The blog
Medtech compliance in engineer's language — standards unpacked, field notes, reproducible pipelines.
The SBOM went from best practice to legal requirement: FDA §524B, the Cyber Resilience Act, IEC 81001-5-1. What it must contain, the CycloneDX/SPDX formats, and how to generate and maintain it.
MDR Annexes II and III applied to a SaMD: which sections, which artifacts, and the mistakes that stall an audit. The technical file structure a notified body expects.
Section 524B of the FD&C Act: cyber device criteria, the 4 legal requirements (vulnerability plan, secure development, SBOM, patches), differences with the EU, and an 8-point checklist.
Generating IEC 62304 documentation from the CI/CD pipeline: SOUP list from the SBOM, requirements-tests traceability, PR reviews, release notes. Concrete mapping and an example pipeline.
A realistic 5-step IEC 81001-5-1 catch-up plan for existing code: SBOM, threat model, vulnerability management, security testing and documentation — without rewriting your product.
Rule 11 of Annex VIII of the MDR explained for CTOs: decision tree, MDCG 2019-11 guidance, concrete consequences and edge cases. Why almost all SaMD is at least Class IIa.