Pre-market Services

Medical Device Compliance & Security

We implement a robust medical device management systems, ensuring compliance with ISO 13485, ISO 27001, NEN 7510-1 and others for quality and information security.

Services

  • Implement Information Security Management System (ISO/IEC 27001, NEN 7510-1)
  • Implement Quality Management Systems (ISO 13485, MDSAP, QSR/QMSR)
  • Auditing of Management Systems (Internal, mock, due diligence, supplier, subcontractor audits)
  • Review Quality and Information Security Contracts
  • Interim Quality, Security, and Regulatory support
  • Management Review Assistance
  • ISO 13485 & Information Security Training (Introduction, internal auditor, lead auditor)
Our Specialty

What Do We Offer?

Whether you manufacture medical devices or operate as an economic operator (e.g., importer, distributor, repackager, OEM supplier), implementing a management system can support regulatory compliance. The most widely adopted medical device quality management system (QMS) is ISO 13485 for medical devices, though regional regional requirements may need to be addressed on top of the standard (e.g., in the US, Canada, Brazil, and Australia). For manufacturers entering multiple markets, the Medical Device Single Audit Program (MDSAP) can further streamline compliance and, in some cases, is mandatory.

ISO/IEC 27001 (and NEN 7510-1 in the Netherlands) provides a framework for an information security management system (ISMS) tailored to medical devices. Beyond a QMS and ISMS, management systems can be extended to include Good Clinical Practice (GCP), Privacy Management (ISO/IEC 27701), and Good Machine Learning Practices (GMLP).

At MedQAIR, we specialise in implementing the best management systems for medical devices, covering quality management, information security, and compliance with evolving AI regulations. Our expertise includes ISO 13485, ISO/IEC 27001, and NEN 7510-1, ensuring compliance across design, development, distribution, and post-market surveillance.

Relevant Resources - EU

  • UDI Integration in QMS
  • European AI Act 2024/1689
  • Medical Device Language Requirements by Country
  • NEN 7510-1 informative page (NEN, Dutch)

Relevant Resources - US

  • QMS Regulation: Final Rule & FAQs
  • QS Regulation & Medical Device CGMP

Relevant Resources - Others

  • IMDRF: MDSAP informative page (FDA website)
  • ISO/IEC 27001
  • ISO 13485
  • ISO/IEC 42001
Blog Hub

Latest Insights & Updates

Explore our blog posts on MDR, IVDR, and EU AI Act medical device compliance to stay ahead of regulatory changes.

Frequently Asked Questions

Find answers to common questions about our services, compliance processes, and how we can assist your business.

Why do medical device organisations need a management system?

Management systems provide the framework for controlling product quality, regulatory compliance, information security, supplier oversight, and post-market activities. Regulators increasingly expect manufacturers and other economic operators to demonstrate that these activities are managed through documented and controlled processes.

How does ISO 13485 support MDR and IVDR compliance?

ISO 13485 is widely used as the foundation for medical device quality management systems. While compliance with ISO 13485 alone does not guarantee MDR or IVDR compliance, it provides the structure needed to manage design controls, supplier management, risk management, post-market activities, and regulatory documentation.

Can one management system support multiple markets?

Yes. A well-designed management system can support compliance across multiple jurisdictions, including the EU (MDR/IVDR), United States (FDA QMSR), Canada (where MDSAP is mandated), Australia, and other international markets. Additional market-specific requirements can then be integrated into the core system.

How does information security fit within medical device compliance?

Information security is increasingly linked to product safety, cybersecurity, privacy, and regulatory compliance. Standards such as ISO/IEC 27001 and NEN 7510-1 help organisations establish governance and controls for managing sensitive information and supporting cybersecurity obligations throughout the product life cycle.

Do AI-enabled medical devices require additional management system controls?

Yes. AI-enabled systems often require additional governance activities related to data management, model development, validation, monitoring, cybersecurity, and change management. Management systems should support these activities while maintaining compliance with applicable medical device and AI regulations.

Can MedQAIR help integrate quality management and information security processes?

Yes. Many organisations benefit from integrating quality and information security activities into a single management framework. This helps reduce duplication, improve governance, and create alignment between regulatory compliance, cybersecurity, and operational processes.

What is MDSAP and when is it relevant?

The Medical Device Single Audit Program (MDSAP) allows manufacturers to demonstrate compliance with quality management requirements across multiple participating regulatory jurisdictions through a single audit programme. It is particularly important for manufacturers seeking access to the Canadian market.

How do management systems support regulatory inspections and audits?

Management systems establish the procedures, records, responsibilities, and evidence needed during regulatory inspections, certification audits, supplier audits, and due diligence reviews. Well-maintained systems help organisations demonstrate compliance and respond efficiently to audit findings.

Can importers, distributors, authorised representatives, and other economic operators benefit from management systems?

Yes. Economic operators have responsibilities under MDR, IVDR, and other regulatory frameworks. Structured management processes help ensure traceability, supplier oversight, complaint handling, documentation control, and fulfilment of regulatory obligations.

How often should management systems be reviewed?

Management systems should be reviewed on an ongoing basis to reflect organisational changes, new products, regulatory developments, cybersecurity risks, supplier changes, and audit outcomes. Periodic management reviews help ensure continued effectiveness and compliance.

What are the most common compliance gaps identified during management system assessments?

Common findings include incomplete procedures, inadequate training records, weak supplier controls, insufficient cybersecurity governance, ineffective risk management processes, gaps in post-market activities, and inconsistencies between documented procedures and operational practice.

Can management systems support cybersecurity and privacy compliance?

Yes. Management systems can help organisations establish governance processes for cybersecurity, vulnerability management, incident handling, supplier oversight, access control, and privacy-related activities. These processes support compliance with standards and regulations applicable to healthcare technologies.

What is the role of training within a management system?

Training ensures personnel understand their responsibilities, applicable procedures, regulatory requirements, and organisational processes. Effective training programmes support audit readiness, operational consistency, and ongoing compliance throughout the product lifecycle.

Can MedQAIR support organisations that already have a management system in place?

Yes. MedQAIR supports both new implementations and existing systems. Services include gap assessments, remediation planning, audit preparation, process optimisation, supplier management reviews, cybersecurity integration, training, and ongoing quality, security, and regulatory support.

How do management systems support organisations developing software and AI systems?

Management systems help organisations establish controlled processes for software development, change management, validation, cybersecurity, supplier management, documentation, and post-market monitoring. These controls support compliance across software medical devices, AI-enabled systems, electronic health record systems, and other digital health technologies.

Is ISO 13485 certification mandatory for medical device manufacturers?

ISO 13485 is not legally mandatory in every jurisdiction, but it is the de facto global standard for a medical device QMS and is required in practice in most markets. The EU MDR/IVDR requires an “”appropriate”” QMS (Article 10), and Notified Bodies use ISO 13485 as the basis for audit. In the US, FDA’s Quality Management System Regulation (QMSR), effective February 2026, aligns 21 CFR Part 820 with ISO 13485:2016. Canada, Australia, Japan, and other MDSAP countries also use ISO 13485 as the audit standard.

Book a Free 30-Minute Consultation

Schedule a Meeting With Our Experts

Get a Free Consultation