GUIDE
Rule 11 reclassified an entire industry. Software that was Class I under the directives is Class IIa or higher under the Regulation — and the threshold between IIa, IIb and III turns on a single question most people answer too quickly.
Written with Francesca Di Giuseppe, Senior QA/RA Specialist (LinkedIn) — content reviewed on 1 August 2026
Rule 11 has three parts, and reading them in order matters more than it looks. The first covers software that informs a decision. The second covers software that monitors. The third is the residual: everything else is Class I.
Software intended to provide information used to take decisions with diagnostic or therapeutic purposes is Class IIa, except where those decisions may cause:
Software intended to monitor physiological processes is Class IIa, except where it monitors vital physiological parameters and the nature of the variations could result in immediate danger to the patient, in which case it is Class IIb.
All other software is Class I. This is a narrower category than most people hope: it catches software that genuinely does not inform a clinical decision and does not monitor.
The medical devices directives had no software rule. Standalone software was treated as an active device under the general active-device rules, and because those rules are written around energy, substances and diagnosis by instrument, most software fell to the residual rule and landed in Class I — self-declared, no Notified Body, no certificate.
Rule 11 changed the starting point rather than the edge cases. The same product, with the same intended purpose, moved from a class a company could declare itself into a class that requires an audited quality management system and a Notified Body — with the cost and the waiting list that implies.
NOTE —
Almost every argument about Rule 11 is really an argument about one thing: what happens if the software is wrong? That single answer moves the device across three classes.
| IF AN INCORRECT OUTPUT COULD CAUSE | CLASS |
|---|---|
| Death, or irreversible deterioration of health | III |
| Serious deterioration of health, or a surgical intervention | IIb |
| Harm below those thresholds | IIa |
| No clinical decision is informed, and nothing is monitored | I |
The most common attempt to argue a lower class is that a clinician reviews the output, so the software does not really decide anything. It is a weaker argument than it sounds. Rule 11 speaks of software that provides information used to take a decision — not software that takes it. Information a clinician relies on is squarely within the rule.
The argument has more force where the output is one input among several and the clinician has independent means of reaching the same conclusion. It has almost none where the software is the only thing looking at the data.
The class follows the intended purpose, and the intended purpose is what you declare — so the temptation is obvious. It does not survive contact with a Notified Body, which will read your marketing material alongside your technical documentation. If the website promises decision support and the file claims a data viewer, the file loses.
Under the implementing rules in Annex VIII, Chapter II, software that drives a device or influences its use falls within the same class as that device. Software controlling an infusion pump does not get to be Class I because it merely sends instructions.
Rules apply cumulatively, and the strictest wins. Software that also incorporates a medicinal substance, uses tissue-derived material, or forms part of a closed-loop therapeutic system is caught by the special rules too. Rule 11 is where software classification starts, not where it ends.
No, but most of it is. Rule 11 places software that provides information used to take diagnostic or therapeutic decisions in Class IIa as a starting point, rising to IIb or III depending on the severity of harm if the output is wrong. Software that does not drive such decisions and does not monitor physiological processes remains Class I.
The directives had no software-specific classification rule. Standalone software was an active device and, in practice, most of it landed in Class I and could be self-declared. Rule 11 of the MDR gave software its own rule and moved the majority of it to Class IIa or above, which means a Notified Body.
If it qualifies as a medical device at all, yes. Software with a purely administrative or logistical purpose is not a medical device. Software that provides information for a clinical decision is, and Rule 11 then applies — the question is whether it informs the decision or merely transports the data.
The implementing rules in Annex VIII, Chapter II, state that software which drives a device or influences its use falls within the same class as that device. This is separate from Rule 11 and is often the provision that decides the class of embedded or controlling software.
CLASSIFY YOUR SOFTWARE
The questionnaire asks the two questions that decide Rule 11 — what the software does, and the severity of harm if it is wrong — then evaluates every other rule that could apply and reports the strictest. Free, about five minutes.
This guide describes Annex VIII of Regulation (EU) 2017/745 and is intended for orientation. It is not legal or regulatory advice. Classification of a specific device should be confirmed by a qualified regulatory affairs professional against the full text of the Regulation and the MDCG guidance on classification.