Skip to main content
QMSQMS
QMS
  • Welcome to your QMS
  • Quality Manual
  • Procedures
  • Records
    • GP-001 Documents and records control
    • GP-002 Quality planning
    • GP-003 Audits
    • GP-004 Vigilance system
    • GP-005 HR and training
    • GP-007 Post-market surveillance
    • GP-009 Sales
    • GP-010 Suppliers
      • 🔍 Evidence
      • R-010-001 Suppliers evaluation
      • R-010-002 Approved Suppliers List
    • GP-011 Provision of service
    • GP-012 Design, Redesign and Development
    • GP-018 Infrastructure and facilities
    • GP-019 Non-product software validation
    • GP-023 Change control management
    • GP-031 Training Data Governance
    • GP-050 Data Protection
    • GP-051 Security violations
    • GP-052 Data Privacy Impact Assessment (DPIA)
    • GP-110 Esquema Nacional de Seguridad
    • GP-200 Remote Data Acquisition in Clinical Investigations
  • Legit.Health Plus Version 1.1.0.0
  • Legit.Health Plus Version 1.1.0.1
  • Legit.Health Utilities
  • Licenses and accreditations
  • Applicable Standards and Regulations
  • BSI Non-Conformities
  • Pricing
  • Public tenders
  • Records
  • GP-010 Suppliers
  • R-010-001 Suppliers evaluation

R-010-001 Suppliers evaluation

  • Governed by GP-010 Purchases and suppliers evaluation

Supplier verification​

The editable spreadsheet is here: https://docs.google.com/spreadsheets/d/1AKpRbAkVn3I-mxIFqwcx2FjB27jla2kTschyCZXjeQk/edit?usp=sharing

#CodeProvider NameTypeScoreRequired scoreApprove
1S-AMAAmazon Web Services, IncControlled Impact Vendor (CIV)138TRUE
2S-ATLAtlassian CorporationControlled Impact Vendor (CIV)118TRUE
3S-GOOGoogle LLCNon-Impact Vendor (NIV)126TRUE
4S-PSCPS ConsultingNon-Impact Vendor (NIV)86TRUE
5S-AUDAudensNon-Impact Vendor (NIV)86TRUE
6S-STRStripe, IncNon-Impact Vendor (NIV)126TRUE
7S-IDIiDISC Information Technologies, S.L.Non-Impact Vendor (NIV)136TRUE
8S-LAWLawesomeNon-Impact Vendor (NIV)86TRUE
9S-HUBHubSpot, Inc.Non-Impact Vendor (NIV)126TRUE
10S-HOLHolded TechnologiesNon-Impact Vendor (NIV)96TRUE
11S-FACFactorialNon-Impact Vendor (NIV)116TRUE
12S-SLASlack Technologies, Salesforce IncNon-Impact Vendor (NIV)126TRUE
13S-APOApotech ConsultingNon-Impact Vendor (NIV)106TRUE
14S-BSIBSINon-Impact Vendor (NIV)106TRUE
15S-MICMicrosoftControlled Impact Vendor (CIV)138TRUE
16S-GLAGL AI INVESTMENTControlled Impact Vendor (CIV)108TRUE
17S-DOCDocker, Inc.Controlled Impact Vendor (CIV)128TRUE
18S-CMGCMG MedDevNon-Impact Vendor (NIV)86TRUE
19S-DMEDmed softwareControlled Impact Vendor (CIV)118TRUE
20S-DESDesign scienceControlled Impact Vendor (CIV)108TRUE
21S-BRABrazil Import Healthcare SolutionsNon-Impact Vendor (NIV)106TRUE

Security evaluation for IT suppliers (ENS op.pl.3, op.ext.2/3)​

The following IT suppliers undergo an annual security evaluation as required by ENS. Evaluation date: 2026-02-26. Scoring criteria are defined in GP-010 section 5c (5 criteria, 1-3 points each, threshold >=12/15).

#CodeProvider NameSecurity ScoreRequiredApprovedCertificationsRSEG Approval
1S-AMAAmazon Web Services, Inc1512TRUEENS ALTA, ISO 27001, SOC 2 Type IIRequired
2S-ATLAtlassian Corporation1212TRUEISO 27001, SOC 2—
3S-GOOGoogle LLC1412TRUEISO 27001, SOC 2 Type II—
12S-SLASlack Technologies, Salesforce Inc1412TRUEISO 27001, SOC 2—
15S-MICMicrosoft1312TRUEISO 27001, SOC 2 Type IIRequired

S-AMA​

  • Name: Amazon Web Services, Inc
  • Service/Product provided: Cloud services
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 13
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration71Prior experience with this supplier shows a high degree of quality of the supplier. However, the supplier has a poor rating on Trustpilot. Still, AWS is the leading cloud supplier worldwide and its trusted by the majority of the consumers.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The presence of a certificated quality manage system is evidenced in the supplier's website and also in the constract of license of use in force between.
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The vendor provided an ISO 27001 certificate, that is attached as evidence to this record as S-AMA-ISMS Certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy92It's quite afforable by all standards, plus they offer un free credits for being an innovative startup
Technical capacityCapability to provide the services82They have a wide range of services, including elastic balancing, as well as instances for different processing activities.
ExperienceKnowledge and domain on their activity102They practically invented modern cloud infrastructure services.
InternationalPresence in the whole world102They operate in all continents.

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Proactive communication via AWS Health Dashboard; detailed post-incident analyses published for major events
Contractual compliance3Full SLA compliance throughout our relationship; no breaches observed in eu-west-1 services
Technical expertise3Industry leader; proactive security recommendations via AWS Trusted Advisor and Security Hub
Security issues3No security incidents affecting our organization; holds ENS ALTA certification, ISO 27001, SOC 2 Type II
Service availability3Availability consistently exceeds the 99.99% SLA commitment for our services in eu-west-1
  • Security score: 15/15 — Approved
  • Certifications: ENS ALTA, ISO 27001, SOC 2 Type II
  • RSEG approval: Required and granted — infrastructure provider classified as high-risk component

S-ATL​

  • Name: Atlassian corporate
  • Service/Product provided: Project management software, code collaboration software
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 11
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration51Prior experience with this supplier shows a high degree of quality of the supplier. However, the supplier has a very bad rating on Trustpilot. Still, Atlassian is of the major project management softwares.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 27001 certification that is attached as evidence to this record as S-ATL-ISMS Certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy102We are using the free version and it's enough. When scaling to the paid version, it is still affordable.
Technical capacityCapability to provide the services102Atlassian is the only one providing, in the same ecosystem, a task manager, a knowledgebase and a git code repository. This makes it perfect to manage all the lifecycle: requirements (in Confluence), activities (in Jira) and deliverables (in Bitbucket).
ExperienceKnowledge and domain on their activity102The supplier is a long-lived company, one of the most in this space.
InternationalPresence in the whole world102The supplier operates in all continents.

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate response times; status page provides updates during incidents
Contractual compliance2Generally compliant; occasional notification delays during degraded service periods
Technical expertise3Expert-level project management and collaboration tools with comprehensive security features (Atlassian Guard)
Security issues2Historical service disruptions documented publicly; current track record is clean; holds ISO 27001 and SOC 2
Service availability3Recent availability has been consistent, meeting or exceeding SLA commitments
  • Security score: 12/15 — Approved (meets threshold)
  • Certifications: ISO 27001, SOC 2

S-GOO​

  • Name: Google LLC
  • Service/Product provided: Google Workspace
  • Type: Non-Impact Vendor (NIV)
  • Final score: 12
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration71Prior experience with this supplier shows a high degree of quality of the supplier. The supplier has an average rating on Trustpilot. It is a well-established company and its trusted by the majority of the consumers.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2Google Cloud Platform is certified as ISO 9001 compliant after undergoing an audit by an independent third party.
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy71It's not expensive and it includes services that, if hired separately from different companies, would add up to triple the price.
Technical capacityCapability to provide the services82The supplier has a wide range of services.
ExperienceKnowledge and domain on their activity102Well-established company with a significant number of years of experience.
InternationalPresence in the whole world102The supplier operates worldwide.

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Fast communication via Google Workspace Status Dashboard and admin console alerts; responsive support for Workspace customers
Contractual compliance3Full SLA compliance; no breaches observed for our Workspace subscription
Technical expertise3Expert-level platform with comprehensive security admin controls, DLP, and audit logging
Security issues3No security incidents affecting our organization; holds ISO 27001, SOC 2 Type II
Service availability2Meets the 99.9% SLA commitment; occasional brief service degradations observed in Gmail and Drive, all within SLA
  • Security score: 14/15 — Approved
  • Certifications: ISO 27001, SOC 2 Type II

S-PSC​

  • Name: PS Consulting
  • Service/Product provided: Regulatory and Quality services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 8
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The supplier does not have reviews in Trustpilot, but the reviews from companies we know were good. The supplier does not have a huge market penetration, which is expected.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have an ISO 13485 certification; however, the supplier implemented a quality management system compliant with ISO 13485.
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy61It's not expensive and it includes services that, if hired from different companies, would increase the price.
Technical capacityCapability to provide the services82The supplier has employees with the technical capacities required to provide the services.
ExperienceKnowledge and domain on their activity92They have demonstrated the required knowledge and experience to provide the services
InternationalPresence in the whole world51The supplier operates in Spain only, but they provide services for the European CE Marking

S-AUD​

  • Name: Audens
  • Service/Product provided: Legal services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 8
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The supplier does not have reviews in Trustpilot, but the reviews from companies we know were good. The supplier does not have a huge market penetration, which is expected.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy61It's not expensive and it includes services that, if hired separately from different companies, would increase the price.
Technical capacityCapability to provide the services82The supplier has significant experience in the field.
ExperienceKnowledge and domain on their activity92The supplier is specialised in new technologies, both for GDPR and also other contractual matters.
InternationalPresence in the whole world51The supplier operates in Spain only, but most of it applies to the whole EU.

S-STR​

  • Name: Stripe, Inc
  • Service/Product provided: Financial services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 12
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The supplier has an average score in Trustpilot, plus the reviews from companies we know were good. The supplier has a strong market penetration.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an equivalent to ISO 27001 certification, called Payment Card Industry (PCI) Data Security Standard.
Affordable priceCompared to competitors and considering special discounts we may enjoy82It's one of the most afforable solutions, much more than Paypal.
Technical capacityCapability to provide the services82The supplier has a wide range of services, including the possibility to allow care providers to charge patients through us.
ExperienceKnowledge and domain on their activity92The supplier is specialised in the field and has years of experience.
InternationalPresence in the whole world102The supplier is the payment processor with the largest geographic coverage.

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Excellent incident communication via status.stripe.com; responsive developer support
Contractual compliance3Full SLA compliance; consistent service delivery
Technical expertise3Industry-leading payment platform with proactive security features (Radar for fraud detection, real-time webhook notifications)
Security issues3No security incidents affecting our organization; PCI DSS Level 1 certified, SOC 2 Type II
Service availability3Consistently exceeds SLA availability targets
  • Security score: 15/15 — Approved
  • Certifications: PCI DSS Level 1, SOC 2 Type II

S-IDI​

  • Name: iDISC Information Technologies, S.L.
  • Service/Product provided: Translation services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 13
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. They don't have reviews in Trustpilot, but the reviews from companies we know were good. The supplier exhibits significant market penetration, as evidenced by its headquarters in Spain, the USA, and Brazil.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 9001 certification. Other relevant certifications for the services provided: ISO 17100 (Translation services) certiifcation, ISO 18587 (Translation services - Post-editing of machine translation output) certification.
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy61Good standard prices for the services provided.
Technical capacityCapability to provide the services82The supplier has a wide range of services. In addition to translation, the supplier offers comprehensive services in writing, proofreading, content management, subtitling, dubbing, interpreting (both in-person and online), voice-over, multilingual DTP and SEO optimization of translations.
ExperienceKnowledge and domain on their activity92The supplier has highly qualified translators who are fluent in both the source and target languages.
InternationalPresence in the whole world82The supplier offers translation in more than 56 languages; the supplier has headquarters in Spain, in USA and Brazil.

S-LAW​

  • Name: Lawesome
  • Service/Product provided: Legal services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 8
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The supplier does not have reviews in Trustpilot, but the reviews from companies we know were good. The supplie does not have a huge market penetration, which is expected.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy71The supplier counts with experts in big companies and startups and applies a special price for small companies and comparing the expertise and quality they're one of the most afforable solutions.
Technical capacityCapability to provide the services82The supplier has a wide range of services, including financing rounds consultancy, corporate venturing, protection and explotation of innovation.
ExperienceKnowledge and domain on their activity82The supplier is specialised in the field and have years of experience.
InternationalPresence in the whole world51The supplier operates in Spain only, but most of it applies to the whole EU.

S-HUB​

  • Name: HubSpot, Inc
  • Service/Product provided: Customer Relationship Management software
  • Type: Non-Impact Vendor (NIV)
  • Final score: 12
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration92Prior experience with this supplier shows a high degree of quality of the supplier. The supplier is rated above the media in Trustpilot and our experience working with it is satisfactory. They have a huge market penetration
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier does not have ISO 27001 certification, but they are SOC-2 certified, that is the equivalent in the US. The SOC-3 public report of internal controls over security, availability, processing integrity, and confidentiality is archived as evidence.
Affordable priceCompared to competitors and considering special discounts we may enjoy82We are using the free version and it's enough. When scaling to the paid version, it is still affordable.
Technical capacityCapability to provide the services82The supplier connects everything scaling companies need to deliver a best-in-class customer experience into one place.
ExperienceKnowledge and domain on their activity92The supplier has more than 15 years of experience
InternationalPresence in the whole world102The supplier operates worldwide.

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate response via ticket-based support and status page
Contractual compliance3Full SLA compliance
Technical expertise3Comprehensive CRM platform with role-based access control and audit logging
Security issues3No security incidents affecting our organization; SOC 2 Type II certified
Service availability3Consistently available, exceeding SLA commitments
  • Security score: 14/15 — Approved
  • Certifications: SOC 2 Type II

S-HOL​

  • Name: Holded Technologies
  • Service/Product provided: Software for invoicing and accounting
  • Type: Non-Impact Vendor (NIV)
  • Final score: 9
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The don't have reviews in Trustpilot, but the reviews from companies we know were good. The supplier is increasing is market penetration.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82Best solution for startups and it is one of the most afforable.
Technical capacityCapability to provide the services82The solution the supplier offers allows us automating tasks and streamlining our accounting and invoicing
ExperienceKnowledge and domain on their activity71The supplier has more than 5 years of experience helping SMEs being more efficient and having more information about their businesses to make better decisions.
InternationalPresence in the whole world102The supplier operates worldwide

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate ticket-based support; smaller platform with less formal incident communication
Contractual compliance2Generally compliant; occasional minor delays during maintenance windows
Technical expertise2Adequate invoicing and accounting platform with standard security controls
Security issues3No security incidents affecting our organization
Service availability3Service availability has been consistent and meets contractual expectations
  • Security score: 12/15 — Approved (meets threshold)
  • Certifications: None — INCIBE security questionnaire sent per GP-010 section 5c

S-FAC​

  • Name: Factorial
  • Service/Product provided: Human Resources management software
  • Type: Non-Impact Vendor (NIV)
  • Final score: 11
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration92Prior experience with this supplier shows a high degree of quality of the supplier. The supplier is rated above the media in Trustpilot and our experience working with it is satisfactory. The supplier has a strong market penetration.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy71Best solution for startups and it's one of the most afforable.
Technical capacityCapability to provide the services82In addition to automating processes, Factorial provide us with data with which to grow our company's talent.
ExperienceKnowledge and domain on their activity82More than 5 years of experience
InternationalPresence in the whole world92The supplier operates in more than 12 countries

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate ticket-based support; status page available
Contractual compliance3Full compliance with subscription terms
Technical expertise3Comprehensive HR platform with role-based access control and GDPR-compliant data handling
Security issues3No security incidents affecting our organization; ISO 27001 certified
Service availability2Meets SLA; occasional performance degradations observed during peak periods
  • Security score: 13/15 — Approved
  • Certifications: ISO 27001

S-SLA​

  • Name: Slack Technologies, Salesforce Inc
  • Service/Product provided: Cloud-based team communication platform
  • Type: Non-Impact Vendor (NIV)
  • Final score: 12
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration92Prior experience with this supplier shows a high degree of quality of the supplier. The supplier has a good rating onTrustpilot, and the reviews from companies we know were good. The supplier has a huge market penetration.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82We are using the free version and it's enough. When scaling to the paid version, it is still affordable.
Technical capacityCapability to provide the services92It offers a wide range of features and benefits that are useful for us as real-time messaging, channels to organize conversations based on projects, teams or departments, integration with a wide range of other tools, search functionality and mobile access.
ExperienceKnowledge and domain on their activity92The supplier demonstrated to have the required knowledge and experience to provide the services
InternationalPresence in the whole world102The supplier operates worldwide

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Good incident communication via status.slack.com and in-app notifications
Contractual compliance3Full SLA compliance
Technical expertise3Enterprise-grade messaging platform with comprehensive security features (Enterprise Key Management, DLP integrations)
Security issues3No security incidents affecting our organization; ISO 27001 and SOC 2 certified
Service availability2Meets SLA; occasional brief degraded performance observed
  • Security score: 14/15 — Approved
  • Certifications: ISO 27001, SOC 2

S-APO​

  • Name: Apotech Consulting
  • Service/Product provided: Regulatory services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 10
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The don't have reviews in Trustpilot, but our experience working with them was good. The supplier shows an increasing market penetration.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82The supplier offers an international portfolio of consultancy, in some cases cheaper than their equivalences with other suppliers, in other cases more expensive.
Technical capacityCapability to provide the services92The supplier demonstrated their capability of providing us with the high-quality services.
ExperienceKnowledge and domain on their activity92The supplier counts with a big amount of consultants with demonstrate experience on the different consultancy projects they offer.
InternationalPresence in the whole world92The supplier is UK-based, however offers services around the world, as Mexico and USA.

S-BSI​

  • Name: BSI
  • Service/Product provided: Notified Body services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 10
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Despite the supplier has a poor rating on Trustpilot, it is worldwide recognized. They have a huge market penetration and we are satisfied with the services
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0They do not have ISO 13485 certification
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has ISO 27001 certifaction
Affordable priceCompared to competitors and considering special discounts we may enjoy40The price is the most expensive in comparison with their competitors, but they offer faster terms.
Technical capacityCapability to provide the services82The European Commission has notified that BSI, Notified Body number : 2797, has the technical capacity to provide the services that we require.
ExperienceKnowledge and domain on their activity102The supplier is accredited by different international bodies as: American National Standards Institute - American Society for Quality National Accreditation Board LLC (ANAB); China National Accreditation Service for Conformity Assessment (CNAS); Raad voor Accreditatie (RvA) in the Netherlands; United Kingdom Accreditation Service (UKAS).
InternationalPresence in the whole world92The supplier is recognized as Notified Body worldwide

S-MIC​

  • Name: Microsoft
  • Service/Product provided: Code repository
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 13
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration61We do not have previous experience with this supplier yet. Despite the supplier has a poor rating on Trustpilot, it is worldwide recognized. The supplier has a huge market penetration
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has ISO 9001 certification
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has ISO 27001 and ISO 27018 certifications, and the supplier is SOC 1, SOC 2 and SOC 3 compliant
Affordable priceCompared to competitors and considering special discounts we may enjoy92We are using the free version and it's enough. When scaling to the paid version, we will review this section.
Technical capacityCapability to provide the services92Microsoft GitHub is the only one providing a git code repository that includes a verified signature choice for the commits performed compliant with the 21 CFR part 11. This makes it perfect to manage the QMS documents and records.
ExperienceKnowledge and domain on their activity102The supplier is a well-established company in the field
InternationalPresence in the whole world92The supplier operates worldwide

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Proactive incident communication via githubstatus.com; detailed post-incident reports
Contractual compliance3Full SLA compliance for GitHub services
Technical expertise3Industry-leading code hosting and CI/CD platform with comprehensive security features (Dependabot, code scanning, secret scanning)
Security issues2Occasional supply chain security incidents reported in the npm ecosystem (public disclosures); GitHub platform itself maintains strong security posture; ISO 27001 and SOC 2 certified
Service availability2Meets SLA; occasional degraded performance in GitHub Actions observed
  • Security score: 13/15 — Approved
  • Certifications: ISO 27001, ISO 27018, SOC 1, SOC 2, SOC 3
  • RSEG approval: Required and granted — code repository containing all source code classified as high-risk component

S-GLA​

  • Name: GL AI INVESTMENT
  • Service/Product provided: Servers
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 10
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration71We do not have previous experience with this supplier yet, however the references we got from very reliable sources are very encouraging.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2It is subjected to external audits and evaluations of third parties in accordance with international quality management regulations (ISO9001, ISO17025, 17065, EFQM) and customer audits periodically.
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0We could not find ISO 27001 certification or equivalent.
Affordable priceCompared to competitors and considering special discounts we may enjoy92We have closed a long-term contract, with a lower price than other providers such as AWS for better service (more computing capacity).
Technical capacityCapability to provide the services82The supplier provide sservers dedicated exclusively to us with plenty of power, plus dedicated support staff.
ExperienceKnowledge and domain on their activity82They are suppliers of Skymedic, an aesthetic medicine company, providing them the same services that we have contracted.
InternationalPresence in the whole world61The supplier does not have international presence yet, but their supplier Leitat also colaborates with the worldwide recognized company HP

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution3Direct and immediate communication as related entity; issues escalated without delay
Contractual compliance3Full compliance under intercompany service agreement
Technical expertise2Adequate server management and infrastructure capabilities for dedicated hosting
Security issues3No security incidents affecting our services; servers dedicated exclusively to our organization
Service availability2Meets contractual expectations; occasional planned maintenance windows
  • Security score: 13/15 — Approved
  • Certifications: None — INCIBE security questionnaire sent per GP-010 section 5c
  • RSEG approval: Required and granted — infrastructure provider classified as high-risk component

S-DOC​

  • Name: Docker, Inc
  • Service/Product provided: Platform-as-a-service (PaaS) products
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 12
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82The references we got from very reliable sources are very encouraging. We are satisfied with their services.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has ISO 27001 certification and SOC2. The supplier also complies with leading privacy regulations like GDPR, CCPA, CPA, CTDPA, VCDPA, UCPA, and the APEC Privacy Framework
Affordable priceCompared to competitors and considering special discounts we may enjoy102It is an open source
Technical capacityCapability to provide the services102Docker excels in containerization technology, offering a powerful Docker Engine and a cloud-based registry service, Docker Hub. It supports cross-platform compatibility and integrates seamlessly with orchestration tools like Kubernetes for high availability and scalability.
ExperienceKnowledge and domain on their activity92Established in 2013, it has a strong market presence and significantly influenced the containerization field, with wide adoption by major corporations. It boasts a large, active community and a history of continuous innovation.
InternationalPresence in the whole world102The supplier operates worldwide

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate incident communication via status.docker.com; community-driven support model
Contractual compliance3Full compliance with subscription terms and licensing
Technical expertise3Industry standard for containerization; comprehensive documentation and security scanning (Docker Scout)
Security issues2Occasional vulnerabilities reported in Docker Hub community images; Docker platform itself maintains security through regular patching; ISO 27001 and SOC 2 certified
Service availability3Docker Hub and Docker Desktop consistently available, exceeding SLA commitments
  • Security score: 13/15 — Approved
  • Certifications: ISO 27001, SOC 2

S-CMG​

  • Name: CMG MedDev
  • Service/Product provided: Regulatory and Quality services
  • Type: Non-Impact Vendor (NIV)
  • Final score: 8
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82Prior experience with this supplier shows a high degree of quality of the supplier. The don't have reviews in Trustpilot, but the reviews from companies we know were good. They don't have a huge market penetration, which is expected.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy71The pricing of the selected supplier is comparable to that of its competitors, yet remains the most economical option.
Technical capacityCapability to provide the services82The supplier's employees have relevant expertise required to provide the services.
ExperienceKnowledge and domain on their activity92The supplier demonstrated the required knowledge and experience to provide the services
InternationalPresence in the whole world51The supplier operates in Spain, although the supplier provides services to comply with FDA medical device regulation

S-DME​

  • Name: Dmed software
  • Service/Product provided: Cybersecurity testing
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 11
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82The supplier has been recommended to us because of the quality of its services. The supplier is present in Europe.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.TRUE2The supplier has an ISO 13485 certificate
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82The supplier has comparable prices The pricing of the selected supplier is comparable to that of its competitors, yet remains the most economical option.
Technical capacityCapability to provide the services82The supplier can count on knowledgeable personnel with extensive experience in cybersecurity topics for medical device requirements in Europe and USA.
ExperienceKnowledge and domain on their activity82The supplier has extensive experience in cybersecurity testing according to FDA requirements.
InternationalPresence in the whole world71The supplier is based in Europe, although the supplier provides services to comply with FDA medical device regulation

Security evaluation (ENS)​

CriterionScoreComments
Incident resolution2Adequate communication for project-based engagements; responsive to queries during testing periods
Contractual compliance3Full compliance with agreed testing scope, timelines, and deliverables
Technical expertise3Expert-level cybersecurity testing capabilities; DEKRA CASA Tier 3 certified methodology; specialized in medical device cybersecurity
Security issues2No direct security incidents; limited formal security certifications visible for the organization itself (no ISO 27001)
Service availability2Project-based delivery; meets agreed timelines and milestones
  • Security score: 12/15 — Approved (meets threshold)
  • Certifications: None — INCIBE security questionnaire sent per GP-010 section 5c

S-DES​

  • Name: Design science
  • Service/Product provided: Human factors testing
  • Type: Controlled Impact Vendor (CIV)
  • Final score: 10
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82The supplier has been recommended to us because of the quality of its services. The supplier is present in US and Europe (Germany).
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82The price of this supplier, compared to the price for the same service of other companies based in US, is affordable.
Technical capacityCapability to provide the services82The supplier can count on knowledgeable personnel with extensive experience in planning and conducting human factors testing according to FDA requirements.
ExperienceKnowledge and domain on their activity82The supplier has extensive experience in the human factors testing according to FDA requirements.
InternationalPresence in the whole world82The supplier has offices in US and in Europe (Germany).

S-BRA​

  • Name: Brazil Import Healthcare Solutions
  • Service/Product provided: Regulatory services in Brazil
  • Type: Non-Impact Vendor (NIV)
  • Final score: 10
CriteriaParametersValueScoreComments
Quality of servicesPrior experience with this supplier Customer reviews in Trustpilot.com Market penetration82One employee had prior experience with this supplier and reported a high degree of quality and satisfaction. There is not any review in Trustpilot, however, previous experience with this supplier was satisfactory. The supplier is specialised in the Brazilian market; however the supplier has headquarters in USA and UK and counts with 30 years of experience.
QMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have a QMS certification (ISO 9001 / ISO 13485)
ISMS CertificationObserved by looking at the supplier's claims and the mention of the QMS in the license of use.FALSE0The supplier does not have ISO 27001 certification.
Affordable priceCompared to competitors and considering special discounts we may enjoy82The supplier offers regulatory services with comparable costs to other competitors.
Technical capacityCapability to provide the services92The supplier has the adequate resources to provide us with the required regulatory services.
ExperienceKnowledge and domain on their activity92The supplier has 30 years experience in regulatory and quality matters and counts on speciaised consultants.
InternationalPresence in the whole world92The supplier is based in Brazil and their core business is the Brazilian market. The supplier has headquarters in USA and UK.

Record signature meaning​

  • Author: JD-004
  • Reviewer: JD-005
  • Approver: JD-001 ㅤ
Previous
S-THA
Next
R-010-002 Approved Suppliers List
  • Supplier verification
    • Security evaluation for IT suppliers (ENS op.pl.3, op.ext.2/3)
    • S-AMA
      • Security evaluation (ENS)
    • S-ATL
      • Security evaluation (ENS)
    • S-GOO
      • Security evaluation (ENS)
    • S-PSC
    • S-AUD
    • S-STR
      • Security evaluation (ENS)
    • S-IDI
    • S-LAW
    • S-HUB
      • Security evaluation (ENS)
    • S-HOL
      • Security evaluation (ENS)
    • S-FAC
      • Security evaluation (ENS)
    • S-SLA
      • Security evaluation (ENS)
    • S-APO
    • S-BSI
    • S-MIC
      • Security evaluation (ENS)
    • S-GLA
      • Security evaluation (ENS)
    • S-DOC
      • Security evaluation (ENS)
    • S-CMG
    • S-DME
      • Security evaluation (ENS)
    • S-DES
    • S-BRA
  • Record signature meaning
All the information contained in this QMS is confidential. The recipient agrees not to transmit or reproduce the information, neither by himself nor by third parties, through whichever means, without obtaining the prior written permission of Legit.Health (AI Labs Group S.L.)