Software of unknown provenance (SOUP) and off-the-shelf (OTS) software-It's role in developing medical devices

Software of unknown provenance (SOUP) and off-the-shelf (OTS) software-It's role in developing medical devices
07-Jul-2025

SOUP & OTS Software in Medical Devices

What is SOUP & OTS?

SOUP:

SOUP refers to any software used in a medical device that was not specifically developed for medical applications or for integration into medical devices. Instead, they were created for general use, and their inclusion in a medical device often comes without complete records or adequate documentation of the development process.

Examples include:

  • Open source software
  • Cloud based software
  • Commercial libraries
  • Third party software for connected devices

Although SOUP can be beneficial in reducing development time and cost, it can have risks because its reliability, security, and overall functionality are not under the direct control of the medical device manufacturer.

Off the Shelf (OTS) Software:

SOTS (Off The Shelf) software is ready made software that can be bought and easily added to a product with little to no changes. Many medical device manufactures choose to use OTS software because it saves time and money compared to creating custom software from scratch. Even though OTS software is widely used in many industries, it still needs to be thoroughly tested and checked to make sure it's safe for use in medical devices.

The FDA requires that OTS software used in medical devices must follow the same safety and quality standards as custom software. This means the software has to be tested to make sure it's safe and works properly in healthcare. Manufacturers need to check the software's development process, test it, and ensure it meets all the necessary rules. While using OTS software can save time and money compared to building custom software, it's important to choose and manage it carefully to make sure it complies with all regulations.

Figure 1: Inclusion of SOUP/OTS in Internally made Software

Component

Category

Software developed by Cool Product Inc.

Internally developed software

Open source, math library

SOUP (or OTS)

Operating system from Fast OS Inc.

SOUP (or OTS)

Display driver

SOUP (or OTS)

 

The Importance of Reporting and Managing SOUP & OTS in MedTech Companies

The incorporation of SOUP/OTS in medical devices raises several concerns, especially since the software comes from external sources. Because manufacturers do not have control over how this software was developed, it introduces significant risks.

These risks could impact:

Risk Area

Description

Reliability

Malfunctions or defects in SOUP could affect the overall performance of the medical device

Cybersecurity

Unchecked third party software might introduce vulnerabilities to attacks

Safety

The lack of validation and testing of third party software could compromise patient safety

As part of regulatory requirements, medical device manufacturers must ensure that any SOUP used in their products is thoroughly tested and validated. This includes conducting risk assessments to identify potential hazards and ensuring that SOUP meets the same regulatory standards as custom developed software.

SOUP/OTS Management in Medical Technology

The use of SOUP and OTS software in medical devices presents numerous advantages, such as improved efficiency, reduced development errors, and enhanced patient outcomes. However, the use of third party software must be handled carefully to ensure it meets all regulatory standards.

Healthcare providers and manufacturers must:

  • Validate the software to confirm its safety and effectiveness.
  • Test any software updates or changes to ensure they do not compromise device functionality.
  • Document all testing and validation procedures to comply with regulatory requirements.

When implemented correctly, SOUP and OTS software can enhance the delivery of healthcare services by improving device functionality, reducing costs, and accelerating time to market. Proper management and compliance are essential to realizing these benefits without compromising patient safety.

Streamlining SOUP/OTS Management with a Software Bill of Materials

One essential tool for managing SOUP/OTS in medical devices is the Software Bill of Materials (SBOM). The FDA requires that manufacturers provide an SBOM, which is a comprehensive list of all software components used in a device, including both commercial software and third party components.

An SBOM helps manufacturers track the various software components and ensures they are aware of any changes, vulnerabilities, or risks associated with the software.

This proactive approach to risk management allows developers to react to emerging threats before they impact patient safety. By maintaining an up to date SBOM, manufacturers can stay ahead of potential risks and ensure that their devices continue to meet regulatory requirements.

As the use of third party software in medical devices continues to rise, managing SOUP becomes an increasingly important aspect of ensuring device safety and regulatory compliance. While SOUP offers clear advantages in terms of cost and development time, manufacturers must take careful steps to validate, test, and document the software used in their devices.

By leveraging tools like the Software Bill of Materials (SBOM) and adhering to rigorous validation procedures, manufacturers can minimize risks and maximize the potential of SOUP in medical device development.

Master Files for Devices MAFs in OTS for Market Approvals

When medical device makers use commercially available off the shelf (OTS) software in their devices, they often need detailed information about how the software was developed and tested. However, the original software manufacturing companies usually want to keep this information private.

To solve this, software OEMs can send the sensitive details directly to the FDA using a Device Master File (MAF).

This way:

  • The FDA can review the information to ensure the software meets safety and regulatory standards.
  • The software company keeps its confidential information secure.

This helps both the software company and the device maker work together while staying compliant with FDA rules.

For MAF, there are no specific content requirements for a MAF. However, a submission will not be accepted as an MAF if it is not substantive in nature and does not contain information that may reasonably be regarded as trade secret or confidential commercial or financial information.

Labeling Guidelines for Medical Devices with SOUP/OTS Software

When a medical device uses SOUP or (OTS) software, its labeling should include key details to guide users and ensure safe operation:

Category

Details

Software Versions

Clearly state the approved version(s) of the software that can be used with the device

Hardware Requirements

List the minimum hardware specifications, such as processor, memory, and interfaces, that the software needs to work properly

Installation Guidance

Provide simple steps for users to check that the software is installed correctly and functions as expected

Important Warnings

Warn users that using unapproved software versions or hardware can compromise safety and effectiveness. If the software runs on a stand alone computer where users can make changes, they must avoid installing other software to prevent risks or errors

 

Managing Maintenance and Obsolescence in Medical Devices with SOUP/OTS Software

When using SOUP/OTS software in medical devices, manufacturers need to address safety, performance, and long term support. Key considerations with respect to submission may include the following:

Safety

Design

Software Testing

Has a risk assessment with traceability to requirements and test reports been provided?

How will the new OTS software component(s) change the performance characteristics?

Do test reports provide objective evidence that identified OTS software component hazards have been addressed?

Are safety functions isolated from new OTS software component(s)?

How will the new OTS software component(s) change the operational environment?

Do test reports provide objective evidence that all identified system hazards have been addressed?

Does the new OTS software component(s) affect system safety integrity?

Is data integrity preserved?

Has a system regression test been performed?

What new human factors conditions are introduced with new OTS software component(s)?

 

 

 

Installation

Obsolescence

Product Configuration

What is the impact of new OTS software component(s) on fielded medical device products? For example, do new OTS software component(s) correctly operate within the specifications of medical devices currently fielded?

Will the old OTS software component(s) still be available for fielded medical devices? Is there a retirement plan for OTS software component(s) to be replaced/eliminated? Do new OTS software component(s) replace fielded components?

Hardware platform (e.g., microprocessor, minimum memory required, addressable word size). Software platform (such as operating system, communications, databases, necessary utilities, etc.). OTS component(s) other than Utilities and Drivers. Internally developed application(s).

In summary, while SOUP and OTS software can be very helpful, they must be managed carefully to ensure medical devices are safe, effective, and compliant with regulations. Proper management ensures that devices continue to work well and keep patients safe.

easyQ Editorial Team

easyQ Editorial Team

Provides expert insights on medical device quality management, regulatory compliance, and eQMS solutions to help MedTech companies simplify compliance and improve quality processes.

Start Your Smart Compliance Journey

Get expert guidance and simplify your compliance process today — talk to our team about how easyQ fits your QMS.

Talk to Our Experts
easyQ compliance experts