[codicts-css-switcher id=”346″]

Global Law Experts Logo
medical device procurement austria

Procuring Medical Devices & Digital Health (samd) in Austria 2026: Procurement, Compliance and Contract Risks

By Global Law Experts
– posted 2 hours ago

Medical device procurement austria is entering a decisive year: developments in Austria’s public procurement framework, together with a surge in tenders for regulated digital health products, are reshaping how contracting authorities and suppliers approach the market in 2026. Hospitals, regional health providers and IT vendors now face overlapping obligations under the EU Medical Device Regulation, national procurement law and data protection rules, all at once, and often in a single tender. This practical guide helps Austrian contracting authorities and IT and medical-device suppliers procure regulated devices and Software as a Medical Device (SaMD) compliantly, with checklists, scoring models and model contract risk allocations.

Whether you sit on a hospital procurement team, run a healthcare IT business or advise on public contracts, the aim here is to turn dense regulatory text into actionable procurement decisions.

This practical guide helps Austrian contracting authorities and IT/medical-device suppliers procure regulated medical devices and SaMD compliantly under the public procurement framework and EU medical device rules, with checklists and model contract risk allocations.

Introduction, why 2026 matters for medical device procurement austria

Two forces are converging. First, the volume of SaMD tenders, cloud-hosted diagnostic tools, AI-assisted decision support and connected devices, has grown sharply, forcing procurement teams to combine software contracting skills with medical device regulatory expertise. Second, layered EU and national regulatory obligations, from the MDR to the GDPR, now bear directly on how technical specifications may be framed. The result is that medical device procurement austria is no longer a purely commercial exercise; it is a compliance exercise that begins before the first line of the tender specification is drafted.

Getting it wrong is expensive. A misclassified product, an under-specified cybersecurity requirement or an ambiguous acceptance clause can lead to procurement challenges, patient-safety incidents or unenforceable contracts. This guide walks through the legal framework, classification, procurement strategy, tender specifications, contract drafting, data protection, evaluation, disputes and practical checklists, in that order, so you can build a defensible, compliant procurement from the ground up.

1. Legal framework: EU & Austrian rules that apply to medical devices and procurement

Procurement of regulated health technology in Austria sits at the intersection of EU product law, EU and national procurement law, and data protection law. Understanding which instrument governs which question is the foundation of every compliant tender.

EU Medical Device Regulation (MDR), classification & conformity

The core product-law instrument is Regulation (EU) 2017/745 on medical devices (the MDR). It defines what constitutes a medical device, sets out the classification rules, and establishes the conformity assessment and CE marking obligations that manufacturers must satisfy before a device, including software, may lawfully be placed on the market. For medical device procurement austria, the practical consequence is straightforward: a contracting authority cannot lawfully accept a product intended for diagnostic or therapeutic use unless it carries a valid CE mark and the underlying conformity documentation exists. Where higher-risk devices are involved, a notified body must have been engaged in the conformity assessment.

Austria’s competent authority (BASG) & national implementing rules

At national level, the Federal Office for Safety in Health Care (Bundesamt für Sicherheit im Gesundheitswesen, BASG) is Austria’s competent authority for medical devices. BASG oversees national implementation of the EU rules, operates vigilance and incident reporting channels, and acts as the point of contact for market surveillance. Contracting authorities should treat BASG’s vigilance framework as a live obligation that continues throughout the contract life, not merely a pre-market formality, because post-award safety incidents must be handled in coordination with the competent authority.

Public procurement rules, key framework & thresholds

Public procurement in Austria is governed principally by the Federal Public Procurement Act (Bundesvergabegesetz), whose consolidated text is published in the Federal Legal Information System (Rechtsinformationssystem des Bundes, RIS), operating within the framework of EU Directive 2014/24/EU on public procurement. The Directive fixes the core principles that every award must respect, non-discrimination, equal treatment, transparency and proportionality, and permits award on the basis of the most economically advantageous tender (MEAT).

Procedure selection and the drafting of technical specifications are governed by that framework; contracting authorities should confirm the current consolidated text and the applicable EU thresholds directly on RIS and in the relevant Commission threshold regulation before launching a procedure, as these determine whether EU-wide advertising and the full procedural regime apply.

GDPR & Austrian data-protection considerations

Because SaMD and connected devices process health data, a special category of personal data, the General Data Protection Regulation applies with full force, supervised in Austria by the Data Protection Authority (Datenschutzbehörde, DSB). Every tender for a product that touches patient data must allocate controller and processor roles, specify technical and organisational measures, and set breach notification obligations. Health data processing in procurement must comply with the GDPR, the Austrian Data Protection Act (Datenschutzgesetz) and DSB guidance, and this compliance cannot be bolted on after award, it must shape the specification and the contract from the outset.

2. Is the product a medical device or SaMD? Classification and implications for procurement

The first substantive question in any healthcare IT procurement austria exercise is deceptively simple: is the thing you are buying a medical device at all? The answer drives everything downstream, the documentation you demand, the conformity you verify, and the risk you allocate.

How to classify software (SaMD), using MDCG guidance

Software is a medical device only where the manufacturer intends it for a medical purpose, diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease. The MDCG guidance on the qualification and classification of software provides authoritative decision logic for distinguishing SaMD from software that merely stores, archives, communicates or performs simple searches. For procurement of medical software austria, the crucial distinction is intended purpose: identical code can be a regulated device in one deployment and an unregulated administrative tool in another, depending on the claims the manufacturer makes.

Examples, clinical use versus administrative tools

  • SaMD (regulated). Software that analyses radiology images to flag suspected lesions, an algorithm that calculates a drug dose from patient parameters, or a decision-support tool that recommends a diagnosis.
  • Not SaMD (administrative). A hospital appointment scheduler, a billing system, or a data warehouse that only stores results without interpreting them.
  • Borderline, verify. Patient monitoring dashboards, clinical alerting engines and AI triage tools frequently sit close to the line; require the supplier’s written classification rationale and the corresponding CE documentation.

Consequences for tender specifications and CE marking

Once a product qualifies as SaMD, the tender must treat it as a regulated device. That means requiring CE marking, conformity assessment evidence, a technical file summary and, for higher-risk classes, notified-body certificates. It also means the specification cannot demand functionality that would change the intended purpose in a way that invalidates the existing conformity assessment. A short classification checklist at the pre-tender stage, intended purpose, risk class, CE status, notified body involvement, protects the authority from accepting a non-compliant bid.

3. Procurement strategy & route selection under the procurement framework

Choosing the right procedure is a strategic decision, not an administrative default. The procurement framework gives contracting authorities several routes, each with different trade-offs for complex, regulated technology.

Which procedure to use

Procedure Best suited to Trade-offs for SaMD
Open Well-defined, standardised devices with clear specifications Fast and transparent, but inflexible where clinical requirements need refinement
Restricted Markets with many potential bidders where pre-qualification matters Allows pre-screening of clinical evidence and cybersecurity maturity
Negotiated / competitive procedure with negotiation Complex SaMD where requirements evolve during dialogue Flexible, but demands strong process discipline to preserve equal treatment
Competitive dialogue Innovative or bespoke digital health solutions where the authority cannot define the solution in advance Ideal for novel AI or integration challenges; resource-intensive

Use of frameworks & dynamic purchasing systems

Framework agreements and dynamic purchasing systems are in common use for IT and health procurements in Austria, and the federal procurement agency (Bundesbeschaffung GmbH, BBG) offers practical guidance and centralised purchasing routes. For recurring SaMD needs, software licences, maintenance, updates, a framework can aggregate demand and lock in compliance baselines, while a dynamic purchasing system keeps a regulated supplier pool open to new entrants as the market evolves. Both models suit fast-moving digital health, but each requires the compliance criteria to be set correctly at the point the framework is established.

Specifying functional versus technical requirements

Over-prescriptive technical specifications risk distorting competition and can breach the equal-treatment principle. The safer approach for medical device procurement austria is to specify outcomes and functional requirements, what the product must achieve clinically and operationally, rather than a single vendor’s technical architecture. Where technical standards are cited, allow equivalents supported by evidence, consistent with EU procurement principles.

Procurement-stage risk allocation

Push key compliance checks upstream. Use pre-qualification or selection criteria to test clinical evidence maturity, cybersecurity posture and regulatory status before evaluating price. This protects patient safety and reduces the risk of awarding to a bidder that cannot ultimately deliver a compliant product. Prominent legal-technology developments for 2026, the shift to cloud and SaaS delivery, the embedding of AI components, and growing sustainability requirements, all point the same way: authorities must screen suppliers on capability and compliance, not just cost.

4. Technical and compliance tender requirements (specs & scoring)

The heart of a defensible procurement is a specification that translates regulatory obligations into measurable, scorable requirements. This is where saMD procurement compliance is won or lost.

Clinical performance and evidence requirements

Require the clinical evaluation report and, where relevant, post-market clinical follow-up data. Clinical evidence should be treated as a pass/fail gateway rather than a scored nicety: a product that cannot demonstrate its clinical performance for the intended use should not proceed to price evaluation. Ask for the intended-purpose statement, the summary of safety and clinical performance where applicable, and evidence that the evaluation covers the specific patient population and clinical setting of the tender.

Cybersecurity & safety-by-design requirements

Connected devices and SaMD are attack surfaces. Specify secure development lifecycle practices aligned with IEC 62304, vulnerability disclosure and reporting processes, and patching and update service levels with defined response times for critical vulnerabilities. Require penetration-test evidence and a documented incident response procedure. In saas medical device procurement in particular, the update obligation is central, the authority must know how patches are delivered, tested and validated without invalidating the device’s conformity.

Interoperability, data portability & integration testing

Specify the interoperability standards the product must support, the data formats for export, and a formal integration-testing stage against the authority’s existing clinical systems. Data portability provisions protect the authority at exit, ensuring patient data and configuration can be recovered in a usable format when the contract ends.

Service levels, maintenance and software updates for SaaS

For cloud-delivered SaMD, define uptime commitments, maintenance windows, support response and resolution targets, and the treatment of both corrective and adaptive updates. Because saas as a medical device austria means the product continues to evolve after go-live, the contract must address how functional changes are managed, tested and, where they affect the intended purpose, re-certified.

Scoring matrix example, medical device procurement austria

Table A below is an illustrative scoring matrix. Clinical evidence and cybersecurity are weighted heavily and supported by pass/fail gateways; price is expressed as total cost of ownership rather than headline licence cost. Weightings are indicative only and should be set for each individual procurement.

Criterion Weighting Sample sub-criteria Gateway?
Clinical evidence & performance 30% Clinical evaluation report quality; population fit; post-market data Yes (pass/fail entry)
Cybersecurity & safety-by-design 25% IEC 62304 lifecycle; patching SLA; penetration test; incident response Yes (minimum threshold)
Total cost of ownership 20% Licence, integration, maintenance, exit costs over term No
Interoperability & integration 15% Standards support; integration test outcome; data portability No
Support, maintenance & updates 10% Uptime; response times; update governance No

5. Contract drafting: acceptance, warranties, liability and clinical performance guarantees

A compliant procurement can still fail at the contract stage if risk is allocated loosely. The contract is where regulatory obligations become enforceable commercial promises, and where the boundary between a software defect and a clinical failure must be drawn with care.

Acceptance testing for SaMD, staged acceptance and clinical pilots

Avoid a single lump-sum acceptance on delivery. Use staged acceptance: factory or configuration acceptance, integration acceptance against live systems, and a clinical site pilot with defined key performance indicators before go-live. Tie payment milestones to acceptance stages so that the authority retains leverage until the product performs as specified in its actual clinical environment.

Warranty versus performance obligations

Distinguish clearly between a warranty against software defects (bugs, non-conformity with specification) and a performance obligation tied to clinical outcomes or accuracy metrics. Ambiguity here is a frequent source of procurement disputes austria: a supplier may fix code defects promptly yet resist responsibility where the product fails to deliver the promised clinical performance. Separate remedies, free correction for defects, service credits and step-in rights for performance shortfalls, reduce that ambiguity.

Liability allocation & insurance

Medical-device liability and general software-defect liability are not the same risk, and the contract should reflect this. Require the supplier to maintain product liability and professional indemnity cover appropriate to a regulated device, and address the interaction between contractual liability caps and the supplier’s non-excludable obligations under Austrian law. Because saas as a medical device austria blends product and service risk, ensure the insurance regime covers both the device and the ongoing service.

Change control, upgrades and regulatory re-certification

The contract must anticipate that the device will change. Include a change-control mechanism that flags whether a proposed update affects the intended purpose or classification and therefore triggers a fresh conformity assessment. Place the obligation on the supplier to maintain CE conformity throughout the term and to notify the authority, and, where required, BASG, of any change affecting safety or regulatory status.

Table B, risk allocation: supplier versus contracting authority

Risk area Supplier obligation Contracting authority obligation
Software defects Correct non-conformities within defined SLA at no cost during warranty Report defects promptly with reproduction detail
Clinical performance Warrant performance against specified KPIs; remedy shortfalls Provide representative clinical data and test environment
Regulatory conformity Maintain CE marking; fund re-certification where updates require it Cooperate with vigilance and market-surveillance processes
Updates & patches Deliver security and functional updates per SLA; validate before release Approve maintenance windows; support integration retesting
Data protection Act as processor per instructions; implement TOMs; notify breaches Act as controller; define lawful basis and processing scope
Indemnities Indemnify for IP infringement and regulatory breach attributable to the product Indemnify for misuse outside intended purpose or instructions

For a broader treatment of procurement thresholds and contractor compliance under the current framework, see the companion guidance on contract lawyers in Austria, public procurement thresholds and contractor compliance, which complements this sector-specific guidance.

6. Data protection, interoperability & cybersecurity obligations

Health data is among the most sensitive categories the GDPR regulates, and its protection must run through the entire procurement, not just the data-processing agreement annex.

GDPR obligations and controller/processor roles in procurement

Establish at the specification stage whether the supplier acts as a processor on the authority’s instructions or as a controller in its own right for certain functions. Cloud-hosted SaMD typically places the supplier in a processor role, requiring a data-processing agreement that meets Article 28 GDPR requirements. The Datenschutzbehörde supervises compliance in Austria, and its guidance should inform how data residency, sub-processing and international transfers are handled in the contract.

Technical & organisational measures for medical data

Specify encryption at rest and in transit, access controls, audit logging, pseudonymisation where feasible, and role-based access aligned to clinical workflows. These technical and organisational measures should be verifiable, supported by certifications and audit rights, rather than asserted.

Incident response, breach notification and clinical coordination

A data breach involving a clinical system is simultaneously a data-protection event and potentially a patient-safety event. The contract should set breach notification timelines to the authority that are tight enough to allow the authority to meet its own GDPR notification obligations, and should require coordination with clinical teams and, where relevant, BASG vigilance reporting.

Certification & attestation

Require recognised certifications as evidence of maturity: ISO/IEC 27001 for information security management and IEC 62304 for the medical device software lifecycle. These attestations should be current, in scope for the specific product, and subject to a contractual obligation to maintain them for the contract term.

7. Tender evaluation, award and post-award management

Evaluation and award must be as rigorous as the specification, and the work does not stop at signature.

Bid evaluation process

Apply the gateway criteria first, clinical evidence and minimum cybersecurity thresholds, before scoring the qualitative and quantitative award criteria. Document the evaluation reasoning for each bid to withstand any subsequent challenge, consistent with the transparency principle underpinning EU procurement law.

Verifying CE conformity and notified-body documents

Do not accept CE marking at face value. Verify the declaration of conformity, confirm the notified body’s identity and certificate validity for higher-risk classes, and check that the intended purpose in the documentation matches the clinical use in the tender. This verification is the practical safeguard that turns procurement of medical software austria from a paper exercise into genuine assurance.

Contract management, monitoring clinical performance and safety incidents

Establish ongoing monitoring against the contracted KPIs, track safety incidents, and maintain a register of updates and their conformity impact. Active contract management is how the authority captures early warning of degradation or regulatory change.

Early-warning clauses and escalation

Include contractual triggers requiring the supplier to notify the authority immediately of field safety corrective actions, recalls, or regulatory findings affecting the product. Pair these with an escalation path so that safety issues reach clinical governance and legal counsel without delay.

8. Common procurement disputes & how to reduce risk

Disputes in this field cluster around a small number of recurring failure points. Anticipating them at the drafting stage is the most effective mitigation.

Most frequent disputes

  • Specification non-conformity. The delivered product does not meet a functional or technical requirement, often because the specification was ambiguous.
  • Clinical performance failures. The product functions technically but does not achieve the promised clinical accuracy or outcome.
  • Delayed or disruptive updates. Patches arrive late, or an update degrades performance or triggers an unaddressed re-certification requirement.

Preventive drafting and evidence-gathering best practices

Draft measurable acceptance criteria, retain a full evaluation and testing record, and require the supplier to maintain documentation supporting conformity throughout the term. A well-kept evidential trail transforms a contested performance claim into a documented breach, which is decisive in any procurement disputes austria scenario.

Remedies & dispute routes under Austrian law

Remedies range from contractual mechanisms, service credits, correction obligations, termination for persistent breach, to procurement-specific review procedures for challenges to the award itself, and general civil remedies including damages and, where appropriate, injunctive relief. Review of procurement decisions in Austria is handled by the competent review bodies (at federal level the Federal Administrative Court, Bundesverwaltungsgericht, and at regional level the respective Landesverwaltungsgerichte), with the applicable routes and deadlines set out in the Federal Public Procurement Act and equivalent regional legislation consolidated on RIS. Time limits for challenging an award decision are short; authorities and suppliers should confirm the current position before acting.

9. Practical checklists & template clause snippets

The following checklists distil the guidance into working tools to support each phase of medical device procurement austria.

Pre-tender checklist

  • Confirm intended purpose and whether the product is SaMD using MDCG guidance.
  • Establish risk class and required conformity documentation.
  • Select the procurement procedure and confirm current thresholds on RIS.
  • Define controller/processor roles and data residency requirements.

Tender specification checklist for SaMD

  • Require CE marking, declaration of conformity and, where applicable, notified-body certificates.
  • Require the clinical evaluation report as a pass/fail gateway.
  • Specify cybersecurity requirements: IEC 62304 lifecycle, patching SLA, penetration testing, incident response.
  • Specify interoperability standards, integration testing and data portability at exit.

Acceptance & go-live checklist

  • Complete staged acceptance: configuration, integration and clinical pilot.
  • Verify KPIs met against the contract before go-live sign-off.
  • Confirm data-processing agreement, TOMs and breach notification path are live.
  • Register the update-governance and re-certification process.

Contract clause snippets

  • Warranty. Distinguish defect correction from clinical performance remedies with separate SLAs.
  • Updates. Require validated delivery, classification-impact assessment and re-certification funding.
  • Clinical performance. Bind the supplier to measurable KPIs with service credits and step-in rights.
  • Cybersecurity SLA. Set critical-vulnerability response times and mandatory breach notification windows.

Conclusion & next steps

Successful medical device procurement austria in 2026 depends on treating regulatory compliance as the starting point rather than an afterthought. Classify the product correctly using the MDR and MDCG guidance, select the right procedure under the public procurement framework, translate clinical, cybersecurity and data-protection obligations into scorable specifications, and allocate risk precisely in the contract for acceptance, warranties, liability and updates. Do this, and the authority buys not just a product but a defensible, safe and enforceable outcome; suppliers, in turn, win contracts they can deliver without dispute. Given the interaction of EU product law, national procurement rules and the GDPR, engaging procurement counsel at the specification and negotiation stages is the most reliable safeguard.

You can explore further guidance through the Information Technology practice area for Austria and connect with specialists via the Global Law Experts directory.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabine Alvarez Privado at APS-LAW, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2017/745 on medical devices (MDR)
  2. MDCG 2019-11 Guidance on Qualification and Classification of Software
  3. Austrian Federal Office for Safety in Health Care (BASG)
  4. Rechtsinformationssystem des Bundes (RIS)
  5. Bundesbeschaffung GmbH (BBG)
  6. Austrian Data Protection Authority (Datenschutzbehörde, DSB)
  7. Directive 2014/24/EU on public procurement
  8. Bundesverwaltungsgericht (Federal Administrative Court)

FAQs

Is software used in a hospital always a medical device in Austria?
No. Software is a medical device only if its manufacturer intends it for a diagnostic or therapeutic purpose, applying the MDR and MDCG guidance. Administrative and general IT tools, scheduling, billing or pure data storage, are not SaMD and are procured outside the medical device regime.
Require CE marking documentation, the declaration of conformity, conformity assessment evidence, a technical file summary, the clinical evaluation report, and notified-body certificates where the risk class requires them. Verify each document against the intended clinical use rather than accepting the CE mark at face value.
Yes. In saas medical device procurement, a cloud service is SaMD where it performs a medical function. Tender it as a regulated device: set data residency, patch and update SLAs, uptime commitments and re-certification obligations, and require the supplier to maintain CE conformity throughout the term.
Require evidence of a secure development lifecycle aligned with IEC 62304, penetration-test reports, defined patching SLAs, a documented incident response procedure and contractual breach notification timelines. Treat minimum cybersecurity maturity as a gateway threshold rather than a purely scored criterion.
Engage counsel at specification drafting, at pre-qualification when assessing clinical evidence, when negotiating acceptance, warranty and liability terms, and before escalating any post-award safety or performance issue. Early involvement prevents ambiguity that later becomes the basis of a dispute.
ai act spain enforcement
By Global Law Experts

posted 1 hour ago

By Kerwin Tan

posted 3 hours ago

By Rafaella Dionysiou

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Procuring Medical Devices & Digital Health (samd) in Austria 2026: Procurement, Compliance and Contract Risks

Send welcome message

Custom Message