Not all software has the same consequences for failure. The highest level is when failure is catastrophic, i.e. "Failure may cause deaths, usually with loss of the airplane." This requires the highest "Level A" assurance level.
Presumably MCAS was not originally evaluated as needing to meet the highest level. If it were, the single AoA input would have immediately disqualified the design right off the bat.
There's some speculation that the delays on the "fix" are because if they have to redevelop the software at a "Level A" standard that means basically a complete reimplementation with full tracability of requirements from design to source code through compilation to executable, with independent verification. That won't happen in a few weeks.