ISO 13485 meets ISO/IEC 27001 — one system, not two
MedTech teams get pulled into ISO/IEC 27001 the moment insurers, hospitals or B2B partners ask for it — often long before certification is even on the table. Release 4.6.0 adds the ISMS Extension into your existing Easy13485 QMS, so you don't have to build and run a second management system next to it.
Two mindsets, one team
Run both without an anchor and your QMB ends up maintaining two rulebooks, two audit calendars, and two versions of "how we actually work."
Analyze first, act after
Risk gets classified, documented and signed off before a control is implemented. Correct for product risk. Too slow for information security.
Baseline now, refine later
Controls go live even before every detail is perfect, then get tightened over time. Correct for security. Feels reckless inside a 13485 mindset.
Release 4.6.0 doesn't pick a side. It gives both mindsets one place to live.
One QMS, ISMS included — not bolted on
ISO/IEC 27001 is integrated as an additional management system inside your existing QMS. No new main processes, no second process landscape.
No second process landscape
ISO/IEC 27001 runs as an additional management system inside your existing QMS — not next to it.
13485 coverage mapped
Wherever your ISO 13485 processes already satisfy a 27001 control, the reference shows it. You don't rebuild what's already there.
ISMS content stays filterable
Teams that only need ISO 13485 don't see ISMS-only content cluttering their system.
Dedicated 27001 roles
New role definitions for information security responsibilities, aligned with your existing QMB / PRRC structure.
"4.6.0 merges both mindsets into one lean setup for MedTech startups — without building a second management-system universe. If you're building SaMD, partners and auditors increasingly expect security maturity alongside regulatory discipline. Best of all: you don't need to start with 27001 — you can extend into it once insurers, hospitals or partners ask for it."
— Dr. Volker Klügl, Managing Director, ipp. Dr. Klügl
Two depths, freely combinable with your product line
The ISMS Extension sits on top of Essential or Certified. It is not available on Light — Light is scoped for simple, low-complexity products without a software/electronic scope.
Structure and framework
ISO/IEC 27001-oriented ISMS structure with an annual remote ISMS Internal Audit included. CIA assessment, Statement of Applicability, incident management and individual SOP maintenance stay with your team — that's how the standard is built, not something IPP can take over.
Certification-oriented
Everything in Essential depth, plus deeper evidence logic and certification-body preparation. Freely combinable with either 13485 line — e.g. Certified (13485) with ISMS Essential depth, or Essential (13485) with ISMS Certified depth.
The ISMS Internal Audit and your ISO 13485 Internal Audit stay two separate annual remote audits. We don't combine them — there's too much ground to cover in one session.
Where this becomes relevant — and where it stops
Relevant for you if
- ✓Building SaMD and partners or hospitals ask about security maturity.
- ✓Insurers or hospital partners require IT security evidence before covering your device deployment.
- ✓Already on Essential or Certified and want security discipline without running a second system.
What this doesn't do
- ✕No certification — the certification body issues that, not Easy13485.
- ✕No CIA assessment or SoA on our side — that stays with your team, as the standard requires.
- ✕No combined audit — ISO 13485 and ISMS keep two separate annual reviews.
Before you start
Do we need ISO/IEC 27001 from day one?
No. You can run Easy13485 without ISMS and add the Extension once insurers, hospitals or partners start asking for security maturity.
Is the ISMS Internal Audit combined with our ISO 13485 audit?
No, they stay two separate annual remote audits — different topics, different scope.
Does IPP handle the CIA assessment and Statement of Applicability?
No. IPP delivers the ISMS structure, framework and audit format. The CIA assessment, SoA, incident management and SOP maintenance are your team's responsibility — the standard doesn't allow IPP to take that over.
Can we run the ISMS Extension on Light?
No. Light is scoped for simple, low-complexity products. The ISMS Extension is available on Essential and Certified only.
Find out where you stand
A Claim Check clarifies your claim, scope and product line — and whether the ISMS Extension is relevant for you now, or something to plan for later.

