adesso Blog

If you’re developing a medical device, your focus is likely to be on its function: the idea, the clinical benefit, the technology. That’s understandable – after all, your product is meant to help users. But who’s actually checking, in the meantime, whether your product can also ‘stand on its own two feet’ from a regulatory perspective?

Between the MDR, ISO 13485, ISO 14971, IEC 62304 and the like, it’s easy to lose track of the big picture. At the same time, it is precisely these requirements that are key to ensuring a product is even allowed onto the market – and can be used safely once there. A robust quality management system (QMS) is your most important tool in this regard. The ‘QMS Readiness Check’ uses targeted questions to assess the current state of your quality management and provides an overview of which areas are already audit-ready and where further action is required.

From MRI to SaMD – when software becomes medicine

Medical devices are any products used for the diagnosis, prevention, monitoring or treatment of diseases in humans. A classic example: magnetic resonance imaging (MRI). It is estimated that one in two people in Germany undergoes an MRI scan at least once in their lifetime for diagnostic purposes.

Things get interesting as soon as software comes into play: imagine AI-based cloud software that imports MRI images from various devices, automatically identifies and highlights brain aneurysms, and provides doctors with a suggested diagnosis. This software supports a medical decision – and is therefore classified as Software as a Medical Device (SaMD).

Depending on its intended purpose, such software is typically classified as risk class IIa or IIb. And that puts you right in the middle of a world full of requirements, evidence and documentation.

A jungle of standards? Here’s what lies behind it

A medical device – whether hardware, software or a combination – consists of many regulatory building blocks. Among the most important are:

  • MDR – The binding legal framework for medical devices in the EU; the basis of any conformity assessment.
  • ISO 13485 – Defines your quality management system and is therefore the central building block for conformity.
  • ISO 14971 – Risk management: identifying, assessing, mitigating and monitoring risks.
  • IEC 62304 – The software standard for medical devices, key to demonstrating software conformity.
  • IEC 62366-1 – Focus on usability: safe, intuitive operation, minimised user errors.
  • IEC 81001-1 – State-of-the-art IT and cyber security in healthcare software.
  • IEC 60601-1 – Key safety standard for electrical medical devices.

Many manufacturers are familiar with these standards – yet the real challenge remains: Which requirements are truly relevant to your product, to what extent and how specifically must you implement them, and how do you demonstrate this in your QMS and technical documentation?

QMS as the linchpin of your compliance

Regulatory requirements are not just a burdensome add-on to development – they must be firmly integrated into your processes. This is exactly where your QMS comes into play:

  • It structures how you develop, test and document.
  • It defines who is responsible for what.
  • It ensures that you have risks, changes, CAPAs, PMS and vigilance under control.
  • It provides the basis for your approval by the Notified Body.

Without an actively implemented QMS, compliance quickly becomes a gamble – particularly with SaMD, where software and safety requirements are scrutinised particularly closely.

Our QMS Readiness Check – your practical shortcut

A tool that shows you in just a few minutes where your QMS really stands: the QMS Readiness Check was developed by three regulatory experts from our MPL business line to finally give the topic of QMS the attention it deserves. Technically implemented using Claude – designed and set up by the three experts themselves. The first version is currently being finalised, after which the check will be available via the adesso website.

The aim is to provide a pragmatic assessment of how ‘fit’ the QMS and technical documentation are for a regulated environment – particularly for Software as a Medical Device products.

Here’s how it works:

1. The customer works through a structured checklist
The questions are structured in line with the relevant standards and the MDR – tailored to:

  • MDR risk classes I, IIa, IIb, III
  • Software risk classes A, B, C (IEC 62304)

2. The client answers targeted, branching questions
Depending on their answers along the main MDR pathway, they are directed to detailed questions on the individual standards to examine the QMS more closely.

3. An automated evaluation runs in the background
The answers are evaluated using a formula and consolidated into a percentage assessment.

4. The result: a practical assessment of your current position
The customer receives an indication of how well the QMS is set up before proceeding to the next stage with the Notified Body and other relevant parties. To this end, the customer is offered an adesso package and will be contacted by our experts.

Conclusion: It pays to assess early

Our experience shows that carrying out a reality check in good time helps avoid unpleasant surprises during the audit. Our QMS experts will show you which requirements are crucial for your product, to what extent you need to implement them, and how to demonstrate the conformity of your QMS – for a successful market entry and sustainable market retention.

Picture Samira Hamm

Author Samira Hamm

Samira Hamm has been working in the Life Sciences division at adesso SE for several years. Her specialist focus is on requirements engineering and quality management in software projects, particularly within the highly regulated healthcare and medical sectors. She combines methodological expertise with a deep understanding of industry-specific requirements.