Regulatory · 8 May 2026

IEC 62304 gap analysis, first pass

Deterministic software has a certification path. Most of the gap is documentation we have not written.

Standard
IEC 62304
Class
B, assumed
Gaps found
14
Blocking
3

Specifics

The numbers, and where they come from

Figures on this page, with the basis of each
QuantityValueBasis
Clauses assessed43Counted
Gaps found14Counted
Blocking gaps3Assessed
Gaps that are documentation11Assessed
Documentation gaps11Process gaps3Architectural gaps0
Fourteen gaps against IEC 62304. None of them are architectural, which is the point of the exercise.

The finding

The architecture is not the problem

Of fourteen gaps, eleven are documents we have not written and three are processes we have not established. None are architectural. A deterministic engine with a per-response derivation record maps onto the traceability clauses more or less directly, which is the whole commercial argument stated as an audit finding.

This is a first pass by us, not an assessment by a notified body, and it is labelled that way wherever it is quoted.

What is blocking

Three processes, named

Configuration management, problem resolution and a software safety classification rationale. All three are ordinary quality-system work and none of them need the engine to change.

Self-assessed

A gap analysis performed by the vendor is a planning document, not evidence. It becomes evidence when someone independent repeats it, and that has not happened.