When to Submit 510(k) for a software change to an existing device

When to Submit 510(k) for a software change to an existing device
07-Jul-2025

When to Submit 510(k) for Software Change

As per FDA the following the constituted as a significant change:

The device is one that the person currently has in commercial distribution or is reintroducing into commercial distribution, but that is about to be significantly changed or modified in design, components, method of manufacture, or intended use. The following constitute significant changes or modifications that require a premarket notification:

  • A change or modification in the device that could significantly affect the safety or effectiveness of the device, e.g., a significant change or modification in design, material, chemical composition, energy source, or manufacturing process.
  • A major change or modification in the intended use of the device.

According to the US FDA, a device that has been legally cleared through the 510(k) process may require a new 510(k) submission if any significant changes are made to the device. When deciding whether to submit a new 510(k) for changes, manufacturers should use the original device as the basis for comparison. Manufacturers can determine whether a new 510(k) submission is required or if documenting the rationale is sufficient by following the questions outlined in the flow chart for each specific type of change.

The Common Types of Software Changes

The following list of common types of changes is intended to help manufacturers determine whether a new 510(k) submission is necessary. The manufacturer is expected to understand the impact of the change in line with the flowchart above to evaluate the need for a new 510(k).

  • Infrastructure: Examples include switching compilers, changing programming languages (C to C++, C++ to Java), or changing software drivers or libraries.
  • Architecture: Examples include porting to a new OS, software changes to support a new hardware platform and new middleware.
  • Core Algorithm: Examples include alarm algorithms on a monitor, a motor control algorithm for an infusion pump, and a detection module and measurement engine algorithm for an IVD.
  • Cosmetic Changes: Examples include changing the company logo that is displayed on the background of every screen could involve modifying multiple software modules. While the number of modules impacted may be large, it won't impact the device's safety and effectiveness or intended use.
  • Clarification of Requirements - No Change to Functionality: Examples include revised phrasing of an existing requirement or creation of a new requirement altogether, without changing or adding functionality.
  • Reengineering and Refactoring: Reengineering is defined as the examination and alteration of software to reconstitute it in a new form, and includes the subsequent implementation of the new form. While Refactoring seeks to improve a program structure and its maintainability.

Examples of Changes that Need a New 510(K) and the Ones that do Not

Category of Change

Changes

Examples

Justification

Decision

Cybersecurity

Proactive software security patch

A device manufacturer finds a security vulnerability as part of an ongoing security evaluation of their device. The manufacturer modifies the software solely to remove this vulnerability. The manufacturer's analysis determined that the change does not have any other impact on the software or the device.

The change solely addresses cybersecurity vulnerabilities and has no impact on the device or safety.

Document as part of Change Management Process - No New 510(k)

Changes inline with recently cleared Predicate

Error during a maintenance procedure

A manufacturer makes a software modification to fix an automated scheduled daily maintenance procedure. The defect concerned the cleaning solution bottle size parameter used in a maintenance procedure. The defect impacted the system's ability to detect fluid on the bottle septum and caused intermittent fluid detection errors during the maintenance procedure. The user may need to repeat the procedure 2-3 times to complete the procedure without error. A software change is made to update the size parameter as was originally documented in the software specifications.

The change is to correct the software error of changing the bottle size parameter back to the specified bottle size to bring the system back to specification.

Document as part of Change Management Process - No New 510(k)

Changes introducing new risk or modifying existing risk

Adding a new programming mode to a cardiac monitor

The device is an implantable, automatically activated monitoring system that records subcutaneous electrocardiograms designed to record the arrhythmias in a patient. The manufacturer has made a software modification to add an alternative programming mode to change the way the device interacts with the programmer. This new programming mode provided different capabilities for data programming, interrogating, and managing the device data and function. The mode introduces new technology that impacts the safety profile of the device as a result of the energy transfer that occurs during programming.

This feature brings new risks due to the new programming mode, which could cause harm through energy transfer to the patient.

Document as part of Change Management Process - New 510(k) Required

 

Removing a diagnostic parameter

An electroencephalogram (EEG) diagnostic monitor was cleared with Spectral Edge Frequency (SEF) and Peak Power (PP). SEF and PP are used by neurologists as quantitative parameters along with the raw EEG trace and other clinical metrics to arrive at a clinical decision. The device's intended use is to monitor brain electrical activity through electrodes placed on the surface of the head. A modification is made to remove PP from the displayed quantitative parameters based on a marketing conducted survey that indicated customers did not use PP in their clinical decisions.

Removal of PP does not add a new risk or modify any of the existing risks for the device.

Document as part of Change Management Process - No New 510(k)

Changes introducing new risk control measure or modifying existing risk control measure

Adding user interface alerts and controls

An IVD analyzer manufacturer makes software modifications to replace existing modes of controls for handling samples having invalid characters in specimen IDs (specimen identification mis-association) received from Laboratory Information Systems or middleware vendors. Existing manual modes of control were adequate but required operator interaction to evaluate whether a result record for a sample had an invalid specimen ID. The new modes of control include additional automation through a design improvement that will not generate results for a sample having an invalid specimen ID. Instead, the system software will: (1) generate a warning message to the operator that an invalid specimen ID was detected; (2) not generate or report results for a sample having an invalid specimen ID; and (3) create a system log entry.

This software change automates a risk control for identifying invalid characters, replacing a manual process. If invalid characters aren't properly identified, patient lab results could be lost or replaced with incorrect ones, potentially affecting treatment decisions and causing harm.

Document as part of Change Management Process - New 510(k) Required

 

Infusion pump alarm

A general-purpose infusion pump has one alarm to alert the user when an occlusion has been detected. The software change modifies the existing alarm to provide two alarms related to occlusion: occlusion downstream and occlusion upstream. These alarms provide specific information to help resolve the occlusion.

The change updates the existing alarm for occlusion, an important safety measure to help prevent harm by managing specific occlusion events effectively.

Document as part of Change Management Process - New 510(k) Required

Changes in line with clinical functionality and performance specifications

Modify device algorithms

A manufacturer makes a software modification to enhance an arrhythmia detection algorithm. The device is intended to provide detection alarms for life-threatening arrhythmias in an intensive care unit (ICU) environment. The change impacts sensitivity and specificity and therefore the detection of arrhythmias, which are critical to the clinical performance of the device.

The modification has a direct impact on the diagnostic performance of the device in which the performance of the arrhythmia detection was changed.

Document as part of Change Management Process - New 510(k) Required

 

Steriliser user interface change

A sterilizer display provides vital information on the temperature, the pressure, and the remaining cycle time. Software changes are made to increase the font size of these parameters on the display due to customer feedback (not related to any adverse events). The items are all in the same location and the appearance is unchanged aside from the larger font size.

The information was previously displayed and the change has no significant effect on the functionality or the performance of the device.

Document as part of Change Management Process - No New 510(k)

10 Key Points to Keep in Mind while making Changes in Software

  1. Modifications undertaken with the purpose of significantly affecting the safety or effectiveness of a device require 510(k) submission.
  2. Conducting an initial risk-based assessment.
  3. Unintended consequences of changes.
  4. Use of risk management processes.
  5. The role of testing (i.e. verification and validation activities) in evaluating whether a change could significantly affect safety and effectiveness.
  6. Evaluating simultaneous changes to determine whether the submission of a new 510(k) is required.
  7. Appropriate comparative device and the cumulative effect of changes.
  8. Documentation requirement to comply with the QS regulation, 21 CFR Part 820, etc.
  9. 510(k) submissions for modified devices which describe all changes that trigger the requirement for submission of a new 510(k).
  10. Ensure substantial equivalence determinations.

Start Your Smart Compliance Journey

Get expert guidance and simplify your compliance process today — talk to our team about how easyQ fits your QMS.

Talk to Our Experts
easyQ compliance experts