The blog
Medtech compliance in engineer's language — standards unpacked, field notes, reproducible pipelines.
Comp AI automates SOC 2, ISO 27001 and HIPAA evidence, open-source: what compliance-as-code gives a medtech SaaS, and why the MDR technical file stays separate.
Unicis Platform CE, self-hosted open-source GRC: what it covers for a medical device software team — ISMS, risk register, GDPR — and where the MDR file starts.
The Stryker attack reached no medical device, but the manufacturer's control plane. What that changes for your threat model and your quality system.
The threat model the FDA expects: four security architecture views, the risk matrix, exploitability rather than probability, and the transfer into ISO 14971.
Scanning your SBOM, triaging CVE noise and recording every decision with VEX: the post-market surveillance pipeline the FDA and IEC 81001-5-1 expect.
Generating 80% of IEC 62304 docs with AI without audit rejection: what to automate, the 20% a human must own, and the gate that keeps the file defensible.
The SBOM went from best practice to legal requirement: FDA §524B, the Cyber Resilience Act. What it must contain, the formats, and how to maintain it.
Section 524B of the FD&C Act: cyber device criteria, the 4 legal requirements (vulnerability plan, SBOM), differences with the EU, and an 8-point checklist.
Generating IEC 62304 documentation from the CI/CD pipeline: SOUP list from the SBOM, requirements-tests traceability, release notes — concrete mapping.
A realistic 5-step IEC 81001-5-1 catch-up plan for existing code: SBOM, threat model, vulnerability handling, testing, documentation — without rewriting it.