HealthVerified by Kopik: Official sources reviewed and answers tested by Kopik

Surgical robots & medical device software: FDA regulatory pathways and guidance

Covers FDA's regulatory pathways for robotically-assisted surgical devices (RASD) and the software inside them: 510(k) and De Novo classification, premarket software documentation levels, premarket cybersecurity, human factors and usability testing, AI-enabled device software functions and Predetermined Change Control Plans (PCCP), SaMD clinical evaluation, post-market Medical Device Reporting, and the Quality Management System Regulation (QMSR) aligned with ISO 13485. Built for regulatory affairs managers at medtech companies, robotics startups and clinical engineers who need article-level, citable answers rather than a general overview; it is not individualized regulatory advice, and two included FDA guidances (RASD premarket submissions, AI-enabled device lifecycle management) are still drafts, not final. Curated by Kopik from public sources: U.S. Food and Drug Administration and eCFR (U.S. government works, public domain).

Ask your question

Free account required

Each question stands alone Β· 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

This assistant answers questions about how the U.S. Food and Drug Administration (FDA) regulates robotically-assisted surgical devices and the software inside them, from premarket pathways to post-market reporting. It is meant for regulatory affairs teams, robotics startups and clinical engineers who want precise, citable answers. Every answer comes from public FDA guidance documents and the eCFR, and two of the included guidances are still drafts.

510(k) or De Novo: choosing a pathway for a surgical robot

Under the 510(k) process, a robotically-assisted surgical device (RASD) must be compared with a legally marketed predicate device to support substantial equivalence. The new device must have the same intended use as the predicate and either the same technological characteristics or different ones that do not raise different questions of safety and effectiveness.

When there is no legally marketed predicate, the De Novo process offers a route to Class I or Class II for devices whose risks can be controlled by general controls, or general and special controls. A sponsor can file a direct De Novo request without first receiving a not substantially equivalent (NSE) determination on a 510(k), and FDA must issue its classification decision by written order within 120 days of receiving the request.

The FDA's draft RASD guidance also describes an umbrella and covered procedure approach: data from a complex, higher risk procedure can support authorization for less complex procedures in the same surgical specialty.

Training and human factors for robotic systems

The draft RASD guidance states that safety and effectiveness depend heavily on users achieving competency with the system. Each manufacturer should develop a training program validated before clinical use, and the premarket submission should include an overview of the training plan.

The training should not focus only on surgeons: it should also cover other operating room staff who interact with the device, such as bedside assistants and surgical scrub nurses. Training may combine didactic training on the system's capabilities, a robotic surgical simulator and use of the device in bench, animal or cadaver models.

The final human factors guidance defines a critical task as a user task that, if performed incorrectly or not at all, would or could cause serious harm. Validation testing should include at least 15 participants from each distinct user population.

Software documentation and cybersecurity in the submission

The FDA guidance on device software functions sets two documentation levels. Enhanced Documentation is recommended when a failure or flaw of a software function could present a hazardous situation with a probable risk of death or serious injury; otherwise Basic Documentation applies. At the Enhanced level, for example, all unit and integration test protocols and reports should be provided.

For cybersecurity, section 524B of the Federal Food, Drug, and Cosmetic Act applies to "cyber devices": devices that include software, can connect to the internet and have characteristics that could be vulnerable to cybersecurity threats. For these devices a software bill of materials (SBOM) is required, and FDA considers that the ability to connect to the internet includes unintended connectivity.

The cybersecurity guidance also asks for a security risk management report that summarizes the risk evaluation methods, details the residual risk conclusion and mitigation activities, and traces the threat model, risk assessment, SBOM and testing documentation.

Quality system: the QMSR and ISO 13485

21 CFR Part 820, now called the Quality Management System Regulation, incorporates ISO 13485:2016 by reference. Manufacturers must document a quality management system that complies with ISO 13485 and with the other applicable requirements of Part 820.

Where a clause of ISO 13485 conflicts with the Federal Food, Drug, and Cosmetic Act or its implementing regulations, the U.S. law controls. The draft RASD guidance also recalls that all software changes must be verified and validated under the applicable clauses of ISO 13485:2016.

Frequently asked questions

Is a robotically-assisted surgical device actually a robot?

According to the FDA overview of computer-assisted surgical systems, the device is not actually a robot, because it cannot perform surgery without direct human control. The surgeon uses computer and software technology to control instruments through small incisions.

Does a training program limited to surgeons meet FDA expectations?

Not according to the draft RASD guidance. It recommends that the training program and competency expectations also include other operating room staff, such as bedside assistants and scrub nurses. Training should also be reassessed when user interfaces change, new instruments are added or new user groups appear.

When should a sponsor choose Basic rather than Enhanced software documentation?

Basic Documentation applies when no software failure could present a hazardous situation with a probable risk of death or serious injury. For Class III devices or combination products, a sponsor that concludes Enhanced Documentation does not apply should give a detailed rationale.

What is the 510(k) Summary and why does it matter?

The 510(k) Summary is a public document that summarizes the basis for a substantial equivalence determination. The draft RASD guidance recommends including a complete summary in the premarket notification, and FDA intends to verify that it is accurate and complete.

What does a SaMD clinical evaluation cover?

The IMDRF guidance adopted by FDA describes three parts: a valid clinical association between the software output and the targeted clinical condition, analytical validation and clinical validation. Together they show that the software provides the expected technical and clinical data.

Is this assistant a substitute for regulatory advice?

No. It gives answers grounded in public FDA and eCFR texts, not individualized regulatory advice. Two of the guidances it uses, on RASD premarket submissions and on AI-enabled device lifecycle management, are drafts and not for implementation.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=us-fda-surgical-robotics-samd
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-us-fda-surgical-robotics-samd "https://kopik.io/api/mcp?base=us-fda-surgical-robotics-samd" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-us-fda-surgical-robotics-samd": {
      "url": "https://kopik.io/api/mcp?base=us-fda-surgical-robotics-samd",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/us-fda-surgical-robotics-samd/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.