Skip to main content
QMSQMS
QMS
  • Welcome to your QMS
  • Quality Manual
  • Procedures
  • Records
    • GP-001 Documents and records control
      • Deprecated
      • R-001-001 Control of documents
      • R-001-002 Manufacturer declaration of conformity for Brazil
      • R-001-002 Manufacturer declaration of conformity
      • R-001-005 List of applicable standards and regulations
      • R-001-008 Legit.Health Plus label for Brazil
      • R-001-009 Training on procedures of the QMS
      • R-001-009 Training on procedures of the QMS
      • R-001-009 Training on procedures of the QMS
      • R-001-009 Training on procedures of the QMS
      • R-001-009 Training on procedures of the QMS
    • GP-002 Quality planning
    • GP-003 Audits
    • GP-004 Vigilance system
    • GP-005 HR and training
    • GP-007 Post-market surveillance
    • GP-009 Sales
    • GP-010 Suppliers
    • GP-012 Design, Redesign and Development
    • GP-018 Infrastructure and facilities
    • GP-019 Software validation
    • GP-023 Change control management
    • GP-050 Data Protection
    • GP-051 Security violations
    • GP-052 Data Privacy Impact Assessment (DPIA)
    • GP-200 Remote Data Acquisition in Clinical Investigations
    • GP-011 Provision of service
    • GP-110 Esquema Nacional de Seguridad
  • Legit.Health Plus Version 1.1.0.0
  • Legit.Health Plus Version 1.1.0.1
  • Licenses and accreditations
  • Applicable Standards and Regulations
  • Grants
  • Pricing
  • Public tenders
  • Records
  • GP-001 Documents and records control
  • R-001-005 List of applicable standards and regulations

R-001-005 List of applicable standards and regulations

Introduction​

In accordance with Regulation (EU) 2017/745 (MDR), especially Annex II (Technical Documentation), Annex IX (Conformity Assessment), and Article 10(9), the manufacturer must maintain an up-to-date list of all applicable standards, regulations, and guidance documents relevant to the product and the QMS. This list is compiled at the QMS and reviewed at least annually and whenever necessary (e.g., when new or revised standards are published, or regulatory requirements change). Documents are organized in folders according to topic or country.

The following tables provide a comprehensive overview of all applicable standards and regulations stored in the QMS, as required by MDR Annex II, Section 4 and Annex IX, Section 2.3. Each table corresponds to a specific folder or regulatory domain.

Spanish Regulations​

CodeNameSourceVersionDateCompliance
02_01Instrucción PS1/2022 sobre el procedimiento de licencia previa de funcionamiento de instalaciones de productos sanitariosAEMPSPS 1/20222022-04-01Full (applicable requirements according to the type of product)
02_02CERTPS-ManualEmpresa: Certificado de libre ventaAEMPS2.12023-11-21Full (applicable requirements according to the type of product)
02_03R_DEX_18_Guía para la elaboración de la documentación técnica: Marcado CE MDRCNCPS32024-12-01Full (applicable requirements according to the type of product)
02_04Real Decreto 192/2023 por el que se regulan los productos sanitarios_7416BOENot specified2023-03-21Full (applicable requirements according to the type of product)
02_05Real Decreto 1907/1996 sobre publicidad y promoción comercial de productos, actividades o servicios con pretendida finalidad sanitariaBOENot specified1996-08-06Full (applicable requirements according to the type of product)
02_06Real Decreto 1591/2009 por el que se regulan los productos sanitariosBOENot specified2009-11-06Full (applicable requirements according to the type of product)
02_07Real Decreto 1090/2015 por el que se regulan los ensayos clínicos con medicamentos, los Comités de Ética de la Investigación con medicamentos y el Registro Español de EstudioClínicosBOENot specified2015-12-24Full (applicable requirements according to the type of product)
02_08Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD)BOE3/20182018-12-06Full (aplicable a datos personales tratados en el marco de productos sanitarios)
02_09Esquema Nacional de Seguridad (ENS) - Real Decreto 311/2022BOE311/20222022-05-03Parcial (aplicable a sistemas de información en el sector público y a proveedores de servicios tecnológicos)

US Code of Federal Regulations (CFR - Title 21) and HIPAA​

CodeNameSourceVersionDateCompliance
03_01Part 11 — Electronic Records; Electronic Signatures — Rules on the validity of electronic records and electronic signatures.FDANot specified20230602Partial
03_02Part 801 — Labeling — Requirements for the content, format and placement of labeling.FDANot specifiedNot specifiedPartial
03_03Part 803 — Medical Device Reporting (MDR) — Obligation to report deaths, serious injuries and malfunctions.FDANot specifiedNot specifiedPartial
03_04Part 806 — Reports of Corrections and Removals — Obligation to report market corrections and removals.FDANot specifiedNot specifiedPartial
03_05Part 807 — Establishment Registration and Device Listing — Requirements to register the establishment and list the device. Includes the 510(k) notification (Subpart E).FDANot specifiedNot specifiedPartial
03_06Part 812 — Investigational Device Exemptions (IDE) — Requirements for clinical investigations.FDANot specifiedNot specifiedPartial
03_07Part 820 — Quality System Regulation (QSR) / QMSR — Quality Management System (QMS) requirements for design, manufacturing, packaging, etc.FDANot specified20230927Full (applicable requirements according to the type of product)
03_08Part 822 — Postmarket Surveillance — Requirements for postmarket surveillance studies (Section 522), if required.FDANot specifiedNot specifiedPartial
03_09Part 860 — Medical Device Classification Procedures — Procedures to classify or reclassify devices.FDANot specifiedNot specifiedPartial
03_10Parts 862-892 — Classification Panels — Specialty-based classification list. Used to find product code and predicate for 510(k).FDANot specifiedNot specifiedPartial
03_11Health Insurance Portability and Accountability Act (HIPAA) — US law for data privacy and security provisions for safeguarding medical information.HHSNot specified1996-08-21Full (applies to protected health information in the US)

EU Medical device Regulations and GDPR​

CodeNameSourceVersionDateCompliance
04_01Directive 93/42/EEC concerning medical devicesEuropean CommissionM52007-10-11Full (applicable requirements according to the type of product for the Legacy Device)
04_02Regulation 2017/745 on medical devicesEuropean CommissionM12020-04-24Full (applicable requirements according to the type of product)
04_03Regulation 2017/2185 related to codes and medical devicesEuropean Commission2017-11-24Partial
04_04Regulation 2023/607 amending Regulations (EU) 2017/745 and (EU) 2017/746 as regards the transitional provisionsEuropean Commission2023-03-20Full (applicable requirements according to the type of product for the Legacy Device)
04_05Commission regulation 2021/2226 on electronic instructions for use of medical devicesEuropean Commission2021-12-14Full (applicable requirements according to the type of product)
04_06Regulation (EU) 2024/1689 - Artificial Intelligence ActEuropean Commission2024-07-12Partial
04_07Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) — EU law on data protection and privacy.European Parliament and Council2016/6792016-04-27Full (applies to personal data processing in the EU)

Guides​

There are both European (MDCG, MedDev) and US (FDA) guidelines applicable to medical device software, including those with AI and cybersecurity, especially for Class II devices. Below are the main guideline categories consulted during the preparation of medical device documentation.

EU Guidelines​

CodeNameSourceVersionDateCompliance
05_01Manual on borderline and classification in the community regulatory framework for medical devices1.222019-05-01Partial
05_02Additional guidance regarding the vigilance system as outlined in MEDDEV 2.12-1 rev.8European Commission82018-11-04Partial
05_03MDCG 2020-5 Clinical evaluation - EquivanceMDCG02020-04-01Partial
05_04MDCG 2020-7 PMCF plan templateMDCG02020-04-01Partial
05_05MDCG-2020-8 PMCF evaluation report templateMDCG02020-04-01Partial
05_06MDCG-2020-1 Guidance con clinical evaluation of MD softwareMDCG02020-03-01Partial
05_07MDCG 2022-4 Guidance on appropriate surveillance regarding the transitional provisions under Article 120 of the MDR about devices covered by certificates according to the MDD or the AIMDDMDCG22024-05-01Full (applicable requirements according to the type of product)
05_08MDCG 2022-2021 Guidance on PSUR according to regulation (EU) 2017/745 MDRMDCG02022-12-01Partial
05_09MDCG 2023-3 Questions and answers on vigilance terms and concepts as outlined in the Regulation (EU) 2017/745 on medical devicesMDCG22025-01-01Full (applicable requirements according to the type of product)
05_10Meddev 2.1/6 Guidelines on the qualification and classification of stand-alone software used in healthcare within the regulatory framework of medical devicesEuropean Commission02016-07-01Partial
05_11Meddev 2.7/1 Guidelines on medical devicesEuropean Commission42016-06-01Partial
05_122023/C 163/06 Content and structure of the summary of the clinical investigation reportEuropean Commission2023-05-08Full (applicable requirements according to the type of product)
05_13MDCG 2020-3 Guidance on significant changes regarding the transitional provision under Article 120 of the MDR about devices covered by certificates according to MDD or AIMDDMDCG12023-05-01Partial
05_14Manual on borderline and classification for medical devices under Regulation (EU) 2017/745 on medical devices and Regulation (EU) 2017/746 on in vitro diagnostic medical devices32023-09-01Partial
05_15Principles and practices for medical device cybersecurityIMDRF2020-03-18Partial
05_16Machine Learning-enabled Medical Devices: Key Terms and DefinitionsIMDRF2022-05-06Full (applicable requirements according to the type of product)

US Guidelines​

CodeNameSourceVersionDateCompliance
05_17Software as a Medical Device (SaMD): Clinical EvaluationFDA/IMDRFIMDRF/SaMD WG/N41FINAL:20172017-12-21Full (applicable requirements according to the type of product)
05_18Guidance for the Content of Premarket Submissions for Software Contained in Medical DevicesFDAFDA-2019-D-55882021-11-04Full (applicable requirements according to the type of product)
05_19Artificial Intelligence and Machine Learning (AI/ML) Software as a Medical Device Action PlanFDAN/A2021-01Full (applicable requirements according to the type of product)
05_20Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket SubmissionsFDAFDA-2021-D-11582023-09-27Full (applicable requirements according to the type of product)
05_21General Principles of Software Validation; Final Guidance for Industry and FDA StaffFDAFDA-2008-D-00942002-01-11Full (applicable requirements according to the type of product)
05_22Deciding When to Submit a 510(k) for a Software Change to an Existing DeviceFDAFDA-2017-D-65692017-10-25Full (applicable requirements according to the type of product)
05_23Postmarket Management of Cybersecurity in Medical DevicesFDAFDA-2016-N-22612016-12-28Full (applicable requirements according to the type of product)
05_24Design Considerations and Pre-market Submission Recommendations for Interoperable Medical DevicesFDAFDA-2015-N-00012017-09-06Full (applicable requirements according to the type of product)
05_25Computer Software Assurance for Production and Quality System SoftwareFDAFDA-2022-D-07952022-09-13Full (applicable requirements according to the type of product)

Clinical Practice Guidelines (EU and US)​

CodeNameSourceVersionDateCompliance
05_26Guideline for good clinical practice E6 (R2) Step 5EMA/ICHE6 (R2)2017-06-14Partial

International Standards​

CodeNameSourceVersionDateHarmonized/Recognized (number)Compliance
06_01ISO 13485:2016 Medical devices. Quality management systems. Requirements for regulatory purposesISOE2016-03-01EU Harmonized: EN ISO 13485:2016 / FDA Recognized: Yes (No. 5-114)Establishes the requirements for a quality management system specific to medical devices. All QMS processes are aligned to ensure compliance with this standard.
06_02IEC 62304:2006/A1:2015 Medical device software - Software life cycle processesAENOR2015-06-01EU Harmonized: EN ISO 62304:2006/A1:2015 / FDA Recognized: Yes (No. 13-79)Defines the life cycle requirements for medical device software. Applied to all software development and maintenance activities for our products.
06_03IEC 82304-1:2016 Health software - Part 1: General requirements for product safetyIEC12016-10-01EU Harmonized: EN IEC 82304-1:2021 / FDA Recognized: Yes (No. 13-135)Specifies safety and security requirements for health software products. Considered in the design and technical documentation of all health software.
06_04ISO 14155 Investigación clínica de productos sanitarios para humanos. Buenas prácticas clínicasUNE2020EU Harmonized: EN ISO 14155:2020 / FDA Recognized: Yes (No. 2-156)Provides requirements for the design, conduct, recording, and reporting of clinical investigations. Applied to all clinical investigations involving our devices.
06_05ISO14971:2019 Medical devices - Application of risk management to medical devicesISO2019-12-01EU Harmonized: EN ISO 14971:2019 / FDA Recognized: Yes (No. 5-117)Establishes a process for risk management for medical devices. All risk management activities are performed in accordance with this standard.
06_06ISO15223-1:2021 Medical devices - Symbols to be used with medical device labels, labelling and information to be suppliedISO2021-07-01EU Harmonized: EN ISO 15223-1:2021 / FDA Recognized: Yes (No. 5-120)Specifies symbols for use in medical device labeling. All labeling and IFU are reviewed for compliance with this standard.
06_07ISO24791 Medical devices - Guidance on the application of ISO14971ISO22020-06EU Harmonized: EN ISO 24791:2020 / FDA Recognized: NoProvides guidance on the application of ISO 14971 for risk management. Used as a reference to ensure best practices in risk management.
06_08ISO62366-1:2015/A1:2020 Medical devices - Part 1: Application of usability engineering to medical devicesAENOR2020-08-01EU Harmonized: EN ISO 62366-1:2015/A1:2020 / FDA Recognized: Yes (No. 5-119)Specifies usability engineering requirements to ensure safe use of medical devices. Usability is addressed in product design and documentation.
06_09ISO27001 Tecnología de la información. Técnicas de seguridad. Sistemas de gestión de la seguridad de la información. RequisitosUNE2017-02-01EU Harmonized: EN ISO 27001:2017 / FDA Recognized: NoProvides requirements for an information security management system. Considered for the protection of information in our QMS and IT systems.
06_10ISO27002 Tecnología de la información. Técnicas de seguridad. Código de prácticas para los controles de seguridad de la informaciónAENOR/MINCOTUR2017-05-01EU Harmonized: EN ISO 27002:2017 / FDA Recognized: NoOffers guidelines for organizational information security standards and practices. Used as a reference for IT security controls.
06_11Good machine learning practice for MD development: guiding principlesFDA, Health Canada / Medicines & Healthcare products regulatory agency2021-10-01IMDRF: GMLP / FDA Recognized: No / EU Harmonized: NoProvides guiding principles for the development of machine learning-enabled medical devices. Used to inform development and validation of AI/ML components.
06_12Proposed regulatory framework for modifications to AI/ML-based SaMDFDA2019-04-02FDA Recognized: No / EU Harmonized: NoOutlines a regulatory approach for modifications to AI/ML-based software as a medical device. Used as reference for regulatory strategy.
06_13IEC 81001-5-1:2021 Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycleIEC12021-12-01EU Harmonized: EN IEC 81001-5-1:2021 / FDA Recognized: NoSpecifies requirements for cybersecurity activities throughout the product life cycle of health software and IT systems. Applied to ensure security in product development and maintenance.

Signature meaning

The signatures for the approval process of this document can be found in the verified commits at the repository for the QMS. As a reference, the team members who are expected to participate in this document and their roles in the approval process, as defined in Annex I Responsibility Matrix of the GP-001, are:

  • Author: Team members involved
  • Reviewer: JD-003, JD-004
  • Approver: JD-001
Previous
R-001-002 Manufacturer declaration of conformity
Next
R-001-008 Legit.Health Plus label for Brazil
  • Introduction
  • Spanish Regulations
  • US Code of Federal Regulations (CFR - Title 21) and HIPAA
  • EU Medical device Regulations and GDPR
  • Guides
    • EU Guidelines
    • US Guidelines
    • Clinical Practice Guidelines (EU and US)
  • International Standards
All the information contained in this QMS is confidential. The recipient agrees not to transmit or reproduce the information, neither by himself nor by third parties, through whichever means, without obtaining the prior written permission of Legit.Health (AI LABS GROUP S.L.)