Guides and playbooks/Cybersecurity
QITY QMS AND AIKIDO

Prepare cybersecurity evidence earlier, and get it accepted faster

The joint playbook from Qity QMS and Aikido for secure-by-design submission acceleration.

Playbook, 6 sectionsAugust 2026
Download the PDF
TL;DR
  • 01Cybersecurity evidence for a submission is usually assembled late, and four artefact sets get reconciled by hand: threat model reporting, vulnerability findings, risk evaluations, and SBOM records.
  • 02On average, about 40 percent of that evidence already exists in the QMS. Aikido produces the rest continuously during development.
  • 03Three links close the round trip: SBOM versions align with release baselines, vulnerability findings feed risk evaluation, and remediation moves through formal change control.
  • 04The result is earlier readiness, fewer review cycles, and more predictable submissions, without rebuilding the file before submission.

The challenge: the cybersecurity file is assembled late

Cybersecurity evidence for medical device submissions is often assembled late, across disconnected systems. Four artefact sets have to be reconciled by hand before submission: threat model reporting, vulnerability findings, risk evaluations, and SBOM records.

Most companies spend weeks before submission rebuilding the cybersecurity file: producing threat model reports, documenting vulnerability findings, reconciling risk evaluations, and exporting SBOM records.

The shift: your cybersecurity documentation, in one round trip

Connect the cybersecurity artefacts generated in Aikido with lifecycle governance in Qity QMS, and the same artefacts produced during development become submission-ready evidence.

AIKIDO

Generates cybersecurity artefacts continuously during development.

QITY QMS

Governs the lifecycle and the regulatory framework as controlled records.

SUBMISSION

Submission-ready evidence, already assembled when submission starts.

When submission starts, the cybersecurity file already exists.

What you already have

On average, about 40 percent of the cybersecurity evidence needed for a submission already exists in the QMS. Aikido produces the remaining 60 percent continuously during development.

QITY QMS CONTAINS
  • DHR records
  • Software and hardware development documentation
  • Architecture descriptions
  • Risk management files
  • Design verification and validation
  • Device master record baselines
AIKIDO CONTAINS
  • Dependency inventories
  • Machine-readable SBOMs
  • Vulnerability findings
  • Penetration testing

One quality management system, one cybersecurity evidence set

Cybersecurity documentation and artefacts generated throughout development exist in Qity QMS as controlled records, with integrated dynamic risk management built in. Aikido feeds it directly.

  • SBOM versions align with release baselines.
  • Vulnerability findings feed risk evaluation.
  • Remediation moves through formal change control, directly into the QMS.

The outcome: secure-by-design submission acceleration

Qity QMS governs the management system and the regulatory framework. Aikido generates continuous cybersecurity artefacts during development. Together they produce the cybersecurity evidence required for FDA submissions and MDR technical documentation without rebuilding the file before submission: earlier readiness, fewer review cycles, and more predictable submissions.

TRY THIS YOURSELF

Check which EU and UK regulations apply to your company. About a minute, no account required.

Open the Compliance Radar

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA