Published on

September 24, 2026

Last updated on

September 24, 2026

How Is SaMD & AI Medical Software Regulated in China? NMPA Requirements Guide

Software code updates can deploy in minutes, but regulatory frameworks move on a very different timeline. Navigating SaMD regulation in China means reconciling this constant tension between rapid software iteration and strict, lifecycle-focused oversight.

For medtech teams bringing AI diagnostic tools, medical imaging platforms, or clinical decision-support systems to market, NMPA approval is far more than a static submission gate. Digital health products continually evolve through algorithm retraining, bug fixes, and feature additions, so the NMPA scrutinizes the entire software lifecycle, including how models are validated, how risk changes as capabilities expand, and how post-market code releases are governed.

This guide outlines key NMPA requirements for Software as a Medical Device (SaMD) and AI software, from classification to clinical evaluation and post-market oversight. For support with bringing your SaMD to the Chinese market, explore Cisema’s medical device registration services or contact our team today.

When Is Software Regulated as a Medical Device in China

Before assessing timelines or testing requirements, manufacturers must first determine whether their software falls under NMPA medical device regulations.

Under State Council Decree No. 739 and official NMPA medical device software guidelines, standalone software falls under medical device regulations when its intended use covers core medical functions, including:

  • Disease Management: Diagnosis, prevention, monitoring, treatment, or symptom relief.
  • Injury Support: Diagnosis, monitoring, treatment, or functional compensation for physical injuries.
  • Anatomical & Physiological Functions: Inspection, substitution, adjustment, or support of body structures or processes.
  • Life Support: Maintenance or support of vital human life functions.
  • Reproductive Health: Pregnancy control and family planning.
  • Specimen Examination: Processing human tissue or fluid samples to deliver diagnostic insights.

Stand-Alone vs. Embedded Software

Once medical intent is confirmed, the next question is whether the software is evaluated independently or as part of a larger hardware submission:

  • Stand-alone software: Operates independently on general-purpose platforms (PCs, mobile, cloud infrastructure) and is registered as a standalone SaMD product.
  • Embedded software: Incorporated into or dependent on specific medical device hardware (e.g., firmware on an MRI machine). In this case, the software is generally assessed as part of the overall medical device rather than as a separate SaMD product.

What about wellness apps? A general fitness tracker that counts steps or logs resting heart rates for personal wellness falls outside NMPA scope. However, if that same app adds an algorithm to flag cardiac arrhythmias for diagnostic review, it crosses into SaMD territory.

How Is SaMD Classified Under China’s NMPA Rules?

With the software established as a medical device, the next step is determining its risk profile. China divides medical devices into three risk classes:

Risk Class Typical Application to SaMD
Class I — Low Risk Rarely applicable to standalone SaMD
Class II — Moderate Risk Common for supportive diagnostic or data-processing tools
Class III — High Risk Common for high-impact AI, automated triage, and critical diagnostic systems

The classification assessment can consider factors such as:

  • Intended clinical function and operating environment
  • Degree of risk associated with incorrect software output
  • Whether the software provides information, analysis, recommendations, or diagnostic conclusions
  • Degree of healthcare-professional reliance on the output
  • Algorithmic complexity and technical characteristics
  • Use of artificial intelligence or other advanced technologies

Standalone SaMD generally falls into Class II or Class III. AI integration does not automatically trigger Class III, but it can lead to greater scrutiny of dataset validation, with reviewers referring to the NMPA AI Classification Principles.

Read this article for a deep dive into risk classification for medical devices in China.

Is Clinical Evaluation Required for SaMD?

Clinical evaluation is an important part of NMPA medical device registration, but it does not automatically mean conducting a clinical trial in China.

The NMPA maintains catalogs of devices exempt from clinical evaluation, which can include certain types of software, such as:

  • Medical image storage and transmission systems (PACS)
  • Radiation contouring software
  • Basic data-processing software

These catalogs can be updated over time, so manufacturers should first determine whether their SaMD qualifies for an applicable clinical evaluation exemption.

Where an exemption does not apply, manufacturers may be able to establish clinical safety and effectiveness through an appropriate clinical evaluation pathway, including comparison with predicate devices where permitted.

However, if your software introduces novel algorithms, unproven clinical functions, or autonomous decision-making, you may need to prepare for a clinical trial in China.

For a closer look at when a clinical trial may be required, read our guide: When Is a Clinical Trial Required for China NMPA Medical Device Registration?

What Does the NMPA Require for SaMD Registration?

Clinical safety is only one part of the submission dossier. The NMPA also needs to understand how the software was developed, tested, controlled, and secured. Requirements therefore cover several software-specific areas.

Software Development, Testing, and Quality Management

Under NMPA software guidelines and China's GoodManufacturing Practice (GMP) Appendix for Independent Software, dossiers mustdemonstrate controlled software development, covering:

  • Verification and validation (V&V) procedures
  • Configuration management and separation ofdevelopment and QA roles.
  • Compliance with national standards,such as GB/T 25000.51 (the benchmark standard for software product quality and testing)

Cybersecurity Guidelines

Building on core software quality, cybersecurity for networked systems is treated as an integral part of overall device safety. The NMPA’s "Medical Device Cybersecurity Registration Review Guidelines (2022 Revision)" call for cybersecurity documentation covering areas such as:

  • Cybersecurity risk management, requirements, and verification and validation (V&V).
  • Cybersecurity capabilities, data architecture, security patches, and vulnerability assessment.
  • Traceability analysis, cybersecurity maintenance, and management of remaining vulnerabilities.

What Additional Requirements Apply to AI-Based SaMD?

AI-enabled SaMD builds on standard software requirements but adds specific requirements for algorithm validation.

Where machine learning or deep learning is used, the ":Guideline for the Registration Review of Artificial Intelligence Medical Devices (2022 Revision)" applies. Reviewers evaluate AI products through comprehensive Algorithm Research Reports detailing:

  • Data Governance & Quality: Provenance, labeling standards, balance, and diversity of training and validation datasets.
  • Algorithm Performance: Specificity, sensitivity, and Receiver Operating Characteristic (ROC) metrics evaluated on clinical test sets.
  • Risk Controls & Human-in-the-Loop: Safety boundaries and protocols defining how clinicians review and override AI outputs.
  • Data Privacy Compliance: Full alignment with Chinese cross-border data transfer regulations and local privacy framework laws (Personal Information Protection Law - PIPL and Data Security Law - DSL).

How Does the NMPA Regulate Software Updates?

Initial registration secures market entry, but software development rarely stands still after approval. To balance rapid software iteration with post-market oversight, the NMPA uses a dual-tier version tracking system:

  • Complete Version (X.Y.Z.B): Internal build tracking that accounts for routine patches, bug fixes, and minor refactoring.
  • Released Version (X.Y): The approved version made commercially available. This must be consistently displayed across your Instructions for Use (IFU), Product Technical Requirements (PTR), test reports, and software splash screen.

Major vs. Minor Software Changes

Because post-market modifications are inevitable, manufacturers must evaluate codechanges remain within your approved scope:

Change Type Typical Characteristics Regulatory Consideration
Major change Changes affecting intended use, fundamental safety, core algorithms, or effectiveness May require a formal registration change before implementation
Minor change Bug fixes, maintenance, or patches that do not affect the Released Version or approved intended use Generally managed under the manufacturer's quality system, with applicable regulatory reporting or inclusion in a later submission

Building an engineering change-control pipeline that connects software development updates directly to NMPA regulatory review rules from the outset is essential to maintain ongoing compliance.

What Should Manufacturers Assess Before Registering SaMD in China?

Successfully coordinating all these elements requires comprehensive operational planning. Before launching formal registration activities in China, ensure your cross-functional team can address these five strategic questions:

1. Are Your Marketing Claims Accidentally Expanding Your Regulatory Scope?

The NMPA looks closely at public marketing, app store descriptions, and user interfaces. If a secondary feature suggests diagnostic insights, even as a "reference tool," it can drag your entire platform into a higher risk category.

Have you audited your marketing language to ensure it aligns strictly with your intended regulatory profile?

2. Who Will Serve as Your China Legal Agent?

Foreign companies without a corporate entity in China must legally appoint a China NMPA Legal Agent. Partnering with an independent regulatory agent (like Cisema), rather than a commercial distributor, preserves ownership and control over your registration certificates..

With these benefits in mind, have you established an independent local representation strategy?

3. Is the Software Already Authorized in Its Home Market?

The NMPA generally requires proof of approval in your home country (like an FDA clearance or CE mark) via a Certificate of Free Sale before accepting an application.

Is your home-country approval in place, and do you have the necessary documentation ready for submission?

4. Is Your Software Ready for China’s Testing Requirements?

Under NMPA self-inspection rules, overseas lab reports are reports are not automatically accepted. Testing may be performed by qualified domestic Chinese laboratories. Under specific conditions, though, overseas laboratory test data can be adopted with sufficient justification and supporting documentation.

have you drafted a finalized Product Technical Requirements (PTR) document to serve as the test specification and established your local testing strategy?

5. How Will Your Team Handle Data Privacy and Software Versioning?

Processing Chinese patient data on overseas servers triggers strict enforcement under China’s Personal Information Protection Law (PIPL) and Data Security Law (DSL), while uncoordinated code changes can easily breach NMPA versioning rules.

Has your engineering team integrated local cloud hosting (such as AWS China or Alibaba Cloud) and aligned your internal software release cycles with the NMPA's strict X.Y versioning framework?

Final Thoughts: China SaMD Registration Support

Bringing SaMD to market in China requires a plan that extends beyond initial medical device registration, with a regulatory model that can scale alongside your codebase.

With China’s AI regulations, data privacy rules, and testing standards evolving rapidly, attempting this process without on-the-ground technical oversight can stall a commercial launch. Cisema serves as your regulatory and market access partner in China, translating complex NMPA requirements into an operational plan covering everything from initial risk classification to medical device regisrtation and post-market obligations.

To evaluate your SaMD’s registration pathway and find the fastest route to market in China, contact Cisema today.

Further Information

References

Connect with Cisema

With more than 20 years of experience and a team of over 100 specialists, Cisema helps global companies achieve compliance across Asia Pacific with confidence and accelerate market entry.

Talk to an Expert
Explore Whitepapers

Stay Informed with Monthly News and Analysis

Stay informed with the latest regulatory changes, expert insights, and market opportunities across APAC, delivered straight to your inbox.

Sign Up for Newsletter

Contact Our Consultants & Discover How We Can Support You

Let Cisema help turn your plans into reality.

Request Proposal