What a standard or regulation asks for in practice, what evidence satisfies it, and what changes when it is revised.
Open access, no formAlso available as PDF
TOPIC
IMDRF/SAMD WG/N90 FINAL:2026
Predetermined Change Control Plans, and what your quality system has to hold
PLAYBOOKChange control
A PCCP pre-authorises software changes you have not made yet. The plan does not create control, it commits you in writing to control you must already be able to demonstrate.
Risk management for machine learning in medical devices
PLAYBOOKAIRisk
It does not replace ISO 14971 or add requirements to it. It points the same process at the sources of harm that exist because a device learns from data.
The gray areas between the Cyber Resilience Act and your medical device
BRIEFINGCRAMDR
MDR and IVDR products are excluded under Article 2(2), and the exclusion attaches to the product rather than the company. Nine ecosystem cases where the answer is not obvious.
Setting your AI-powered medical device for success, with Qity AIMS
ARTICLE14 min read
A model can perform well while the evidence explaining how it was created, tested, integrated, released, and maintained stays fragmented. Seven standards used together.
Answer a few questions about your size, sector, and target markets. The Radar returns the EU and UK regulations that apply to you now and the ones that are coming, and names for each one when it starts to bite and what evidence it expects.
Useful before a funding round, a new market, or a first submission, when the question is which obligations you have already crossed into.
A SAMPLE RESULT
NIS2, important entityCyber Resilience ActEU AI Act, high riskGDPR, controller and processorMDR, class IIa
A card game about clearing the FDA. Pick 510(k), De Novo, or PMA, spend effort filing design controls, risk, verification, cybersecurity, and labelling, and hold the boxes against the reviewer before the clock runs out.