Easy13485 4.7.0 : Start lean. Add ISMS when it matters

Easy13485 4.7.0 adds ISMS-related improvements for MedTech startups building SaMD, connected devices or hospital-facing systems. ISO 13485 remains the regulatory backbone, while ISO/IEC 27001 maturity can be added when product, customer or partner requirements make it relevant.
Easy13485 4.7.0 adds ISMS-related improvements for MedTech startups building SaMD, connected devices or hospital-facing systems. ISO 13485 remains the regulatory backbone, while ISO/IEC 27001 maturity can be added when product, customer or partner requirements make it relevant.

Easy13485 4.7.0

Add ISMS when it matters

Not every MedTech startup needs ISO/IEC 27001 from day one.

But if you build SaMD, connected devices or hospital-facing systems, information security maturity will become relevant sooner than many teams expect.

With Easy13485 4.7.0, we focused on one key question:

How can an ISMS become auditable without creating a second management system universe?

Easy13485 4.7.0 adds ISMS-related improvements for MedTech startups building SaMD, connected devices or hospital-facing systems. ISO 13485 remains the regulatory backbone, while ISO/IEC 27001 maturity can be added when product, customer or partner requirements make it relevant.

What we added and improved

With Easy13485 4.7.0, we added and improved several ISMS-related elements:

  • ISMS objectives and dedicated register
  • explicit ISMS assessment in Management Review
  • stronger ISR responsibilities for controls, evidence and ISMS records
  • ISMS Manual as a guide through requirements, processes and templates
  • CIA-based assessment for process software, IT processes and IT equipment
  • Threat Monitoring as a repeatable PMS activity
  • information security incidents integrated into complaint handling
  • clearer tracking of cybersecurity measures: product evidence via design control, process evidence via control register

ISO 13485 remains the regulatory backbone

The idea is simple:

ISO 13485 remains the regulatory backbone.

ISO/IEC 27001 maturity can be added when your product, customers, hospitals, insurers or partners require it.

This approach allows MedTech startups to start lean and add ISMS maturity when it becomes relevant for the product, the customer environment or the market requirements.

Easy13485 4.7.0: ISO 13485 als Basis, ISO/IEC 27001 modular ergänzbar für MedTech-Startups

Relevant for SaMD and connected medical devices

If you are building SaMD or a connected medical device, one important question is:

When does ISMS become relevant for our QMS?

Easy13485 4.7.0 addresses this question by connecting ISO 13485 with information security maturity in a structured way.

The goal is not to create a second management system universe, but to make ISMS elements auditable within the existing QMS logic.

Schreiben Sie einen Kommentar

Ihre E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

*

wellness app medical device

“BREATHMENT” Wellness app or a Medical Device

Overview of the classification variety The following table can serve as a rough orientation of the classification using the example of different pulse measuring functionalities. These tables provide only an exemplary overview. Exact classification may vary by the exact definition of the intended use as discussed later in this paper.

zum Beitrag »

Neue Verlängerung der Übergangsfristen der MDR in Sicht

UPDATE Am 7. März 2023 hat der Rat der Europäischen Union den Vorschlag der Kommission angenommen. Zuvor hatte das Europäische Parlament am 16. Februar 2023 über den Entwurf mit einer positiven Mehrheit abgestimmt. Dementsprechend wird den Herstellern von Medizinprodukten und den Benannten Stellen mehr Zeit für die Zertifizierung von Medizinprodukten gewährt.

zum Beitrag »