Easy13485 Update ISO IEC 27001 Release 4.6.0

If you’re building SaMD, you can’t treat ISO 13485 (MDR) and ISO/IEC 27001 (ISMS) as separate projects anymore. Release 4.6.0 integrates both into one lean, startup-operable QMS—without creating a second process landscape.
Easy13485 meets ISO IEC 27001
Release 4.6.0 · Easy13485 Makerspace

ISO 13485 meets ISO/IEC 27001 — one system, not two

MedTech teams get pulled into ISO/IEC 27001 the moment insurers, hospitals or B2B partners ask for it — often long before certification is even on the table. Release 4.6.0 adds the ISMS Extension into your existing Easy13485 QMS, so you don't have to build and run a second management system next to it.

ISO 13485 ISO/IEC 27001 Essential & Certified No second process landscape
Easy13485 Release 4.6.0 — ISO 13485 meets ISO/IEC 27001
The problem

Two mindsets, one team

Run both without an anchor and your QMB ends up maintaining two rulebooks, two audit calendars, and two versions of "how we actually work."

MedTech thinking

Analyze first, act after

Risk gets classified, documented and signed off before a control is implemented. Correct for product risk. Too slow for information security.

Security thinking

Baseline now, refine later

Controls go live even before every detail is perfect, then get tightened over time. Correct for security. Feels reckless inside a 13485 mindset.

Release 4.6.0 doesn't pick a side. It gives both mindsets one place to live.

What we did

One QMS, ISMS included — not bolted on

ISO/IEC 27001 is integrated as an additional management system inside your existing QMS. No new main processes, no second process landscape.

1

No second process landscape

ISO/IEC 27001 runs as an additional management system inside your existing QMS — not next to it.

2

13485 coverage mapped

Wherever your ISO 13485 processes already satisfy a 27001 control, the reference shows it. You don't rebuild what's already there.

3

ISMS content stays filterable

Teams that only need ISO 13485 don't see ISMS-only content cluttering their system.

4

Dedicated 27001 roles

New role definitions for information security responsibilities, aligned with your existing QMB / PRRC structure.

"4.6.0 merges both mindsets into one lean setup for MedTech startups — without building a second management-system universe. If you're building SaMD, partners and auditors increasingly expect security maturity alongside regulatory discipline. Best of all: you don't need to start with 27001 — you can extend into it once insurers, hospitals or partners ask for it."

— Dr. Volker Klügl, Managing Director, ipp. Dr. Klügl

Scope

Two depths, freely combinable with your product line

The ISMS Extension sits on top of Essential or Certified. It is not available on Light — Light is scoped for simple, low-complexity products without a software/electronic scope.

Essential depth

Structure and framework

ISO/IEC 27001-oriented ISMS structure with an annual remote ISMS Internal Audit included. CIA assessment, Statement of Applicability, incident management and individual SOP maintenance stay with your team — that's how the standard is built, not something IPP can take over.

Certified depth

Certification-oriented

Everything in Essential depth, plus deeper evidence logic and certification-body preparation. Freely combinable with either 13485 line — e.g. Certified (13485) with ISMS Essential depth, or Essential (13485) with ISMS Certified depth.

The ISMS Internal Audit and your ISO 13485 Internal Audit stay two separate annual remote audits. We don't combine them — there's too much ground to cover in one session.

Fit & limits

Where this becomes relevant — and where it stops

Relevant for you if

  • Building SaMD and partners or hospitals ask about security maturity.
  • Insurers or hospital partners require IT security evidence before covering your device deployment.
  • Already on Essential or Certified and want security discipline without running a second system.

What this doesn't do

  • No certification — the certification body issues that, not Easy13485.
  • No CIA assessment or SoA on our side — that stays with your team, as the standard requires.
  • No combined audit — ISO 13485 and ISMS keep two separate annual reviews.
Questions

Before you start

Do we need ISO/IEC 27001 from day one?

No. You can run Easy13485 without ISMS and add the Extension once insurers, hospitals or partners start asking for security maturity.

Is the ISMS Internal Audit combined with our ISO 13485 audit?

No, they stay two separate annual remote audits — different topics, different scope.

Does IPP handle the CIA assessment and Statement of Applicability?

No. IPP delivers the ISMS structure, framework and audit format. The CIA assessment, SoA, incident management and SOP maintenance are your team's responsibility — the standard doesn't allow IPP to take that over.

Can we run the ISMS Extension on Light?

No. Light is scoped for simple, low-complexity products. The ISMS Extension is available on Essential and Certified only.

Next step

Find out where you stand

A Claim Check clarifies your claim, scope and product line — and whether the ISMS Extension is relevant for you now, or something to plan for later.

Schreiben Sie einen Kommentar

Ihre E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

*