<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Doxeva — Code to Compliance</title><description>Medical device software compliance, explained for engineers: IEC 62304, MDR Rule 11, cybersecurity, ISO 14971.</description><link>https://doxeva.com/</link><language>en-US</language><item><title>A medical device SBOM: the legal requirement (FDA §524B, CRA) and how to keep it</title><link>https://doxeva.com/en/blog/sbom-medical-device/</link><guid isPermaLink="true">https://doxeva.com/en/blog/sbom-medical-device/</guid><description>The SBOM went from best practice to legal requirement: FDA §524B, the Cyber Resilience Act, IEC 81001-5-1. What it must contain, the CycloneDX/SPDX formats, and how to generate and maintain it.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The MDR technical documentation for software: the structure a notified body expects</title><link>https://doxeva.com/en/blog/technical-file-mdr-software/</link><guid isPermaLink="true">https://doxeva.com/en/blog/technical-file-mdr-software/</guid><description>MDR Annexes II and III applied to a SaMD: which sections, which artifacts, and the mistakes that stall an audit. The technical file structure a notified body expects.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FDA §524B: the cybersecurity plan without which your submission will be refused</title><link>https://doxeva.com/en/blog/fda-524b-cybersecurity-plan/</link><guid isPermaLink="true">https://doxeva.com/en/blog/fda-524b-cybersecurity-plan/</guid><description>Section 524B of the FD&amp;C Act: cyber device criteria, the 4 legal requirements (vulnerability plan, secure development, SBOM, patches), differences with the EU, and an 8-point checklist.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The IEC 62304 documentation that writes itself: our CI/CD pipeline</title><link>https://doxeva.com/en/blog/iec-62304-docs-ci-cd-pipeline/</link><guid isPermaLink="true">https://doxeva.com/en/blog/iec-62304-docs-ci-cd-pipeline/</guid><description>Generating IEC 62304 documentation from the CI/CD pipeline: SOUP list from the SBOM, requirements-tests traceability, PR reviews, release notes. Concrete mapping and an example pipeline.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>IEC 81001-5-1: where to start when you already have 100k lines of code</title><link>https://doxeva.com/en/blog/iec-81001-5-1-where-to-start/</link><guid isPermaLink="true">https://doxeva.com/en/blog/iec-81001-5-1-where-to-start/</guid><description>A realistic 5-step IEC 81001-5-1 catch-up plan for existing code: SBOM, threat model, vulnerability management, security testing and documentation — without rewriting your product.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>MDR Rule 11: why your app is probably Class IIa</title><link>https://doxeva.com/en/blog/mdr-rule-11-class-iia/</link><guid isPermaLink="true">https://doxeva.com/en/blog/mdr-rule-11-class-iia/</guid><description>Rule 11 of Annex VIII of the MDR explained for CTOs: decision tree, MDCG 2019-11 guidance, concrete consequences and edge cases. Why almost all SaMD is at least Class IIa.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>