Change Control Process

Manage software change requests with impact analysis and approvals per IEC 62304.

26|6|Updated Jan 4, 2026
One-click install
npx skills add https://github.com/AminAlam/meddev-agent-skills --skill change-control-process
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Change Control Process
Source: https://github.com/AminAlam/meddev-agent-skills/tree/main/documentation/change-control
Command: npx skills add https://github.com/AminAlam/meddev-agent-skills --skill change-control-process

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill establishes a structured and compliant process for managing changes to regulated medical device software, ensuring safety, quality, and traceability.

Core Features & Use Cases

  • Controlled Change Lifecycle: Manages the entire process from request to verification.
  • Impact Analysis: Assesses the effects of changes on safety, cybersecurity, and regulatory submissions.
  • Traceability: Links changes to requirements, risks, and code artifacts.
  • Use Case: When a bug is found in a Class C medical device's firmware, this Skill guides the engineer through documenting the fix, analyzing its impact on patient safety and regulatory compliance, obtaining necessary approvals, and verifying the fix through regression testing.

Quick Start

Use the change control skill to document a new software change request for a critical bug fix.

Frequently Asked Questions about Change Control Process

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the change control process for medical device software under IEC 62304?

The change control process for medical device software under IEC 62304 defines a controlled lifecycle for managing modifications to safety-relevant software, ensuring traceability, impact analysis, and regulatory compliance for defect fixes and SOUP updates.

How do I document a software change request for a Class C medical device bug fix?

To document a software change request for a Class C medical device bug fix, you must capture the request, perform impact analysis on safety and cybersecurity, obtain approvals, verify the fix through regression testing, and maintain configuration management traceability.

When do I need to perform an impact analysis for software changes in regulated environments?

You need to perform an impact analysis for software changes in regulated environments whenever modifying safety-relevant software, requirements, design, tests, or configuration items to assess effects on patient safety and regulatory submission considerations.

Does IEC 62304 change control apply to SOUP updates and defect fixes?

Yes, IEC 62304 change control applies to SOUP updates and defect fixes, requiring full documentation, impact analysis, approvals, verification, and configuration management for all modifications to safety-relevant software.

How do I manage regulatory submission considerations when updating medical device firmware?

To manage regulatory submission considerations when updating medical device firmware, the change control process links changes to requirements and risks, assesses regulatory impact, and ensures verification and approval documentation are complete for submission.

What are the limitations of using a generic change control process for medical device software?

A generic change control process lacks the specific mechanisms required for medical device software, such as linking changes to safety-relevant requirements, performing IEC 62304 compliant impact analysis, and managing SOUP updates and regulatory submission considerations.