Let’s discuss your device, your target markets, and the quality, software, and cybersecurity support needed to move forward.
A successful medical device submission starts long before the application is assembled. It starts with the processes that guide development, manage risk, verify performance, and keep the product under control as it changes.
For manufacturers pursuing markets in the United States, European Union, United Kingdom, and Canada, a well-designed Quality Management System (QMS) provides that foundation. When software and connectivity are involved, cybersecurity and software lifecycle activities must be built into the same operating framework.
At RQMIS, we help manufacturers connect these activities so that regulatory submissions are supported by consistent, traceable evidence—and the organization is prepared to maintain compliance after market entry.
A QMS defines how your organization makes decisions, assigns responsibility, controls documents, manages suppliers, and demonstrates that a device meets its requirements. Its value comes from implementation: approved procedures, trained personnel, completed records, and documented follow-through.
Consider a simple question from a reviewer: How do you know this software feature works safely? The answer may require a user need, a design requirement, a risk assessment, a test protocol, a result, and an approved software version. A functioning QMS connects those records.
Establishes responsibilities, repeatable processes, and controlled evidence.
Connects requirements, development decisions, testing, and release control.
Addresses threats, security controls, vulnerabilities, and ongoing response.
When these activities are disconnected, teams may discover inconsistent versions, missing approvals, unsupported claims, or incomplete testing just as a submission deadline approaches. Integrating them early helps reveal gaps while there is still time to address them.
An integrated QMS can support a global regulatory strategy, but submission formats, certification expectations, and market-access routes differ. The device’s intended use, classification, technology, and target market determine the applicable requirements.
FDA’s Quality Management System Regulation (QMSR) became effective on February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820, with FDA-specific provisions. Manufacturers must evaluate applicable requirements and exemptions; an ISO certificate alone does not establish FDA compliance.
A 510(k), De Novo, or PMA relies on product-specific evidence generated through controlled processes. QMS compliance and premarket review are related but distinct obligations. Software documentation should match the device, its risks, and FDA’s applicable documentation expectations.
Sources: FDA QMSR · FDA device software guidance
Under the EU MDR—and the IVDR for in vitro diagnostic devices—manufacturers need quality processes and technical documentation appropriate to their products and conformity assessment routes. Notified body involvement depends on classification and applicable exceptions.
For software and connected devices, lifecycle controls, verification and validation, information security, and risk management must work together. Cybersecurity evidence should connect the product’s architecture and operating environment with risk controls, testing, user information, and post-market activities. These connections help make the technical documentation coherent and maintainable.
Source: European Commission MDCG 2019-16 Rev. 1: Cybersecurity for medical devices
Great Britain operates under the UK Medical Devices Regulations 2002, as amended. The applicable UKCA or accepted CE-marking route determines the conformity assessment requirements. Eligible CE-marked devices remain accepted under transitional arrangements, subject to the relevant conditions and deadlines.
Northern Ireland follows the EU MDR and IVDR framework. A UK strategy therefore needs to identify where the product will be supplied and which route applies. In Great Britain, strengthened post-market surveillance requirements took effect on June 16, 2025, reinforcing the importance of ongoing data review and corrective action.
Sources: MHRA market-access guidance · MHRA post-market surveillance requirements
For manufacturers of Class II, III, and IV devices, Canadian licensing requirements include applicable ISO 13485 quality system certification through the Medical Device Single Audit Program (MDSAP). Class I devices follow a different framework and do not carry the same device-licence and MDSAP requirements.
Quality system certification supports licensing, but it does not replace the product evidence required for the relevant class. Health Canada’s cybersecurity guidance addresses risk management, security controls, verification and validation, and lifecycle planning. Software and cybersecurity records should be consistent with the device configuration covered by the application.
Sources: Health Canada MDSAP · Health Canada cybersecurity guidance
Working software is only part of the story. Manufacturers also need to explain what the software is intended to do, how it was developed, how risks were controlled, and how the released version was evaluated.
Software development support helps engineering and quality teams maintain a clear connection between:
For example, adding a new app feature may affect a shared interface, introduce a dependency, or change how data is processed. A controlled change process helps determine which risks, tests, and regulatory documents need to be revisited before release.
Cybersecurity can affect device availability, data integrity, and clinical performance. Security responsibilities therefore need to connect with design reviews, supplier oversight, risk management, complaint handling, and change control.
For devices within FDA’s statutory “cyber device” definition, applicable premarket submissions must address section 524B obligations, including a software bill of materials, post-market vulnerability management planning, and processes for updates and patches. FDA’s broader guidance also discusses security architecture, threat modeling, and testing.
Source: FDA cybersecurity guidance
A practical program assigns owners to security findings, records remediation decisions, verifies fixes, and evaluates whether a change affects safety or regulatory status. Penetration testing contributes evidence, but ongoing oversight is what keeps that evidence relevant as threats and software components change.
The submission is a milestone.
Your quality system must keep working after the product reaches the market
Activity
Connected evidence
Practical value
RQMIS works with manufacturers to align quality, software, cybersecurity, and regulatory activities with their product stage and target markets. Support can include:
Our software support helps manufacturers’ engineering teams establish the lifecycle documentation and controls needed for regulatory readiness. The project scope defines responsibilities and deliverables, with the manufacturer retaining responsibility for its product and compliance.
Whether you are building your first QMS, preparing a submission, expanding into another market, or updating an existing device, starting with a coordinated plan can help reduce avoidable rework and strengthen the evidence behind your decisions.
Explore RQMIS quality services and cybersecurity support.
Let’s discuss your device, your target markets, and the quality, software, and cybersecurity support needed to move forward.