Medical device procurement austria is entering a decisive year: developments in Austria’s public procurement framework, together with a surge in tenders for regulated digital health products, are reshaping how contracting authorities and suppliers approach the market in 2026. Hospitals, regional health providers and IT vendors now face overlapping obligations under the EU Medical Device Regulation, national procurement law and data protection rules, all at once, and often in a single tender. This practical guide helps Austrian contracting authorities and IT and medical-device suppliers procure regulated devices and Software as a Medical Device (SaMD) compliantly, with checklists, scoring models and model contract risk allocations.
Whether you sit on a hospital procurement team, run a healthcare IT business or advise on public contracts, the aim here is to turn dense regulatory text into actionable procurement decisions.
This practical guide helps Austrian contracting authorities and IT/medical-device suppliers procure regulated medical devices and SaMD compliantly under the public procurement framework and EU medical device rules, with checklists and model contract risk allocations.
Two forces are converging. First, the volume of SaMD tenders, cloud-hosted diagnostic tools, AI-assisted decision support and connected devices, has grown sharply, forcing procurement teams to combine software contracting skills with medical device regulatory expertise. Second, layered EU and national regulatory obligations, from the MDR to the GDPR, now bear directly on how technical specifications may be framed. The result is that medical device procurement austria is no longer a purely commercial exercise; it is a compliance exercise that begins before the first line of the tender specification is drafted.
Getting it wrong is expensive. A misclassified product, an under-specified cybersecurity requirement or an ambiguous acceptance clause can lead to procurement challenges, patient-safety incidents or unenforceable contracts. This guide walks through the legal framework, classification, procurement strategy, tender specifications, contract drafting, data protection, evaluation, disputes and practical checklists, in that order, so you can build a defensible, compliant procurement from the ground up.
Procurement of regulated health technology in Austria sits at the intersection of EU product law, EU and national procurement law, and data protection law. Understanding which instrument governs which question is the foundation of every compliant tender.
The core product-law instrument is Regulation (EU) 2017/745 on medical devices (the MDR). It defines what constitutes a medical device, sets out the classification rules, and establishes the conformity assessment and CE marking obligations that manufacturers must satisfy before a device, including software, may lawfully be placed on the market. For medical device procurement austria, the practical consequence is straightforward: a contracting authority cannot lawfully accept a product intended for diagnostic or therapeutic use unless it carries a valid CE mark and the underlying conformity documentation exists. Where higher-risk devices are involved, a notified body must have been engaged in the conformity assessment.
At national level, the Federal Office for Safety in Health Care (Bundesamt für Sicherheit im Gesundheitswesen, BASG) is Austria’s competent authority for medical devices. BASG oversees national implementation of the EU rules, operates vigilance and incident reporting channels, and acts as the point of contact for market surveillance. Contracting authorities should treat BASG’s vigilance framework as a live obligation that continues throughout the contract life, not merely a pre-market formality, because post-award safety incidents must be handled in coordination with the competent authority.
Public procurement in Austria is governed principally by the Federal Public Procurement Act (Bundesvergabegesetz), whose consolidated text is published in the Federal Legal Information System (Rechtsinformationssystem des Bundes, RIS), operating within the framework of EU Directive 2014/24/EU on public procurement. The Directive fixes the core principles that every award must respect, non-discrimination, equal treatment, transparency and proportionality, and permits award on the basis of the most economically advantageous tender (MEAT).
Procedure selection and the drafting of technical specifications are governed by that framework; contracting authorities should confirm the current consolidated text and the applicable EU thresholds directly on RIS and in the relevant Commission threshold regulation before launching a procedure, as these determine whether EU-wide advertising and the full procedural regime apply.
Because SaMD and connected devices process health data, a special category of personal data, the General Data Protection Regulation applies with full force, supervised in Austria by the Data Protection Authority (Datenschutzbehörde, DSB). Every tender for a product that touches patient data must allocate controller and processor roles, specify technical and organisational measures, and set breach notification obligations. Health data processing in procurement must comply with the GDPR, the Austrian Data Protection Act (Datenschutzgesetz) and DSB guidance, and this compliance cannot be bolted on after award, it must shape the specification and the contract from the outset.
The first substantive question in any healthcare IT procurement austria exercise is deceptively simple: is the thing you are buying a medical device at all? The answer drives everything downstream, the documentation you demand, the conformity you verify, and the risk you allocate.
Software is a medical device only where the manufacturer intends it for a medical purpose, diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease. The MDCG guidance on the qualification and classification of software provides authoritative decision logic for distinguishing SaMD from software that merely stores, archives, communicates or performs simple searches. For procurement of medical software austria, the crucial distinction is intended purpose: identical code can be a regulated device in one deployment and an unregulated administrative tool in another, depending on the claims the manufacturer makes.
Once a product qualifies as SaMD, the tender must treat it as a regulated device. That means requiring CE marking, conformity assessment evidence, a technical file summary and, for higher-risk classes, notified-body certificates. It also means the specification cannot demand functionality that would change the intended purpose in a way that invalidates the existing conformity assessment. A short classification checklist at the pre-tender stage, intended purpose, risk class, CE status, notified body involvement, protects the authority from accepting a non-compliant bid.
Choosing the right procedure is a strategic decision, not an administrative default. The procurement framework gives contracting authorities several routes, each with different trade-offs for complex, regulated technology.
| Procedure | Best suited to | Trade-offs for SaMD |
|---|---|---|
| Open | Well-defined, standardised devices with clear specifications | Fast and transparent, but inflexible where clinical requirements need refinement |
| Restricted | Markets with many potential bidders where pre-qualification matters | Allows pre-screening of clinical evidence and cybersecurity maturity |
| Negotiated / competitive procedure with negotiation | Complex SaMD where requirements evolve during dialogue | Flexible, but demands strong process discipline to preserve equal treatment |
| Competitive dialogue | Innovative or bespoke digital health solutions where the authority cannot define the solution in advance | Ideal for novel AI or integration challenges; resource-intensive |
Framework agreements and dynamic purchasing systems are in common use for IT and health procurements in Austria, and the federal procurement agency (Bundesbeschaffung GmbH, BBG) offers practical guidance and centralised purchasing routes. For recurring SaMD needs, software licences, maintenance, updates, a framework can aggregate demand and lock in compliance baselines, while a dynamic purchasing system keeps a regulated supplier pool open to new entrants as the market evolves. Both models suit fast-moving digital health, but each requires the compliance criteria to be set correctly at the point the framework is established.
Over-prescriptive technical specifications risk distorting competition and can breach the equal-treatment principle. The safer approach for medical device procurement austria is to specify outcomes and functional requirements, what the product must achieve clinically and operationally, rather than a single vendor’s technical architecture. Where technical standards are cited, allow equivalents supported by evidence, consistent with EU procurement principles.
Push key compliance checks upstream. Use pre-qualification or selection criteria to test clinical evidence maturity, cybersecurity posture and regulatory status before evaluating price. This protects patient safety and reduces the risk of awarding to a bidder that cannot ultimately deliver a compliant product. Prominent legal-technology developments for 2026, the shift to cloud and SaaS delivery, the embedding of AI components, and growing sustainability requirements, all point the same way: authorities must screen suppliers on capability and compliance, not just cost.
The heart of a defensible procurement is a specification that translates regulatory obligations into measurable, scorable requirements. This is where saMD procurement compliance is won or lost.
Require the clinical evaluation report and, where relevant, post-market clinical follow-up data. Clinical evidence should be treated as a pass/fail gateway rather than a scored nicety: a product that cannot demonstrate its clinical performance for the intended use should not proceed to price evaluation. Ask for the intended-purpose statement, the summary of safety and clinical performance where applicable, and evidence that the evaluation covers the specific patient population and clinical setting of the tender.
Connected devices and SaMD are attack surfaces. Specify secure development lifecycle practices aligned with IEC 62304, vulnerability disclosure and reporting processes, and patching and update service levels with defined response times for critical vulnerabilities. Require penetration-test evidence and a documented incident response procedure. In saas medical device procurement in particular, the update obligation is central, the authority must know how patches are delivered, tested and validated without invalidating the device’s conformity.
Specify the interoperability standards the product must support, the data formats for export, and a formal integration-testing stage against the authority’s existing clinical systems. Data portability provisions protect the authority at exit, ensuring patient data and configuration can be recovered in a usable format when the contract ends.
For cloud-delivered SaMD, define uptime commitments, maintenance windows, support response and resolution targets, and the treatment of both corrective and adaptive updates. Because saas as a medical device austria means the product continues to evolve after go-live, the contract must address how functional changes are managed, tested and, where they affect the intended purpose, re-certified.
Table A below is an illustrative scoring matrix. Clinical evidence and cybersecurity are weighted heavily and supported by pass/fail gateways; price is expressed as total cost of ownership rather than headline licence cost. Weightings are indicative only and should be set for each individual procurement.
| Criterion | Weighting | Sample sub-criteria | Gateway? |
|---|---|---|---|
| Clinical evidence & performance | 30% | Clinical evaluation report quality; population fit; post-market data | Yes (pass/fail entry) |
| Cybersecurity & safety-by-design | 25% | IEC 62304 lifecycle; patching SLA; penetration test; incident response | Yes (minimum threshold) |
| Total cost of ownership | 20% | Licence, integration, maintenance, exit costs over term | No |
| Interoperability & integration | 15% | Standards support; integration test outcome; data portability | No |
| Support, maintenance & updates | 10% | Uptime; response times; update governance | No |
A compliant procurement can still fail at the contract stage if risk is allocated loosely. The contract is where regulatory obligations become enforceable commercial promises, and where the boundary between a software defect and a clinical failure must be drawn with care.
Avoid a single lump-sum acceptance on delivery. Use staged acceptance: factory or configuration acceptance, integration acceptance against live systems, and a clinical site pilot with defined key performance indicators before go-live. Tie payment milestones to acceptance stages so that the authority retains leverage until the product performs as specified in its actual clinical environment.
Distinguish clearly between a warranty against software defects (bugs, non-conformity with specification) and a performance obligation tied to clinical outcomes or accuracy metrics. Ambiguity here is a frequent source of procurement disputes austria: a supplier may fix code defects promptly yet resist responsibility where the product fails to deliver the promised clinical performance. Separate remedies, free correction for defects, service credits and step-in rights for performance shortfalls, reduce that ambiguity.
Medical-device liability and general software-defect liability are not the same risk, and the contract should reflect this. Require the supplier to maintain product liability and professional indemnity cover appropriate to a regulated device, and address the interaction between contractual liability caps and the supplier’s non-excludable obligations under Austrian law. Because saas as a medical device austria blends product and service risk, ensure the insurance regime covers both the device and the ongoing service.
The contract must anticipate that the device will change. Include a change-control mechanism that flags whether a proposed update affects the intended purpose or classification and therefore triggers a fresh conformity assessment. Place the obligation on the supplier to maintain CE conformity throughout the term and to notify the authority, and, where required, BASG, of any change affecting safety or regulatory status.
| Risk area | Supplier obligation | Contracting authority obligation |
|---|---|---|
| Software defects | Correct non-conformities within defined SLA at no cost during warranty | Report defects promptly with reproduction detail |
| Clinical performance | Warrant performance against specified KPIs; remedy shortfalls | Provide representative clinical data and test environment |
| Regulatory conformity | Maintain CE marking; fund re-certification where updates require it | Cooperate with vigilance and market-surveillance processes |
| Updates & patches | Deliver security and functional updates per SLA; validate before release | Approve maintenance windows; support integration retesting |
| Data protection | Act as processor per instructions; implement TOMs; notify breaches | Act as controller; define lawful basis and processing scope |
| Indemnities | Indemnify for IP infringement and regulatory breach attributable to the product | Indemnify for misuse outside intended purpose or instructions |
For a broader treatment of procurement thresholds and contractor compliance under the current framework, see the companion guidance on contract lawyers in Austria, public procurement thresholds and contractor compliance, which complements this sector-specific guidance.
Health data is among the most sensitive categories the GDPR regulates, and its protection must run through the entire procurement, not just the data-processing agreement annex.
Establish at the specification stage whether the supplier acts as a processor on the authority’s instructions or as a controller in its own right for certain functions. Cloud-hosted SaMD typically places the supplier in a processor role, requiring a data-processing agreement that meets Article 28 GDPR requirements. The Datenschutzbehörde supervises compliance in Austria, and its guidance should inform how data residency, sub-processing and international transfers are handled in the contract.
Specify encryption at rest and in transit, access controls, audit logging, pseudonymisation where feasible, and role-based access aligned to clinical workflows. These technical and organisational measures should be verifiable, supported by certifications and audit rights, rather than asserted.
A data breach involving a clinical system is simultaneously a data-protection event and potentially a patient-safety event. The contract should set breach notification timelines to the authority that are tight enough to allow the authority to meet its own GDPR notification obligations, and should require coordination with clinical teams and, where relevant, BASG vigilance reporting.
Require recognised certifications as evidence of maturity: ISO/IEC 27001 for information security management and IEC 62304 for the medical device software lifecycle. These attestations should be current, in scope for the specific product, and subject to a contractual obligation to maintain them for the contract term.
Evaluation and award must be as rigorous as the specification, and the work does not stop at signature.
Apply the gateway criteria first, clinical evidence and minimum cybersecurity thresholds, before scoring the qualitative and quantitative award criteria. Document the evaluation reasoning for each bid to withstand any subsequent challenge, consistent with the transparency principle underpinning EU procurement law.
Do not accept CE marking at face value. Verify the declaration of conformity, confirm the notified body’s identity and certificate validity for higher-risk classes, and check that the intended purpose in the documentation matches the clinical use in the tender. This verification is the practical safeguard that turns procurement of medical software austria from a paper exercise into genuine assurance.
Establish ongoing monitoring against the contracted KPIs, track safety incidents, and maintain a register of updates and their conformity impact. Active contract management is how the authority captures early warning of degradation or regulatory change.
Include contractual triggers requiring the supplier to notify the authority immediately of field safety corrective actions, recalls, or regulatory findings affecting the product. Pair these with an escalation path so that safety issues reach clinical governance and legal counsel without delay.
Disputes in this field cluster around a small number of recurring failure points. Anticipating them at the drafting stage is the most effective mitigation.
Draft measurable acceptance criteria, retain a full evaluation and testing record, and require the supplier to maintain documentation supporting conformity throughout the term. A well-kept evidential trail transforms a contested performance claim into a documented breach, which is decisive in any procurement disputes austria scenario.
Remedies range from contractual mechanisms, service credits, correction obligations, termination for persistent breach, to procurement-specific review procedures for challenges to the award itself, and general civil remedies including damages and, where appropriate, injunctive relief. Review of procurement decisions in Austria is handled by the competent review bodies (at federal level the Federal Administrative Court, Bundesverwaltungsgericht, and at regional level the respective Landesverwaltungsgerichte), with the applicable routes and deadlines set out in the Federal Public Procurement Act and equivalent regional legislation consolidated on RIS. Time limits for challenging an award decision are short; authorities and suppliers should confirm the current position before acting.
The following checklists distil the guidance into working tools to support each phase of medical device procurement austria.
Successful medical device procurement austria in 2026 depends on treating regulatory compliance as the starting point rather than an afterthought. Classify the product correctly using the MDR and MDCG guidance, select the right procedure under the public procurement framework, translate clinical, cybersecurity and data-protection obligations into scorable specifications, and allocate risk precisely in the contract for acceptance, warranties, liability and updates. Do this, and the authority buys not just a product but a defensible, safe and enforceable outcome; suppliers, in turn, win contracts they can deliver without dispute. Given the interaction of EU product law, national procurement rules and the GDPR, engaging procurement counsel at the specification and negotiation stages is the most reliable safeguard.
You can explore further guidance through the Information Technology practice area for Austria and connect with specialists via the Global Law Experts directory.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabine Alvarez Privado at APS-LAW, a member of the Global Law Experts network.
posted 17 minutes ago
posted 39 minutes ago
posted 59 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message