
What to Expect During Your First Pen Test
A founder's field guide to penetration testing, from a team that's run hundreds of them
Matt Jennings•Sep 08, 2026
What to Expect During Your First Pen TestThe quality management standard for medical device software
ISO 13485 is the internationally recognised quality management system (QMS) standard for medical devices. If you are building software as a medical device, it is the backbone of your route to a UKCA or CE mark, and the QMS that notified bodies and NHS buyers will expect to see. Assuric gives you a ready-to-use electronic QMS so you can build it properly the first time and keep it audit-ready.
Request a demoMedical Device Quality Management System
We are trusted by
We can assist you with all aspects of ISO 13485, including:
Manage your controlled documents, procedures and records in one place. Version control, review workflows and locked approved versions keep you audit-ready, without the folder sprawl and lost sign-offs.
Quality management system
ISO 13485Controlled, versioned and audit-ready
Key documents
Approval workflows, full version history and FDA 21 CFR Part 11 compliant e-signatures. Every document has a clear owner, a review date and an audit trail.
Approval workflow
Drafted
Risk management SOP v3
Reviewed
Quality lead
E-signed
21 CFR Part 11 compliant
Locked and published
Audit trail recorded
Run your medical device risk management alongside your QMS. Record hazards, causes and controls, and link them to your technical documentation so your risk file and your quality system stay in step.
Risk file
Hazards, causes and controls
Customisable procedures and policies written to pass audit, without the twenty-page design control documents you get elsewhere. Start from a sensible baseline and make it yours.
Generate Policy
Suggested
SOP Software Development Lifecycle
Define your approach to software development
SOP Clinical Evaluation
Define your approach to clinical evidence
Reuse controls and evidence across ISO 13485, ISO 27001, IEC 62304 and your clinical safety work. Do the work once and meet several requirements at the same time.
Evidence mapping
Access control policy
One control, evidenced once
ISO 13485
MetISO 27001
MetIEC 62304
MetDCB0129
MetMoving off a manual, audit-unfriendly tool? Bring your documents across with their version history and metadata intact, and pick up where you left off.
QMS migration
From your old tool
Preserved
Pick up exactly where you left off.
Manage internal audits, corrective actions and supplier records in one place, so you walk into your notified body audit prepared rather than scrambling.
Tasks summary
Notified body preparation
Work with our team for ad-hoc advice or hands-on help building your technical file and clinical evaluation. You are not left to work out the standard on your own.
Hi Rosie 👋
How can we help?
Send us a message
Ask about your technical file
ISO 13485 is the quality system the other standards plug into. Do the work once on Assuric and reuse it across all of them.
Your quality management system
Risk management for your device
Your software development lifecycle
Clinical safety for the NHS
Get in touch if we haven’t answered your question below, we are always happy to help!
ISO 13485 is the international standard for a quality management system (QMS) specific to medical devices. It sets out how you design, build, document and maintain a device to a consistent, safe and traceable standard. For medical device software it is the foundation most regulators and buyers expect to see.
It is not a legal requirement in its own right, but in practice it is close to essential. A notified or approved body will expect a compliant QMS before granting a UKCA or CE mark for anything above the lowest risk class, and NHS and enterprise buyers increasingly ask for it during procurement. Even for a Class I self-certified device, an ISO 13485 QMS is the cleanest way to evidence that you build safely.
ISO 9001 is a general quality management standard for any organisation. ISO 13485 is built on the same foundations but tailored to medical devices, with far more emphasis on regulatory requirements, risk management, traceability and documentation. If you make a medical device, ISO 13485 is the one that matters.
They work together. ISO 13485 is your overall quality system, ISO 14971 is how you manage risk, and IEC 62304 covers your software development lifecycle. Assuric lets you manage all three in one place and reuse evidence across them.
It depends on your product and where you are starting from, but the documentation is usually the bottleneck. Assuric shortens that part significantly with ready-to-use templates and a structured QMS, so most teams move faster than they expect. We also work with excellent notified and certification bodies, so when your documentation is ready your audit is with people we know and trust. Book a demo and we will give you a realistic timeline for your device.
Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.
Kelly Klifa
CEO at Heim
Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.
Katie Baker
Director UK & Ireland at Tandem
Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!
Maks Kozarzewski
COO at VitVio
We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!
Maja Mazur
CEO at Healthnix
Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!
Dean Mawson
Clinical Director at DPM
Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.

A founder's field guide to penetration testing, from a team that's run hundreds of them
Matt Jennings•Sep 08, 2026
What to Expect During Your First Pen Test
Learn what CQC compliance is, who needs to register, how CQC inspections work, what evidence you'll need, and how to prepare for registration and inspections.
Dr Johnny Andrews,Cordi Mahony•Jul 24, 2026
CQC Compliance Explained: the Clinical Governance EssentialsGoodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.
