ISO 13485 + ISO 27001 Integrated Documentation Kit

€890.00

Categories ,

ISO 13485 & MDSAP Ready

Editable Word & Excel

ISO 13485 / MDSAP / FDA QMSR

Used by 100+ quality teams

ISO 13485:2016 · ISO/IEC 27001:2022 · EU MDR

ISO 13485 + ISO 27001 Integrated Documentation Kit

One management system for quality and information security: 42 procedures and 71 templates, with a single procedure wherever the two standards ask for the same thing.

€890

VAT calculated at checkout

Get the kit

118 files · 42 procedures · 71 templates
Editable Word and Excel files

Four ways a second management system goes wrong

A medical device manufacturer that adds ISO/IEC 27001 to an ISO 13485 system usually builds it next to the existing one. The result is two document control procedures, two internal audit programmes, two management reviews and two corrective action processes, each with its own forms. Both auditors then find the same weakness twice, and the people who run the system keep two sets of records for one activity.

The second failure is a security system made of policies that nobody operates: documents exist, records do not. The third is a Statement of Applicability chosen from the list of controls and not derived from a risk assessment, so that nothing supports it when it is compared with the risk register. The fourth is procedures that cite documents which do not exist, because the two sets were written at different times by different people.

None of these are hard problems. They are the consequence of treating ISO/IEC 27001 as a second set of documents rather than as further requirements on the management system you already run.

  • 118 files
  • 42 procedures
  • 71 templates
  • 9 integrated procedures
  • 93 controls mapped
  • Word and Excel

Scope

What the kit covers

The kit is the complete ISO 13485 documentation kit with the information security management system built into it. Nine procedures satisfy both standards; the others belong to one standard only and say so.

01

Integrated management processes

Nine procedures written once for both standards: document control, management review, internal audit, CAPA, competence and awareness, objectives and KPIs, change control, regulatory and legal requirements, supplier management.

02

Medical device quality processes

Twenty-one procedures for ISO 13485 and the EU MDR: risk management, design and development, production, process validation, complaints, vigilance, post-market surveillance, UDI, labelling and the medical device file.

03

Information security

Twelve procedures for ISO/IEC 27001: risk assessment and the Statement of Applicability, operational planning, assets and classification, access control, operations, vulnerabilities, secure development, incidents, continuity, logging and monitoring.

Contents

The manual, the policy and 42 procedures, each with its templates

QM-001Quality and Information Security Manualscope, context, roles, process map
QM-002Quality and Information Security Policyone signed policy for both systems
SOP-CORE-01Document and Record Controlboth standards · 3 templates
SOP-CORE-02Management Reviewboth standards · 1 template
SOP-CORE-03Internal Auditboth standards · 3 templates
SOP-CORE-04Corrective and Preventive Actionboth standards · 2 templates
SOP-ISO-02Risk ManagementISO 13485 · 3 templates
SOP-ISO-04Human Resources and Trainingboth standards · 3 templates
SOP-ISO-05KPI and Data Analysisboth standards · 2 templates
SOP-ISO-06Computer System ValidationISO 13485 · 2 templates
SOP-ISO-08Nonconformance ManagementISO 13485 · 2 templates
SOP-ISO-09Change Controlboth standards · 2 templates
SOP-ISO-10Clinical EvaluationISO 13485 · 2 templates
SOP-ISO-11EU Vigilance ReportingISO 13485 · 1 template
SOP-ISO-13Complaint ManagementISO 13485 · 2 templates
SOP-ISO-14UDI ManagementISO 13485 · 1 template
SOP-ISO-15Design and Development ControlISO 13485 · 6 templates
SOP-ISO-16Process ValidationISO 13485 · 3 templates
SOP-ISO-17Medical Device FileISO 13485 · 1 template
SOP-ISO-19Customer Related ProcessesISO 13485 · 1 template
SOP-ISO-20Strategy for Regulatory Complianceboth standards · 3 templates
SOP-ISO-21Infrastructure and Equipment ControlISO 13485 · 2 templates
SOP-ISO-22Supplier Managementboth standards · 5 templates
SOP-ISO-24Production and Service ProvisionISO 13485 · 1 template
SOP-ISO-25Incoming Inspection and ControlISO 13485 · 2 templates
SOP-ISO-26Sterilization Process ValidationISO 13485 · no templates
SOP-ISO-27Advisory Notice and Field Safety Corrective ActionsISO 13485 · 2 templates
SOP-ISO-28Post-Market SurveillanceISO 13485 · 3 templates
SOP-ISO-29Usability EngineeringISO 13485 · 2 templates
SOP-ISO-31Labelling and Translation ManagementISO 13485 · 1 template
SOP-ISO-34Purchase ManagementISO 13485 · 1 template
SOP-ISO-35Notified Body Change NotificationISO 13485 · 1 template
SOP-ISMS-06Information Security Risk ManagementISO/IEC 27001 · 3 templates
SOP-ISMS-08ISMS Operational Planning and ControlISO/IEC 27001 · no templates
SOP-ISMS-09Asset and Information ClassificationISO/IEC 27001 · 1 template
SOP-ISMS-10Access Control and IdentityISO/IEC 27001 · 1 template
SOP-ISMS-11Operations SecurityISO/IEC 27001 · no templates
SOP-ISMS-12Vulnerability and Configuration ManagementISO/IEC 27001 · 1 template
SOP-ISMS-13Secure Development and ChangeISO/IEC 27001 · no templates
SOP-ISMS-14Physical and Environmental SecurityISO/IEC 27001 · no templates
SOP-ISMS-15Human Resources SecurityISO/IEC 27001 · 1 template
SOP-ISMS-17Incident ManagementISO/IEC 27001 · 1 template
SOP-ISMS-18Continuity and ResilienceISO/IEC 27001 · no templates
SOP-ISMS-19Logging and MonitoringISO/IEC 27001 · no templates
GlossaryGlossary of Information Security Terms56 terms, 11 roles
Master IndexMaster Indexall files, clause and control maps

Audience

Who the kit is for

  • Medical device manufacturers that need ISO/IEC 27001 alongside ISO 13485
  • Manufacturers of medical device software and connected devices
  • QA/RA managers asked to take on information security
  • Information security managers joining a regulated manufacturer
  • Consultants building both systems for a client

The kit assumes you know what a quality management system is and can adapt a procedure to your organization. It does not assume prior knowledge of ISO/IEC 27001: the README gives the order in which to implement it. It does not replace the standards, and you need your own copies of both.

What is included

What you get when you buy

  • QM-001 Quality and Information Security Manual and QM-002 Policy
  • 42 procedures in Word, in one layout
  • 71 templates: forms in Word, registers and logs in Excel
  • Statement of Applicability with the 93 Annex A controls, each mapped to its procedure
  • Document Master List pre-filled with the 116 controlled documents of the kit
  • Master Index with the ISO/IEC 27001 clause map, the Annex A control map and a NIS-2 mapping
  • README with the implementation sequence in five phases
  • Glossary of information security terms
  • Free updates when the kit is revised

Questions

Before you buy

Do I need to buy the standards as well?

Yes. The kit implements ISO 13485:2016 and ISO/IEC 27001:2022 but does not reproduce them. The Statement of Applicability gives a short reminder of each control’s subject; the exact control text is taken from your copy of the standard.

Does it replace the ISO 13485 Documentation Kit?

It contains it. All 30 procedures of the ISO 13485 kit are here, nine of them extended to cover ISO/IEC 27001, together with 12 information security procedures. If you need ISO 13485 only, the ISO 13485 kit is enough.

How does it differ from the ISO 27001 Documentation Kit?

The ISO 27001 kit is for an organization that wants ISO/IEC 27001 alone and has no medical device content. In this kit the management-system procedures are shared with the quality system, so there is one document control, one audit programme, one management review and one CAPA process.

Is ISO/IEC 27001 mandatory for a medical device manufacturer?

No. Neither ISO 13485 nor the EU MDR requires it. Manufacturers usually adopt it because customers and tenders ask for it, or because they fall within the scope of NIS-2.

Can the two systems be audited together?

The kit is built for it: one audit programme covers both standards, and the audit report states a conclusion for each. Whether the certification audits are combined is agreed with your certification bodies.

Does the scope of the ISMS have to match the scope of the QMS?

No. The two scopes are stated separately in the manual, and a worksheet in its annexes takes you through the ISMS boundary. They often differ, and the manual says so explicitly.

We already run our own ISO 13485 system. Can we use this kit?

Yes. The nine integrated procedures are written on the MD Regulatory ISO 13485 kit, so you either adopt them in place of yours or move the ISO/IEC 27001 sections into your own procedures. The 12 information security procedures are adopted as they are.

In which format are the documents?

Procedures and forms are Word files; registers, logs and the Statement of Applicability are Excel files. Everything is editable, with bracketed placeholders for your company name, roles and dates.

Do I get updates when the kit changes?

Yes. When the kit is revised, you receive the updated files at no additional cost.

Can the kit be used in more than one company?

Yes. For use across several companies, for example by a consultant with several clients or a group with several legal entities, get in touch and we will arrange a multi-licence purchase.

Does the kit make us compliant or certified?

No. Conformity comes from operating the processes and keeping the records. The kit defines the processes and gives you the forms; the README says in which order to start them and what evidence an auditor will sample.

ISO 13485 + ISO 27001 Integrated Documentation Kit

118 files: the manual, the policy, 42 procedures and 71 templates for ISO 13485 and ISO/IEC 27001, in editable Word and Excel.

Get the kit — €890

€890.00