SaMD (Software as a Medical Device)

Yoctobe Regulatory & Compliance Capability Document

1. Overview

Yoctobe Ltd. is a UK-based health technology company specialising in Software as a Medical Device (SaMD) engineering and Quality Management System (QMS) enablement.
Yoctobe develops compliant medical-grade software, provides an ISO-ready electronic Quality Management System (eQMS), and supports its clients throughout the entire product lifecycle — from concept to post-market surveillance.

Our infrastructure, procedures, and documentation are aligned with the requirements of the UK Medical Devices Regulations 2002 (as amended) and the relevant ISO and IEC standards governing SaMD and health software.

We help accelerate compliant innovation in digital healthcare by allowing manufacturers, clinical partners, and startups to bring safe and effective SaMD products to market efficiently — while maintaining full conformity with MHRA, ISO, and NHS Digital standards.

2. Scope of Services

Yoctobe delivers two main compliance streams:

2.1 SaMD Development

Yoctobe provides full lifecycle software engineering compliant with IEC 62304, covering:

  • Requirements analysis and risk classification
  • Software design, implementation, and verification
  • Usability and human factors engineering
  • Validation and clinical data integration
  • Technical file preparation and documentation

Yoctobe’s engineering practices are structured under a validated lifecycle model ensuring traceability from design input to verification and validation outputs.

2.2 SaMD QMS Provision and Maintenance

Yoctobe provides and maintains a cloud-based eQMS platform that is ISO-ready and pre-configured for medical device compliance.
It includes:

  • ISO 13485 structure and documentation templates
  • Risk management per ISO 14971
  • Software lifecycle management per IEC 62304
  • Usability documentation per IEC 62366
  • Audit trails, training management, and CAPA records
  • Validation report and tool qualification evidence

Each client organisation using the eQMS assumes the role of Legal Manufacturer under MHRA regulations and remains responsible for ISO 13485 certification.
Yoctobe, as the QMS provider and maintainer, ensures the platform remains validated, up to date with regulatory changes, and technically secure.

3. Roles and Responsibilities

DomainYoctobe ResponsibilityClient / Manufacturer Responsibility
Software DevelopmentFull SaMD design, coding, verification, validationCreate and maintain risk log, hazard analysis, and traceability
Quality ManagementProvide, configure, and maintain ISO-ready eQMSOperate and own ISO 13485 certification
Risk Management (ISO 14971)Create and maintain risk log, hazard analysis, traceabilityReview and accept residual risk
Usability (IEC 62366)Conduct formative/summative usability evaluationsApprove user interface risk conclusions
Clinical EvaluationSupport data collection, validation toolsOwn clinical evaluation report and ethics sign-off
Cybersecurity (ISO/IEC 27001)Design secure AWS-based cloud infrastructure, implement encryption and access controlManage certification scope and governance
Regulatory Submission (MHRA)Provide technical file, declaration templatesSubmit documentation and hold registration
Post-Market Surveillance (PMS)Provide PMS logging system and SOP templatesOperate PMS, report vigilance events

4. Standards Alignment

StandardImplementation by YoctobeClient Certification Requirement
ISO 13485:2016 – QMS for Medical DeviceseQMS structure and SOP templates fully alignedClient must hold certification
ISO 14971:2019 – Risk ManagementRisk framework integrated within eQMSReview and approval
IEC 62304:2006+A1:2015 – Software LifecycleFull compliance across requirements, design, verification, validationIncluded in client’s technical file
IEC 62366-1:2015 – Usability EngineeringUser-centred design process and traceabilitySign-off of usability summary
IEC 82304-1:2016 – Health Software SafetyEmbedded in architecture, covering non-device health softwareDemonstrate safe deployment
ISO/IEC 27001:2022 – Information SecurityAWS UK data centres (ISO 27001, Cyber Essentials Plus)Optional certification within client’s ISMS
ISO 14155:2020 – Clinical InvestigationSupports protocol templates and data integrityCertification or ethics governance (if applicable)

5. Infrastructure and Data Governance

Yoctobe hosts all SaMD and eQMS services on UK-based AWS cloud servers within the London region, ensuring:

  • Data residency within UK jurisdiction
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Access management under the principle of least privilege
  • Multi-availability zone redundancy
  • Compliance with ISO/IEC 27001, Cyber Essentials Plus, and GDPR (UK GDPR)

Yoctobe offloads all infrastructure compliance responsibilities to AWS UK while maintaining documented supplier agreements and security validation reports.

6. Technical File & Documentation Outputs

Yoctobe delivers the following MHRA-ready documentation packages to its clients:

  1. Device Description & Intended Use
  2. Software Architecture and Requirements Specification
  3. Risk Management File (ISO 14971)
  4. Usability Engineering File (IEC 62366)
  5. Verification & Validation Reports (IEC 62304)
  6. Cybersecurity & Data Protection Documentation (ISO/IEC 27001)
  7. Clinical Evaluation Support Materials
  8. Post-Market Surveillance & Vigilance Procedures
  9. Declaration of Conformity Template (UKCA)

All documents are version-controlled, traceable, and exported directly from Yoctobe’s eQMS.

7. Lifecycle and Handover Framework

Phase 1 – Initiation
Project governance, eQMS onboarding, risk classification, and intended purpose definition.

Phase 2 – Development
IEC 62304-compliant design and implementation, integrated risk tracking.

Phase 3 – Verification & Validation
Formal testing, usability validation, and cybersecurity validation.

Phase 4 – Technical File Preparation
Compilation of all evidence in MHRA-compatible structure.

Phase 5 – Client Certification & Submission
Client uses Yoctobe’s documentation and eQMS outputs to complete ISO 13485 certification and MHRA registration.

Phase 6 – Post-Market Maintenance
Yoctobe maintains the eQMS and software update documentation for traceability and regulatory continuity.

8. Post-Market and Vigilance Support

Yoctobe’s eQMS includes:

  • PMS logging module
  • Complaint management workflows
  • CAPA and risk re-assessment triggers
  • Audit-ready PMS records export

Clients use these features to maintain ongoing regulatory compliance after market entry.

9. Regulatory Responsibility Statement

Yoctobe acts as:

  • SaMD Developer – responsible for design, implementation, and validation.
  • SaMD QMS Provider & Maintainer – responsible for maintaining the validated ISO-ready eQMS environment.

The client organization acts as the Legal Manufacturer, holding:

  • ISO 13485 certification
  • MHRA registration and regulatory liability
  • Final sign-off on all risk and clinical documentation

This division ensures full compliance with MHRA, ISO, and NHS Digital expectations.

10. Audit Readiness Features

  • End-to-end traceability across all development artefacts
  • Secure audit trail and e-signatures compliant with FDA 21 CFR Part 11
  • Version-controlled SOPs and training logs
  • Full export of QMS records for ISO or MHRA audits
  • Documented tool validation (for eQMS and software verification tools)