What a standard or regulation asks for in practice, what evidence satisfies it, and what changes when it is revised.
Open access, no formAlso available as PDF
TOPIC
PUBLISHED 16 SEPTEMBER 2026ISO 9001:2026 is here, and it is evolution rather than revolution
PLAYBOOKISO 9001Transition
Six expectations that used to be implied are now explicit, clauses 8 to 10 stay familiar, and the transition dates are not yet published. What to gap-assess, and what to leave alone.
Predetermined Change Control Plans, and what your quality system has to hold
PLAYBOOKChange control
A PCCP pre-authorises software changes you have not made yet. The plan does not create control, it commits you in writing to control you must already be able to demonstrate.
Risk management for machine learning in medical devices
PLAYBOOKAIRisk
It does not replace ISO 14971 or add requirements to it. It points the same process at the sources of harm that exist because a device learns from data.
The gray areas between the Cyber Resilience Act and your medical device
BRIEFINGCRAMDR
MDR and IVDR products are excluded under Article 2(2), and the exclusion attaches to the product rather than the company. Nine ecosystem cases where the answer is not obvious.
Setting your AI-powered medical device for success, with Qity AIMS
ARTICLE14 min read
A model can perform well while the evidence explaining how it was created, tested, integrated, released, and maintained stays fragmented. Seven standards used together.
Answer structured questions about one product and the Radar returns its regulatory qualification and class across 17 markets, with the rule it relied on, plus whether the software and AI Act provisions bite.
Or map the company instead: which EU and UK cybersecurity, privacy, product safety and AI obligations apply now, and which are coming.
A card game about clearing the FDA. Pick 510(k), De Novo, or PMA, spend effort filing design controls, risk, verification, cybersecurity, and labelling, and hold the boxes against the reviewer before the clock runs out.