the manufacturer about its incident management procedure and its timelines for reporting to the ANSM (France’s national medicines and medical devices regulator).

For anaesthetists and ICU physicians, these elements are fundamental, as they determine the software’s reliability in situations where every second counts. For healthcare CIOs, they make it possible to anticipate reporting and incident management obligations.

Beyond initial certification, CE marking of medical device software commits both the manufacturer and the user healthcare facility to an ongoing compliance process.

The challenge for healthcare CIOs is twofold: integrating the software into the hospital information system (HIS) and protecting health data. Integrating the software into the HIS requires compliance with the General Data Protection Regulation (GDPR), the French Digital Health Doctrine and the requirements of the European Medical Device Regulation (MDR) 2017/745, which applies to medical devices, including medical software. You should also check compatibility with interoperability standards (HL7, FHIR, IHE) and compliance with security frameworks, in particular Health Data Hosting (HDS) certification, which governs the hosting and security of personal health data, as well as the application of ISO 14971 on risk management for medical devices throughout their lifecycle.

  • Regulation (EU) 2017/745 on medical devices (MDR)
  • General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679
  • ISO 14971:2019 – Medical devices: Application of risk management to medical devices
  • HDS framework – Health Data Hosting (Hébergement de Données de Santé)
  • Digital Health Doctrine – Agence du Numérique en Santé (French Digital Health Agency)

Medical software evolves, and every substantial change must be reassessed by the notified body. Make sure the manufacturer offers a training plan tailored to your clinical and technical teams, as well as responsive support. Clear traceability of updates and transparent communication about regulatory changes are indicators of reliability in a medical software vendor.

You now know how to assess the CE marking of medical device software and make secure choices for your critical care solutions. By checking classification, MDR compliance, clinical evaluation, risk management and technical integration, you protect both your patients and your healthcare facility. Such a demanding process calls for the support of an expert partner. To find out more, read our article on medical software certification. Contact us to discuss your needs and constraints, and we will present certified solutions tailored to your unit.

Bow Medical is a leading French software vendor in Europe, specialising in software for anaesthesia and ICU care. For more than 25 years, its DIANE platform has been used in over 450 healthcare facilities. Each year, our solutions help digitise an average of 5 million critical care records.

Our modules cover more than 70% of the digitised market in France.

Contact us :

Read more:

Share This