AI / SaMD (Software as a Medical Device) — Verus FDA

AI / SaMD

Software Lifecycle, Cybersecurity, and FDA AI expectations, packaged for review.

Software and AI submissions don’t fail because “the code is bad.” They fail because documentation is incomplete, inconsistent, or not aligned to FDA expectations. We build submission-ready software artifacts (including IEC 62304 alignment), define a controlled software lifecycle, implement a PCCP / ML change protocol, and package a defensible cybersecurity story—so your eSTAR and reviewer experience is clean and coherent.

IEC 62304 Software Lifecycle PCCP / ML Change Protocol Cybersecurity (AAMI SW96) ISO 14971 Risk File FDA AI Expectations eSTAR Packaging

Traceability

Requirements → risks → architecture → verification evidence.

Change control

Release governance and controlled updates for regulated software.

Cybersecurity

Threats, controls, SBOM planning, and reviewer-readable evidence.

Reviewer clarity

Clean eSTAR mapping and consistency across exhibits and labeling.

What you get

Submission-ready artifacts that reduce review friction.

These are the core topics we build into your regulatory strategy and submission artifacts. Each item is designed to reduce review friction and prevent the common “software documentation gap” that triggers additional information requests.

62304

IEC 62304 alignment

Lifecycle documentation scaled to your risk class

  • Software safety classification + rationale
  • Documentation level determination (Basic vs Enhanced)
  • Traceability structure (requirements → design → code → tests)
SDLC

Software lifecycle

Design controls for software teams

  • Requirements + architecture baselining
  • Verification/validation strategy + evidence packaging
  • Release management + change control for regulated updates
ML

PCCP / ML change protocol

A controlled plan for model updates

  • Define “what can change” vs “what can’t” without new review
  • Update triggers, monitoring, and rollback criteria
  • Data boundaries + validation approach
CY

Cybersecurity

Threats, controls, and evidence

  • Threat model (STRIDE) + AAMI SW96 security risk management
  • Rated cybersecurity risk assessment + architecture views
  • SBOM framework, vulnerability handling, update strategy
FDA

FDA AI expectations

Defensibility and transparency

  • Performance framing and dataset considerations
  • Clinical workflow, bias considerations, labeling boundaries
  • Post-market monitoring plan (drift, complaints, CAPA linkage)
eSTAR

eSTAR / submission packaging

Make software review easy

  • Section mapping + exhibit structure and naming
  • Consistency checks across software, risk, labeling, performance
  • Final QA to reduce avoidable AI requests

Why submissions stall

Most delays are preventable.

Missing traceability, unclear lifecycle controls, weak cybersecurity narrative, or performance evidence that doesn’t align with claims. We connect artifacts across risk, requirements, verification, labeling, and post-market plans.

Common failure modes

  • Traceability gaps: requirements and hazards don’t map cleanly to tests and releases.
  • Uncontrolled updates: no defined change protocol—especially for ML models.
  • Cybersecurity omissions: threats/controls/evidence not packaged reviewer-first.
  • Claims outpace evidence: performance doesn’t support intended use + labeling language.

How we prevent it

  • Artifact map: what FDA expects for your software risk profile and submission type.
  • Consistency QA: align software docs, risk file, labeling, and performance package.
  • Cyber narrative: threat model → controls → verification evidence → post-market plan.
  • Change governance: release controls and ML update protocol designed to be defensible.

Programs & pricing

Fee schedule effective October 1, 2026 (FY2027)

Engagements scoped to maturity and risk.

Choose the level of support that matches your timeline, software maturity, and submission pathway. Fees quoted as “from” reflect a minimum scope and are confirmed in writing after intake.

Best first step

01 — Software readiness sprint

Know what to build before you write a line of documentation
$6,500
  • FDA Pathway & Readiness Diagnostic$6,500
  • Predicate & SE Landscape Memo (SaMD / AI)$5,500
  • Predicate Verification (confirm one you have)$2,500
  • IEC 62304 deliverables map + documentation level determination
  • SDLC + change control recommendations
  • Cyber strategy outline (threats/controls/evidence)
Credit policy: One assessment fee — Predicate Memo, Predicate Verification, or Pathway Diagnostic — is credited in full against a 510(k) or De Novo engagement opened within 90 days. Where more than one has been purchased, the highest is credited. Pre-Submission and 513(g) fees are execution work and are not credited.
Documentation build

02 — Software & AI artifact packages

Individually scoped, or bundled into a submission
$8,500–$28,500
  • Cybersecurity documentation package$12,500
  • SW96 security risk mgmt, threat model, rated risk assessment, architecture views, SBOM framework
  • ISO 14971 risk management file$8,500
  • IEC 62304 software documentation package$12,500–$22,500
  • Documentation level evaluation, SRS, architecture, SDLC description, V&V summary
  • PCCP / ML change protocol package$12,500–$28,500
  • Change scope, triggers, validation, rollback, drift monitoring

All four are included in a full SaMD submission engagement — buy them separately only if you are self-authoring the rest.

Core engagement

03 — Submission — full build

Authoring + eSTAR assembly + QA
from $45,000
  • SaMD / AI-enabled 510(k)from $45,000
  • De Novo requestfrom $65,000
  • Software/cyber sections only (co-authoring)$12,500–$28,500
  • eSTAR build + QA (packaging only)$6,500–$18,500
  • AI (Additional Information) response$4,500–$12,500

The full-build fee includes the IEC 62304 documentation package, cybersecurity package, ISO 14971 risk file, Small Business Determination filing, and predicate watch through clearance.

Prefer to spread it out? The 510(k) Build Plan runs at $7,500/month over a six-month minimum.

When expectations are unclear

04 — Pre-Sub for AI / SaMD

Lock evidence expectations before you over- or under-build
$9,500–$22,500
  • Standard Q-Sub — single topic, evidence in hand$9,500
  • AI / SaMD Q-Sub — multi-question, evidence strategy$12,500–$22,500
  • Performance framing, dataset and endpoint questions, PCCP scope, cybersecurity expectations
  • Question strategy + meeting objectives
  • Briefing package drafting + exhibits
  • Meeting prep + minutes support

A Pre-Sub is the cheapest way to find out that FDA disagrees with you. There is no FDA user fee — the entire cost is the briefing package, and the questions are the deliverable. The AI/SaMD band reflects the analysis required to ask them well.

Also available: 513(g) Request for Information — $4,500 plus the FDA fee, when you want FDA’s own written classification answer rather than our analysis.

What we need to start

Intended use/claims, software description + architecture overview, current SDLC practices, release history, any threat modeling work, and any performance validation results (including datasets/metrics if ML is involved).

Start async

Share your product details and we’ll respond with a scoped plan and a prioritized artifact list (what to build now vs later), mapped to your likely submission type and risk profile.

Engagement notes:
• Fee schedule effective October 1, 2026 (FY2027). Existing clients are held at prior-year pricing through their next renewal.
• Fees are for consulting services and document preparation. FDA user fees, penetration/security testing, and clinical study costs are billed at cost and are separate.
• We do not fabricate test results. Software V&V execution, SBOM generation from your build, and security test reports remain your engineering team’s deliverables; we define, structure, and package them.
• Ongoing coverage is available through the AI & SaMD Regulatory Intelligence Club ($1,500–$2,500/mo) and the Device Growth Partner program ($6,500–$11,000/mo).

Process

Engineering-friendly workflow. Regulator-friendly outputs.

A practical flow that produces consistent documentation and reviewer-ready packaging.

01 — Align

Claims + risk

Stabilize intended use/claims and define risk boundaries that drive documentation depth.

02 — Build

Lifecycle + traceability

Set IEC 62304-aligned artifacts and traceability from requirements to verification evidence.

03 — Secure

Cyber + updates

Implement cybersecurity documentation and define controlled change protocols (including ML updates).

04 — Package

eSTAR + QA

Assemble exhibits for reviewer readability and run consistency QA across software, risk, labeling, and performance.

Trace
end-to-end
Cyber
defensible
ML
controlled change
eSTAR
review-ready

FAQs

Clear answers for software teams.

What FDA tends to care about, and how to package it cleanly.

Do we need IEC 62304 even if we’re “just software”?

If your product is regulated as a device (including SaMD), you should expect lifecycle documentation and traceability consistent with FDA software expectations. We scale depth to your risk profile and product type, starting with the documentation level determination (Basic vs Enhanced), which decides whether a Software Design Specification is owed at all.

Why does a SaMD 510(k) start at $45,000 when other 510(k)s start lower?

Because the artifact list is longer and none of it is optional. A software submission carries IEC 62304 lifecycle documentation, an SRS, architecture and data-flow documentation, software V&V packaging, a full cybersecurity set (threat model, security risk management, rated risk assessment, architecture views, SBOM), and a risk file that connects software failure to clinical harm. Bought individually those packages alone exceed $30,000.

What is a PCCP / ML change protocol?

A controlled plan defining how a model can change over time—what can update, how performance is validated, what triggers review, and how drift is monitored—so post-market updates remain defensible without a new submission for every retrain.

Will cybersecurity be required?

If your device connects to networks, exchanges data, uses third-party libraries, or could impact clinical decisions, cybersecurity documentation is typically expected. Scope depends on whether the device was previously authorized. We build the narrative and evidence package appropriate to your design and risk.

Is the assessment fee credited if we move forward?

Yes. One assessment fee — the Predicate Memo, Predicate Verification, or Pathway Diagnostic — is credited in full against a 510(k) or De Novo engagement opened within 90 days. If you purchased more than one, the highest is credited. Pre-Submission and 513(g) fees are execution work and are not credited.

Can you generate our SBOM and run our software testing?

No—and you should be cautious of anyone who says yes. The authoritative SBOM must be machine-generated from your build, and V&V results must come from your development records. We build the documentation framework, the security and safety risk analyses, and the submission packaging around them.

Practical next step: If you’re unsure what to build (and what not to build), start with the readiness sprint to lock the artifact map, traceability approach, and cybersecurity packaging plan before you draft. It’s credited back if you proceed to a submission.