SaMD & connected devices
Software and connected-device makers preparing FDA or MDR submissions who need the QMS and the cybersecurity file to tell the same story.
Regulatory + cybersecurity compliance for MedTech
ISO 13485, EU MDR, FDA and premarket cybersecurity, delivered by one practitioner team that understands both the regulation and the code. Fixed fees, defined scope, built for your team to own.
Who we help
Software and connected-device makers preparing FDA or MDR submissions who need the QMS and the cybersecurity file to tell the same story.
Funded start-ups building their first certified quality system, written for their team and their product, not a template set.
Health-software companies selling to hospitals, insurers and the NHS who need ISO 27001, AI governance and security evidence to close deals.
Services
MD QMS Assure builds the quality and regulatory system. MD QMS Apex builds the security engineering behind a regulated product. Every engagement starts with a fixed-price first step.
Build or align your quality system for EU, UK and US markets, from gap analysis to certification.
From £3,000 per standard, gap analysis
View service → Assure · Quality & regulatoryTechnical documentation, economic-operator roles and EUDAMED registration, done right the first time.
From £1,500 market-access check
View service → Assure · Quality & regulatoryISO 42001 and the EU AI Act, mapped onto the MDR evidence you already hold.
From £4,000 readiness assessment
View service → Assure · Quality & regulatoryIndependent internal audits, audit preparation and regulatory horizon-scanning, so your certificate stays valid.
From £1,500 per month
View service → Apex · Security engineeringSBOM, threat model, security risk management and post-market plan, written by people who read the code and the regulation.
From £4,500 readiness assessment
View service → Apex · Security engineeringSenior security oversight for device and health-software companies, without a full-time CISO.
From £2,000 per month
View service →Dates that matter
Devices placed on the market before 28 May 2026 and still being sold must be registered in EUDAMED’s UDI/Device module.
What it means for you → 2 Feb 202621 CFR Part 820 now incorporates ISO 13485 by reference. US-bound manufacturers need a QMSR delta, not a second QMS.
What it means for you → 2 Aug 2028High-risk obligations for AI in products covered by sectoral legislation, including medical devices, apply from this date (AI Digital Omnibus).
What it means for you →How an engagement works
A free 30-minute call to understand your product, markets and deadline.
A fixed-fee proposal within two working days: deliverables, exclusions, timeline and price.
We do the work with your team, not around it. Everything is written for you to own.
We stay with you through audits, submissions and reviewer questions on anything we wrote.
Leadership
You work directly with the people doing the work. No junior hand-offs.
Director
ISO/IEC 27001:2022 Lead Auditor with a security-first background in Azure cloud architecture, identity and access management, and release and risk governance in regulated environments. The technical foundation behind MD QMS Apex.
Full profile →
Senior Compliance Consultant
Regulatory compliance specialist in GMP, ISO 13485, ISO 14971, MDR, EUDAMED and FDA 21 CFR Part 820. Has built quality systems from the ground up and led ISO certification programmes. The regulatory foundation behind MD QMS Assure.
Full profile →Insights
Selling into the EU?
A Romania-based, EUDAMED-registered EU importer, with an EU Authorised Representative service in development. Your QMS, your security file and your EU economic-operator roles, from one group, with the roles kept separate.
Book a free 30-minute discovery call. We’ll understand your product and deadline, and tell you exactly what an engagement would involve and cost. No obligation.
Regulatory radar
FDA, MDR, EUDAMED, the AI Act and medical-device cybersecurity: what changed and what it means for your product. Low volume; unsubscribe any time.