Regulatory · 8 May 2026
IEC 62304 gap analysis, first pass
Deterministic software has a certification path. Most of the gap is documentation we have not written.
Specifics
The numbers, and where they come from
| Quantity | Value | Basis |
|---|---|---|
| Clauses assessed | 43 | Counted |
| Gaps found | 14 | Counted |
| Blocking gaps | 3 | Assessed |
| Gaps that are documentation | 11 | Assessed |
The finding
The architecture is not the problem
Of fourteen gaps, eleven are documents we have not written and three are processes we have not established. None are architectural. A deterministic engine with a per-response derivation record maps onto the traceability clauses more or less directly, which is the whole commercial argument stated as an audit finding.
This is a first pass by us, not an assessment by a notified body, and it is labelled that way wherever it is quoted.
What is blocking
Three processes, named
Configuration management, problem resolution and a software safety classification rationale. All three are ordinary quality-system work and none of them need the engine to change.
Self-assessed
A gap analysis performed by the vendor is a planning document, not evidence. It becomes evidence when someone independent repeats it, and that has not happened.