RESOURCES

Guides and playbooks

What a standard or regulation asks for in practice, what evidence satisfies it, and what changes when it is revised.

Open access, no formAlso available as PDF
TOPIC
IMDRF/SAMD WG/N90 FINAL:2026

Predetermined Change Control Plans, and what your quality system has to hold

PLAYBOOKChange control

A PCCP pre-authorises software changes you have not made yet. The plan does not create control, it commits you in writing to control you must already be able to demonstrate.

Read the playbook
QITY QMS AND AIKIDO

Prepare cybersecurity evidence earlier

PLAYBOOKCybersecurity

Cybersecurity evidence for a submission is usually assembled late, across disconnected systems. The round trip that removes that step.

Read the playbook
ISO/TS 24971-2:2026

Risk management for machine learning in medical devices

PLAYBOOKAIRisk

It does not replace ISO 14971 or add requirements to it. It points the same process at the sources of harm that exist because a device learns from data.

Read the playbook
REPORTING CLOCK STARTS 11 SEPTEMBER 2026

The gray areas between the Cyber Resilience Act and your medical device

BRIEFINGCRAMDR

MDR and IVDR products are excluded under Article 2(2), and the exclusion attaches to the product rather than the company. Nine ecosystem cases where the answer is not obvious.

Read the briefing
EN 18031 AND THE RED

Cybersecurity under the Radio Equipment Directive

PLAYBOOKEN 18031

Four gates decide whether you can self-declare. The password option is the most common self-inflicted trigger that closes Annex II.

Read the playbook
8 JULY 2026

IEC 62304 Edition 2, and is your QMS ready for software and AI evidence

ARTICLE9 min read

Scope widens toward health software, three safety classes become two rigor levels, and an AI development lifecycle enters the standard.

Read the article
21 JULY 2026

Setting your AI-powered medical device for success, with Qity AIMS

ARTICLE14 min read

A model can perform well while the evidence explaining how it was created, tested, integrated, released, and maintained stays fragmented. Seven standards used together.

Read the article
9 AUGUST 2026

Six records that make a DPIA defensible

ARTICLE5 min read

A DPIA is judged on whether the reasoning behind it can still be produced, for the processing as it runs today rather than as it was designed.

Read the article

FREE FROM QITY

COMPLIANCE RADAR

Not sure which rules apply to you

Answer a few questions about your size, sector, and target markets. The Radar returns the EU and UK regulations that apply to you now and the ones that are coming, and names for each one when it starts to bite and what evidence it expects.

Useful before a funding round, a new market, or a first submission, when the question is which obligations you have already crossed into.

A SAMPLE RESULT
NIS2, important entityCyber Resilience ActEU AI Act, high riskGDPR, controller and processorMDR, class IIa
Open the Compliance Radar qity.app, about a minute, no account
CLEARED!, a Qity card game
CLEARED!

Take a device to market, one submission at a time

A card game about clearing the FDA. Pick 510(k), De Novo, or PMA, spend effort filing design controls, risk, verification, cybersecurity, and labelling, and hold the boxes against the reviewer before the clock runs out.

Play at qity.cat qity.cat, free, in the browser

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA