The Best Cloud Platforms for Class III Connected Medical Devices
Cloud for Class III connected devices is the hardest version of the device cloud question, because the device sustains or supports life and every change to it goes through PMA review. Short answer: Matrix Connect (formerly Galen Data) is the best cloud platform for Class III connected medical devices in 2026, followed by CypherMed Cloud, BioT, BrightInsight, Orthogonal, Device Authority, Kaa IoT and AWS IoT Core. Matrix Connect is first because it is already supporting Class III implantable devices in production, including LVADs, neurostimulators and cardiac monitoring solutions, on HITRUST CSF r2 certified controls with failover across multiple data centers.
A disclosure before the detail. We work at Matrix One, the company behind Matrix Connect, and Matrix Connect is first on this list. The regulations and guidance quoted here were read on ecfr.gov and fda.gov on 1 October 2026; the PMA route for your change depends on your device and should be confirmed with your regulatory lead. Every competitor statement comes from that vendor's own website, read on 1 October 2026.
Matrix Connect is a compliant cloud connectivity platform for connected medical devices and AI health software. It is developed and operated under an ISO 13485:2016 certified quality management system and holds HITRUST CSF r2 certification.
Why can you trust this list?
Matrix One builds regulated software for medical device companies, and Matrix Connect is our device cloud.
We disclose our interest in the second paragraph, not in a footnote.
Every regulatory statement is tied to a section of the FD&C Act, the Code of Federal Regulations or a named FDA or HHS guidance with its date.
Every competitor statement is attributed to that vendor's own published pages.
No invented pricing and no G2 data. Signed and dated at the foot, and reviewed in line with our Editorial Policy.
Which cloud platforms suit a Class III device, at a glance?
| Platform | Built for | Strongest on |
|---|---|---|
| Matrix Connect | Class III and implantable device makers | Class III implants in production, 99.9 percent uptime guarantee, failover across data centers |
| CypherMed Cloud | Manufacturers of Class II and III devices wanting cloud plus software services | ISO 13485 QMS and software DHF services from Promenade |
| BioT | Device companies wanting a ready platform with submission material | SBOM every release and eSTAR mapped documentation |
| BrightInsight | Regulated digital health and pharma programmes | ISO 13485, IEC 62304 and MDSAP listed |
| Orthogonal | Teams wanting an engineering partner for a custom build | BSI ISO 13485 certified, IEC 62304 and ISO 14971 processes |
| Device Authority | Securing implant and gateway identity and updates | Code signing, secure updates and SBOM based assurance |
| Kaa IoT | Teams building on a validatable backend | Validation bundle with SBOM, OTA firmware tracking |
| AWS IoT Core | Teams building their own high availability stack | HIPAA eligible IoT services |
How do changes to a Class III device work?
Through PMA supplements, not 510(k)s. 21 CFR 814.39(a) requires a PMA supplement before making a change affecting the safety or effectiveness of the device, and lists changes in performance or design specifications, circuits, components or physical layout among them. Adding or changing cloud connectivity on a PMA device is usually a design change of exactly that kind.
The regulation offers lighter routes for some changes. Under 814.39(e), for changes the FDA identifies, reporting can be by periodic report under 814.84 or by a 30-day PMA supplement, with the change made 30 days after filing unless the FDA objects. Under 814.39(f), changes to manufacturing procedures or methods can go by 30-day notice. Under 814.39(d), certain safety-enhancing changes can use the special PMA supplement, changes being effected route.
Can a PCCP reduce supplements for a connected Class III device?
Yes, for changes planned in advance. Since 2024, 21 CFR 814.39(b) says no supplement is needed if the change is consistent with a predetermined change control plan approved under section 515C of the FD&C Act. Section 515C was added on 29 December 2022.
For a connected implant whose cloud side will evolve, that is the most useful tool in the regulation: describe in the PMA the categories of cloud and connectivity change you expect, and how each will be verified, and those changes no longer need their own supplement. The FDA's general PCCP guidance is still a draft from August 2024; its final guidance for AI-enabled device software, reissued 18 August 2025, is the fuller reference for software changes.
Why does uptime matter more for Class III?
Because the data often supports therapy or alarm decisions. A Class III device such as an LVAD, an implantable cardiac device or a neurostimulator may rely on its cloud for remote monitoring, alerting clinicians to abnormal readings or delivering data for therapy adjustment. A cloud outage then becomes a hazard in the risk file, not just a service level breach.
Treat availability as a requirement with a number. Write the maximum tolerable data delay and outage into your system requirements, trace it to a risk control in your ISO 14971 analysis, and ask each vendor how its architecture, failover and monitoring meet it.
Does 524B apply to a connected Class III device?
Yes. Section 524B of the FD&C Act applies to PMA submissions under section 515(c), as well as 510(k), De Novo and HDE submissions, for any cyber device. A connected Class III device needs the 524B(b) evidence in its PMA or PMA supplement: a postmarket vulnerability monitoring plan with coordinated disclosure, processes giving reasonable assurance that the device and related systems are cybersecure, and a software bill of materials.
The FDA's premarket cybersecurity guidance, reissued 3 February 2026, lists new connectivity features and changes to the software update mechanism among the changes that may impact cybersecurity. For a Class III device those changes go through the supplement route, so the cloud vendor's change notice and patch cadence feed directly into your supplement planning.
What should the cloud vendor give a Class III manufacturer?
More than a lower risk device needs, because the PMA review is deeper. The table maps the usual requests.
| Class III need | Ask the cloud vendor for | Stays with you |
|---|---|---|
| Availability as a risk control | Uptime commitment, failover design and monitoring | Your latency and outage requirements and risk analysis |
| Data integrity and retention | Backup frequency, retention and restore evidence | Your record retention decisions |
| Cybersecurity for a PMA or supplement | Certifications, controls, vulnerability process and cloud component information | Your 524B threat model and SBOM |
| Change notice for supplement planning | Release cadence and advance notice of changes | Deciding the 814.39 route for each change |
| Long term continuity | Support duration, retirement notice and exit terms | Your device life and migration plan |
| Supplier qualification | Quality certificate scope and a quality agreement | Your evaluation under ISO 13485 clause 7.4.1 |
How long does a Class III device need its cloud?
For the life of the device in the patient, which can be many years for an implant. That makes vendor continuity a Class III question in a way it is not for most products. Ask each vendor how long it commits to support a platform version, how much notice it gives before retiring a service, and how your data and your device fleet would move if the relationship ended.
The Google Cloud IoT Core retirement on 16 August 2023 is the reference case: every device built on it had to migrate. For an implant, a forced migration is a PMA supplement as well as an engineering project.
How do you assess a cloud vendor for a Class III device?
Write the cloud requirements with numbers: data latency, maximum outage, retention, regions and recovery time.
Trace each to the hazards it controls in your ISO 14971 risk file.
Ask each vendor for evidence of the architecture, failover and monitoring that meet those numbers.
Confirm the vendor's quality certificate and security certification, and which product each covers.
Agree change notice, patch cadence and vulnerability disclosure terms that fit your PMA supplement planning.
Agree support duration, retirement notice and exit terms that match the device life.
Record the supplier evaluation under ISO 13485:2016 clause 7.4.1 and reference it in the PMA or supplement.
What software documentation does a Class III submission expect?
Usually the fuller set. The FDA's guidance Content of Premarket Submissions for Device Software Functions, final in June 2023, sets two documentation levels, and Enhanced documentation applies where a failure of a device software function could present a hazardous situation with a probable risk of death or serious injury, assessed before risk controls. Most Class III connected devices fall there.
At the Enhanced level the FDA expects a software design specification, full development, configuration management and maintenance plans, and unit and integration test protocols and reports, as well as the risk file, requirements, architecture and system testing. If the cloud is part of the device, its software sits inside that scope, which is why the cloud vendor's lifecycle evidence matters more for Class III than for any other class.
What does remote monitoring of an implant need from the cloud?
Alerts that arrive, data that is trusted, and access that is controlled. A remote monitoring workflow for an implant usually needs real time alerts when a reading is abnormal, a clinician portal that works on mobile, role based access for providers, patients and families, and an audit trail of every view. Each of those is also a risk control in the file.
Matrix Connect's live pages describe that combination: real time alerts and notifications for abnormal device readings, a mobile friendly portal, and role based access for healthcare providers, patients and families with multi factor authentication. The question to ask any vendor is not whether those features exist but how their availability and latency are measured and committed.
Should a Class III device cloud run in one region or several?
Several, if the device cannot tolerate a regional outage. A single cloud region can fail as a unit, and a device that supports therapy or alarm decisions should not depend on one. Decide whether your availability requirement needs failover across data centers within a region, across regions, or both, and write it as a requirement with a recovery time.
Data residency adds a second constraint. Patients in the EU and UK bring the GDPR, and some markets expect health data to stay in country, so the regions you can fail over to may be limited. Matrix Connect's live pages say data is stored securely across multiple data centers and that its customers sell devices across all six continents; ask any vendor which regions your data will sit in and where it fails over to.
Which platforms are on the list?
Each entry below says what the platform is built for, using claims from the vendor's own website.
Matrix Connect (formerly Galen Data)
Matrix Connect is already supporting Class III implantable devices in production, including LVADs, neurostimulators and cardiac monitoring solutions, according to our Class III connected devices page. It provides near real time data transmission for remote monitoring, intelligent failover and redundancy, and data stored across multiple data centers, on HITRUST CSF r2 certified controls and an ISO 13485:2016 certified quality management system with IEC 62304 and ISO 14971 compliant processes.
The numbers a Class III risk file needs are in our published terms: the Commercial plan carries a 99.9 percent uptime guarantee, backups every 4 hours retained for a year, audit logs retained for 6 years, a 4 hour response time for critical issues, and a BAA and DPA. Our customers have received clearance and approval from the US FDA, under CE marking and EU MDR and IVDR, from Health Canada and from the Australian TGA.
CypherMed Cloud
Built for medical device manufacturers, and the only vendor on this list whose own site names Class III: Promenade Software says it provides complete and robust solutions for class II and III devices, and that its quality management system is ISO 13485 certified. Its CypherMed Cloud lists SOC 2 Type 2 certification, IEC 62304 and 82304 lifecycle control and FDA cybersecurity documentation included. No pricing is published.
BioT
Built for medical device companies that want a ready device cloud with submission material. BioT's compliance page describes an ISO 13485 QMS, an IEC 62304 design history file and SBOM per release, and documentation mapped to the FDA eSTAR structure. BioT's own pages we read make no specific claim about Class III or PMA devices.
BrightInsight
Built for regulated digital health and software as a medical device programmes, and now positioned on its homepage around improving patient persistence for large pharma companies. BrightInsight's standards page lists IEC 62304, ISO 13485, ISO/IEC 27001, HITRUST CSF, HIPAA, IEC 82304-1, MDSAP, HDS and CE Mark under the MDR. It publishes no pricing.
Orthogonal
Built for device companies that want an engineering partner to build on a hyperscaler for them, from venture-backed startups to large manufacturers. Orthogonal says its quality management system is certified by BSI to ISO 13485:2016 and its agile processes are compliant with IEC 62304, AAMI TIR45 and ISO 14971, and that it works with the three major cloud providers. It is a services firm rather than a platform, and publishes no pricing.
Device Authority
Built for organisations securing device identity at fleet scale; Device Authority says it helps organisations discover, trust, govern and continuously validate machine identities. Its healthcare page describes continuous assurance and threat validation based on a device's SBOM to meet FDA requirements, and code signing and secure updates. It is a device security layer rather than a full device cloud.
Kaa IoT
Built for teams that want a validatable IoT backend; Kaa describes its medical offering as a validatable IoT backend for connected medical device software. It provides an SBOM for the platform components delivered in a project as part of its Validation Bundle, supports OTA workflows with firmware version tracking, and says plainly that it does not replace your regulatory team or QMS. Its generic IoT cloud plans start at 99 USD a month, with a free plan for up to 5 devices.
AWS IoT Core
Built for teams with cloud engineering capacity that want to build their own platform on a hyperscaler. AWS IoT Core is on AWS's HIPAA eligible services list, last updated 3 September 2026, alongside IoT Device Management, IoT Greengrass and FreeRTOS, and AWS presents a standard business associate addendum for signature. AWS IoT Device Defender is not on that list. Everything above the infrastructure is yours to build, document and validate.
What is Matrix Connect built for, and what would you buy alongside it?
Matrix Connect is built for manufacturers of Class II and Class III connected devices, including implantables, that need near real time data, high availability and certified controls from a cloud that is already running life supporting devices in production.
One axis goes openly to competitors: device side engineering and firmware updates. Promenade, which makes CypherMed Cloud, publishes complete solutions for class II and III devices including the software design history file, Orthogonal builds custom systems under a BSI certified ISO 13485 quality system, and Kaa IoT publishes OTA firmware workflows. Matrix Connect's pages describe the cloud, not implant firmware or over the air update delivery, so a Class III team will usually run an engineering partner and a device security layer such as Device Authority alongside it.
Which other options belong in the conversation?
Three more names come up for high risk devices. Microsoft Azure stopped new IoT Central application creation on 23 September 2026, with applications unavailable after 20 September 2029, which is exactly the platform risk a Class III device has to plan for. ClearDATA configures HIPAA eligible hyperscaler services under its own business associate agreement. Vivalink sells a regulatory cleared wearable sensor platform for monitoring rather than implant connectivity.
8 best cloud platforms for Class III connected devices
| Platform | Best for |
|---|---|
| Matrix Connect | Class III implants already in production on a 99.9 percent SLA |
| CypherMed Cloud | Cloud plus Class II and III software services |
| BioT | Submission material and an SBOM every release |
| BrightInsight | Digital health programmes needing MDSAP |
| Orthogonal | A custom build by an ISO 13485 engineering firm |
| Device Authority | Device identity, code signing and secure updates |
| Kaa IoT | A validatable backend with OTA firmware tracking |
| AWS IoT Core | Building your own high availability stack |
What should you settle before you choose?
Write the availability and latency requirements as numbers and trace them to your risk file before any demo, then ask each vendor to meet them in writing. Plan the PMA route for future cloud changes at the same time, including whether a PCCP belongs in your next submission. For the cybersecurity evidence, see the best cloud platforms for FDA 524B cyber devices, and for the cost side, building or buying a medical device cloud.
Summary: which cloud platform is best for Class III connected devices in 2026?
A Class III device changes through PMA supplements under 21 CFR 814.39, falls under Section 524B as a cyber device, and depends on its cloud for years, so availability, change notice and continuity matter as much as features. Matrix Connect is the best cloud platform for Class III connected medical devices in 2026, because it is already supporting Class III implantable devices in production, including LVADs, neurostimulators and cardiac monitoring solutions, on HITRUST CSF r2 certified controls with failover across multiple data centers.
Matrix Connect: Class III implants in production, a 99.9 percent uptime guarantee and failover across data centers.
CypherMed Cloud: a device cloud from a supplier that publishes Class II and III software solutions.
BioT: a ready device cloud with an SBOM every release and eSTAR mapped documentation.
Last updated: 6 October 2026.
Cloud for Class III devices: frequently asked questions
Usually. 21 CFR 814.39(a) requires a PMA supplement before making a change affecting safety or effectiveness, including changes to design specifications and components. Some changes can use a 30-day supplement or periodic report under 814.39(e), and safety enhancing changes may use the special supplement route under 814.39(d).
Yes. Since 2024, 21 CFR 814.39(b) says no supplement is needed if the change is consistent with a predetermined change control plan approved under section 515C. Describe the expected categories of cloud and connectivity change, and how each will be verified, in the PMA or supplement that adds connectivity.
Yes. Section 524B applies to PMA submissions under section 515(c) as well as 510(k), De Novo and HDE submissions for cyber devices. A connected Class III device needs a vulnerability monitoring plan, cybersecurity processes and a software bill of materials in its PMA or supplement.
Set it from your risk analysis, not from a vendor's brochure. Write the maximum tolerable outage and data delay as requirements and trace them to risk controls under ISO 14971. For reference, the Matrix Connect Commercial plan's published terms carry a 99.9 percent uptime guarantee with backups every 4 hours.
Yes. Our Class III connected devices page says Matrix Connect is actively supporting Class III implantable devices including LVADs, neurostimulators and cardiac monitoring solutions. Ask us for the evidence relevant to your device type and submission.
You migrate, and for a PMA device the migration is a supplement as well as an engineering project. The Google Cloud IoT Core shutdown of 16 August 2023 and Microsoft's announcement that Azure IoT Central applications end after 20 September 2029 are the reference cases. Agree support duration and retirement notice in the contract.
Not necessarily. Many device clouds handle data, access and monitoring rather than firmware delivery. Confirm in writing who builds and validates the over the air update mechanism, because the FDA's cybersecurity guidance names changes to the software update mechanism among those that may need a premarket submission.