You Can’t Escape CE Marking

CE Marking for Health Software: EU Regulatory

Summary

CE marking has long been associated with medical devices placed on the European market. As software has increasingly become part of medical technologies, however, the regulatory landscape has expanded beyond the Medical Device Regulation (MDR) and IVDR. For manufacturers developing medical device software, separating medical and non-medical modules may still help keep the medical device scope focused, but it no longer necessarily keeps the remaining software outside regulatory oversight.

A software system can contain modules that do not contribute directly to the medical intended purpose. In radiology software, for example, an orchestration layer may retrieve images from a PACS, transfer them to the clinical module and return the results without performing the medical functionality itself. Such modules can therefore be positioned outside the medical device scope. This can reduce regulatory overhead, development time and cost, while keeping regulatory attention on functions affecting patient health and safety.

The challenge is that other European legislation can bring these supposedly non-medical modules back into a regulated environment. The AI Act introduces CE-marking requirements for certain high-risk AI systems, while the European Health Data Space (EHDS) establishes requirements for electronic health record systems and adds interoperability requirements for relevant medical devices. The Cyber Resilience Act (CRA) applies to products with digital elements placed on the market with a data connection. As a result, software excluded from the MDR may still fall under another regulatory framework.

The timelines make early assessment particularly important. CRA reporting obligations for actively exploited vulnerabilities and severe incidents begin in September 2026, while CE-marking requirements for CRA products and certain AI systems arrive at the end of 2027. AI Act requirements for AI incorporated into regulated products such as medical devices apply from August 2028, while EHDS CE-marking requirements extend into 2029.

Manufacturers therefore need a regulatory strategy that considers the entire software architecture. This includes assessing the intended purpose, deciding which modules belong within the medical device, identifying the legislation applicable to each module, determining the relevant conformity assessment route, and defining the necessary technical documentation and procedures.

There is also an important practical advantage: these frameworks are designed to work together. Where multiple acts apply, manufacturers can use one CE mark and a single EU declaration of conformity covering the applicable legislation. Technical documentation can likewise follow a common structure, with act-specific information added where necessary.

The module strategy therefore remains useful, but the boundaries around “unregulated” software are narrowing. Manufacturers should map their software against the MDR, AI Act, CRA and EHDS now, considering intended purpose, module boundaries, applicable requirements and documentation, so that upcoming compliance deadlines do not become a last-minute exercise.

Read the original LinkedIn article: You Can’t Escape CE Marketing to understand how CE marking requirements are reaching beyond the medical device itself and what this means for your software architecture.

Latest Blogs

August 19, 2026

Summary CE marking has long been associated with medical devices placed on the European market. As software has increasingly become

August 14, 2026

A medical device quality system has to do more than document procedures. It needs to give an organisation a controlled

August 13, 2026

Summary The MDR and IVDR have significantly changed the regulatory landscape for medical devices in Europe, extending responsibilities and liabilities

logo

Unlock Your Quick Guide to AI Act
Compliance!

Explore AI-enabled SaMD requirements with our easy step-by-step guide.

Cookies help us improve your experience on our website. By using our site, you consent to the use of cookies as described in this policy.