How to Secure your Documents in Confluence?
This short post will provide you insight into taking control over your document management in Confluence Server. This post is not going to touch regular security policies like VPN, firewalls, security policies and ohter things that are outside of the Confluence Server. In other words, all the really technical things are left out and we […]
IEC 60601 – Essential Performance, Safety and Risk Management

Background IEC 60601 is a series of technical standards for the safety and essential performance of medical electrical equipment. Although if focuses primarily on electromechanical devices, it also applies to aspects of the software components. It is a widely recognized standard that most, if not all, medical device companies have to comply with. The concept […]
What is Software Tool Validation?
Modern medical device regulations are putting more and more emphasis on the management of software tools. These tools are software packages that are not part of the medical devices themselves, but support the device during its lifecycle. Nowadays companies use dozens of applications, ranging from accounting tools to email clients to software compilers. Of course […]
What is FMEA?
FMEA stands for Failure Modes and Effects Analysis, it is a step-by-step approach for identifying all possible failures in a design, a manufacturing or assembly process, or a product or service. From ISO 14971: “FMEA is a technique by which the consequences of an individual fault mode are systematically identified and evaluated. It is an […]
Hazard Analysis & FME(C)A on Jira – SoftComply Risk Manager PLUS is out now!
We are happy to inform you that our Risk Management solution for Jira has gotten an upgrade for Jira Server users – the SoftComply Risk Manager Plus focusing specifically on safety-critical product/device/system risks. SoftComply Risk Manager Plus supports both Hazard Analysis as well as FME(C)A, including FME(C)A with Detectability and RPN (Risk Prioritization Number). Although […]
The Importance of IEC 62304 Compliance Part 2
Following up on our first blog post on how to become a trusted software supplier to established medical device manufacturers with the help of IEC 62304, we will now shed some light on specific clauses and requirements of that standard. IEC 62304:2006/Amd 1:2015, 4.3 – Software Safety Classification The 2015 amendment provides more clarity on […]
Don’t be a ”victim” of your Quality System, but instead use it to achieve your objectives!
“If you can’t beat them, join them!” If your company has decided to enter the medical device market, and you are in charge of making this transition, one of the things you will have to implement sooner or later is a compliant quality system. It is not going to be an easy job, but on […]
What is Probability of Failure of Medical Device Software?

One of the more controversial requirements of IEC 62304 is the probability of failure of medical device software during Risk Analysis. EN 62304:2006 paragraph 4.3 “Software Safety Classification” states “If the HAZARD could arise from a failure of the SOFTWARE SYSTEM to behave as specified, the probability of such failure shall be assumed to be […]
Risk Management for JIRA. Why?
Compliant Risk Management is a mandatory regulatory requirement for companies in medical device and other safety-critical domains. It is a specific aspect of safety-critical system development that requires linking risks to system/software design and testing to ensure the system is safe to use. Various standalone solutions exist today for safety-critical system developers that help automate […]
FME(C)A or FMEA?
FMEA or FMECA? Criticality or not? Which one is better? Which one should you use? The answer is simple: it depends. You are probably fed up with the “it depends” answers you get in this sector. But in this case it means “It depends on YOU”. First the compliance bit: there is no requirement, in […]