SaMD

Cloud Infrastructure for SaMD

Software as a Medical Device needs infrastructure that can stand inside a regulated file: an IEC 62304 lifecycle behind every release, SOUP documentation your 62304 file can reference, certified security controls, and hosting where your market requires it. BioT provides that layer. Your software stays the medical device, and the clearance stays yours. BioT customers have achieved FDA clearance and CE marking on the platform.

Where the Platform Sits in Your SaMD Architecture

Your regulated software runs on top. The platform underneath handles what every SaMD needs and no SaMD differentiates on: connectivity, data pipelines, user management, audit logging and integrations.

The documentation package is mapped to the FDA eSTAR structure: requirements, architecture design, test reports, cybersecurity management plan, risk assessment, threat model and SBOM.

See the submission documentation

Your SaMD

What You Inherit and What Stays Yours

The obligation

What BioT provides

The obligation

Quality management and software lifecycle

The same evidence for your own device software, with the platform recorded as a component.

What BioT provides

ISO 13485 QMS, with an IEC 62304 DHF and SBOM updated every release

Held for the platform, and available for you to reference in your own file.

The obligation

Cybersecurity documentation for an FDA submission

Your threat model, risk assessment, vulnerability management plan and security testing.

What BioT provides

Platform controls, architecture and SBOM

Documentation you can cite for the infrastructure layer of the system.

The full table, covering security certification, HIPAA and GDPR data protection and clearance ownership, is on the compliance page.

See the full table on the compliance page

The seam: SOUP documentation

BioT platform release, supplier DHF
SDLCPSoftware Development Life Cycle Procedure RM / RARisk Management and Risk Analysis SRS + SRRSoftware Requirements Specification and Review SDD + SDRSoftware Detailed Design and Review STP + STDSoftware Test Plan and Test Description TRRTest Readiness Review STRSoftware Test Report OTSOff-The-Shelf Software Validation Report TraceabilityFull traceability file across risk, SRS, SDD and STD SVDSoftware Version Description CybersecurityCybersecurity Report SBOMSoftware Bill of Materials
Reissued with every major release, roughly every two months. Additional documents, such as penetration test reports, are available on request.

The supplier Design History File your IEC 62304 file references. Document names from the platform documentation.

The BioT platform

What SaMD Needs from Its Cloud Infrastructure

The requirement

What the platform provides

The requirement

IEC 62304 lifecycle evidence

Your notified body and the FDA expect lifecycle documentation for every piece of software in the system, including the cloud it runs on.

What the platform provides

A Design History File maintained per release

BioT develops under IEC 62304 and maintains a Design History File: requirements, architecture, test reports, risk analysis and a software version description, updated with each release.

The requirement

SOUP documentation

In an IEC 62304 file, a cloud platform is software of unknown provenance unless its vendor documents it. Undocumented SOUP stalls regulatory reviews.

What the platform provides

Evidence that turns the platform into documented SOUP

Specifications, validation reports, known-anomaly lists and an SBOM, reissued with every major release, packaged so your 62304 file can reference them directly.

The requirement

Security certification buyers screen for

Hospitals, IDNs and enterprise buyers screen SaMD vendors on infrastructure security before clinical value gets discussed.

What the platform provides

HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799

Held and audited by BioT for the platform layer, including the healthcare-specific certifications US hospital procurement asks for.

The requirement

Data residency and agreements

SaMD sold into the US and EU needs data hosted in the right region, under the right agreements, with a subprocessor list a privacy review can check.

What the platform provides

Hosting in the US, EU and Asia, with a BAA and a DPA

Run in your own AWS account or on a BioT-managed dedicated environment. Both models come with a BAA, a DPA and a published subprocessor list.

The requirement

Postmarket obligations

Clearance is the start. Section 524B and MDR postmarket surveillance both expect maintained vulnerability management and an SBOM across the product lifecycle.

What the platform provides

Vulnerability management and an updated SBOM every release

Platform patching, monitoring and a machine-readable SBOM maintained per release, with scan reports available for your submissions.

Platform certificates and documentation are available on request.

Deployment Models and Data Location

BioT runs in one of two models. Which one you choose determines where your data sits, and both give you a dedicated production environment.

Certification Cost If You Build Instead

From BioT client engagement data, the direct certification bill for a do-it-yourself medical device cloud is $945,000 over three years, before headcount.

Certification is only part of it. Add the engineering headcount and cloud costs a do-it-yourself build carries, and the three-year saving with BioT is $1,850,775.

See the full three-year cost comparison

Subprocessors, Agreements and Common Questions

BioT publishes the third-party subprocessors used to host and process customer data, with their location and the service each one performs. A BAA and a DPA are available under both deployment models.

See the subprocessor list

What certifications does BioT hold?

BioT holds HITRUST r2 certification, SOC 2 Type II attestation, and ISO 27001, ISO 27799 and ISO 13485 certification. Software development follows IEC 62304. Every major release ships an updated Design History File and SBOM, roughly every two months. The document set is described at docs.biot-med.com and provided under NDA on request.

See the certification list

Is BioT itself SaMD?

No. SaMD classification applies to your software, which performs the medical purpose. BioT is the cloud infrastructure underneath it, documented as SOUP in your IEC 62304 file. The classification, the submission and the clearance stay with your product.

How does the platform fit into an IEC 62304 file?

As documented SOUP with a supplier Design History File behind it. BioT provides specifications, validation evidence, known-anomaly reporting and an SBOM, reissued with every major release, packaged so your file can reference them. Your device-level requirements, risk analysis and testing stay yours.

See the verification and validation documentation

Where is customer data hosted?

On AWS, with availability in the US, EU and Asia. In the customer-account model the deployment sits in your own AWS account. In the managed model it runs on a BioT-managed account with a dedicated environment per customer.

Can I get the BAA and the DPA?

Yes, in every deployment. Both ship in the compliance pack, along with current certificates. Ask through the contact page and the team will send everything.

Bring us your SaMD architecture

Talk to a solution architect