CODE TO COMPLIANCE

The blog

Medtech compliance in engineer's language — standards unpacked, field notes, reproducible pipelines.

Stylised compliance-evidence pipeline, cobalt accents on an ivory background, controls checked automatically
ENGINEERING · 8 MIN Comp AI: open-source compliance-as-code meets the medical device

Comp AI automates SOC 2, ISO 27001 and HIPAA evidence, open-source: what compliance-as-code gives a medtech SaaS, and why the MDR technical file stays separate.

Stylised compliance dashboard, cobalt accents on an ivory background, wired to a self-hosted server
CYBERSECURITY · 8 MIN Unicis Platform CE: open-source GRC for a medical device team

Unicis Platform CE, self-hosted open-source GRC: what it covers for a medical device software team — ISMS, risk register, GDPR — and where the MDR file starts.

Central administration console fanning out to a fleet of endpoints, on a dark background with cobalt accents
CYBERSECURITY · 10 MIN The Stryker attack hit no medical device — and that is exactly the problem

The Stryker attack reached no medical device, but the manufacturer's control plane. What that changes for your threat model and your quality system.

Article cover: schematic architecture views on the left, risk matrix on the right with initial scoring in amber and residual scoring in green
CYBERSECURITY · 12 MIN Threat modelling a medical device: architecture views and the risk matrix

The threat model the FDA expects: four security architecture views, the risk matrix, exploitability rather than probability, and the transfer into ISO 14971.

SBOM card with CycloneDX and SPDX formats linked through a cobalt scan gate to a VEX card listing the not_affected, affected, fixed and under_investigation statuses
CYBERSECURITY · 8 MIN From SBOM to VEX: managing medical device vulnerabilities without drowning the team

Scanning your SBOM, triaging CVE noise and recording every decision with VEX: the post-market surveillance pipeline the FDA and IEC 81001-5-1 expect.

Pages of a technical document on an ivory desk, cobalt markers flagging passages to validate
ENGINEERING · 9 MIN Automating 80% of your IEC 62304 docs without failing audit: the human–AI boundary

Generating 80% of IEC 62304 docs with AI without audit rejection: what to automate, the 20% a human must own, and the gate that keeps the file defensible.

Software component inventory displayed on a dark screen with cobalt-blue accents
CYBERSECURITY · 8 MIN A medical device SBOM: the legal requirement (FDA §524B, CRA) and how to keep it

The SBOM went from best practice to legal requirement: FDA §524B, the Cyber Resilience Act. What it must contain, the formats, and how to maintain it.

Connected medical device with a cobalt-blue status LED on a dark surface
CYBERSECURITY · 8 MIN FDA §524B: the cybersecurity plan without which your submission will be refused

Section 524B of the FD&C Act: cyber device criteria, the 4 legal requirements (vulnerability plan, SBOM), differences with the EU, and an 8-point checklist.

Dark screen showing a CI/CD pipeline graph with cobalt-blue nodes
ENGINEERING · 9 MIN The IEC 62304 documentation that writes itself: our CI/CD pipeline

Generating IEC 62304 documentation from the CI/CD pipeline: SOUP list from the SBOM, requirements-tests traceability, release notes — concrete mapping.

Padlock resting on a printed circuit board with cobalt-blue traces
CYBERSECURITY · 11 MIN IEC 81001-5-1: where to start when you already have 100k lines of code

A realistic 5-step IEC 81001-5-1 catch-up plan for existing code: SBOM, threat model, vulnerability handling, testing, documentation — without rewriting it.