Xyreg Logo
    Back to plans

    Every framework Xyreg checks against

    39 regulatory standards, global market rules and data-security frameworks. Core standards apply from concept; market and device frameworks are assigned automatically as you set target markets and device attributes.

    Core quality, risk & safety standards

    The foundational standards applied to every programme from concept onward.

    Baseline Regulatory Standard Check

    16

    Early cross-standard sanity check performed in Concept & Planning to confirm target markets, device classification, applicable core standards, and the absence of obvious platform-level gaps before design work starts.

    CoreDevice

    ISO 13485:2016 — Quality Management System

    65

    Complete set of 65 ISO 13485:2016 requirements for medical device quality management systems.

    CoreCompany-wide

    ISO 14971 — Risk Management Process

    21

    Enterprise-level risk management process: organisational process definition, management responsibilities, and personnel qualification.

    CoreCompany-wide

    ISO 14971:2019 — Risk Management (Device)

    18

    Device-specific risk management: risk management plan, hazard identification, risk analysis, evaluation, control measures, residual risk assessment, review, and post-production monitoring.

    CoreDevice

    IEC 62366-1 — Usability Engineering

    15

    Application of usability engineering to medical devices per IEC 62366-1:2015+A1:2020.

    CoreDevice

    ISO 15223-1 — Symbols for Medical Devices

    9

    Symbols to be used with information supplied by the manufacturer of medical devices per ISO 15223-1:2021.

    CoreDevice

    ISO 20417 — Information Supplied by Manufacturer

    11

    Requirements for information supplied by the manufacturer with medical devices per ISO 20417:2021.

    CoreDevice

    Electrical, software & biocompatibility

    Auto-assigned from device attributes — active, software-driven or patient-contacting.

    IEC 60601-1:2012 — General Safety and Essential Performance

    100

    General requirements for basic safety and essential performance of medical electrical equipment. Covers electrical, mechanical, radiation and temperature hazards, PEMS, construction and ME systems.

    Auto: active deviceDevice

    IEC 60601-1-2:2014 — EMC Requirements and Tests

    27

    Electromagnetic compatibility requirements and tests for medical electrical equipment and systems. Covers emissions, immunity, risk management for EMC, and accompanying documents.

    Auto: active deviceDevice

    IEC 60601-1-6 — Usability Engineering

    11

    Collateral standard for usability engineering of medical electrical equipment. Covers use specification, hazard-related use scenarios, formative and summative evaluation.

    Auto: active deviceDevice

    IEC 62304 — Software Life Cycle Processes

    29

    Software life cycle processes for medical device software. Covers development, maintenance, risk management, configuration management, and problem resolution.

    Auto: softwareDevice

    ISO 10993 — Biological Evaluation

    14

    Biological evaluation of medical devices — evaluation and testing within a risk management process per ISO 10993-1:2018.

    Auto: patient contactDevice

    IEC 20957 — Stationary Training Equipment

    31

    Safety requirements for stationary training equipment. Covers general safety, stability, strength/durability, labelling, instructions, and display accuracy.

    Auto: device typeDevice

    European Union & Europe

    EU MDR technical documentation and the wider European market set.

    MDR Annex I — General Safety and Performance Requirements

    20

    MDR Annex I General Safety and Performance Requirements — official requirements (Chapter I: 20 items).

    Auto: EU marketDevice

    MDR Annex II — Technical Documentation

    10

    Technical documentation requirements under EU MDR Annex II for comprehensive device documentation.

    Auto: EU marketDevice

    MDR Annex III — Clinical Evaluation and PMCF

    8

    Conformity assessment procedures under EU MDR Annex III for device certification and CE marking.

    Auto: EU marketDevice

    PPWR Compliance Checklist

    24

    Packaging and Packaging Waste Regulation (EU 2025/40) compliance checklist covering material restrictions, labelling, and ecodesign requirements for medical device packaging.

    Auto: EU marketDevice

    DiGA Fast-Track (BfArM §139e SGB V)

    57

    Comprehensive readiness checklist for listing a Digital Health Application (DiGA) in the BfArM directory under §139e SGB V, structured from the BfArM Fast-Track Guide and DiGAV.

    GermanyDevice

    Swiss MepV / Medizinprodukteverordnung

    8

    Swiss Medical Devices Ordinance (MepV) aligned with EU MDR, covering conformity assessment and market surveillance requirements for Switzerland.

    Auto: SwitzerlandCompany-wide

    UK MDR 2002 (MHRA)

    10

    UK Medical Devices Regulations 2002 (as amended) under MHRA covering UKCA marking, conformity assessment, and post-market surveillance for the UK market.

    Auto: UKCompany-wide

    United States (FDA)

    Quality system regulation for the US market, including the 2026 QMSR transition.

    FDA QMSR — Quality Management System Regulation

    88

    FDA QMSR (effective 2 Feb 2026) incorporates ISO 13485:2016 by reference with retained Part 820 sections (820.1, 820.3, 820.7, 820.10, 820.35, 820.45). Replaces the standalone 21 CFR Part 820 QSR. Internal audits, supplier audits, and management reviews are now subject to FDA inspection.

    Auto: US marketCompany-wide

    FDA 21 CFR Part 820 — Quality System Regulation

    56

    Comprehensive FDA 21 CFR Part 820 Quality System Regulation compliance checklist covering all subparts and requirements for medical device manufacturers.

    Auto: US marketCompany-wide

    Global market access

    Auto-assigned when you add a target market to a device.

    Australian Therapeutic Goods Act 1989

    9

    TGA regulatory framework for medical devices including conformity assessment, essential principles, and post-market requirements for the Australian market.

    Auto: AustraliaCompany-wide

    Brazil ANVISA RDC 751/2022

    9

    ANVISA Resolution RDC 751/2022 establishing requirements for registration, labelling, and good manufacturing practices for medical devices in Brazil.

    Auto: BrazilCompany-wide

    Canadian Medical Device Regulations (SOR/98-282)

    10

    Health Canada Medical Device Regulations SOR/98-282 covering device classification, licensing, and quality system requirements for the Canadian market.

    Auto: CanadaCompany-wide

    China NMPA Medical Device Regulations

    10

    NMPA regulatory framework for medical devices including registration, classification, and quality management system requirements for the Chinese market.

    Auto: ChinaCompany-wide

    India CDSCO Medical Device Rules 2017

    9

    Central Drugs Standard Control Organisation Medical Device Rules 2017 covering registration, import licensing, and clinical investigation requirements for India.

    Auto: IndiaCompany-wide

    Japan PAL / PMD Act (PMDA)

    9

    Japanese Pharmaceutical and Medical Device Act covering approval, QMS, and post-market surveillance requirements administered by PMDA.

    Auto: JapanCompany-wide

    South Korea MFDS Medical Device Industry Act

    9

    Korean Ministry of Food and Drug Safety Medical Device Act covering device classification, technical documentation, and GMP requirements for South Korea.

    Auto: South KoreaCompany-wide

    Data, security & AI

    Information security, privacy and AI governance frameworks alongside the device standards.

    GDPR (Regulation 2016/679)

    36

    EU General Data Protection Regulation — audit-ready clause set covering principles, data subject rights, controller/processor obligations, international transfers, and enforcement-relevant articles.

    Auto: EU marketCompany-wide

    SOC 2

    Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy of a service organisation.

    Company-wide

    ISO/IEC 27001 — Information Security Management

    Requirements for establishing, implementing, maintaining and continually improving an information security management system.

    Company-wide

    HIPAA

    US Health Insurance Portability and Accountability Act privacy and security rules for protected health information.

    Company-wide

    HITRUST CSF

    Certifiable framework harmonising HIPAA, ISO 27001, NIST and other authorities into a single control set for healthcare data.

    Company-wide

    ISO/IEC 42001 — AI Management System

    Requirements for an artificial intelligence management system, governing responsible development and use of AI.

    Company-wide

    NIST AI Risk Management Framework

    Voluntary framework for managing risks in the design, development, use and evaluation of AI systems.

    Company-wide

    US Data Privacy (USDP)

    Consolidated US state data privacy requirements for handling personal information across jurisdictions.

    Company-wide

    Custom & reimbursement

    Frameworks you define yourself, plus market-access and reimbursement checklists.

    Reimbursement List

    A custom checklist for tracking reimbursement and market-access requirements specific to your device and target payers.

    CustomDevice

    Custom Frameworks

    Build, validate and mandate your own corporate compliance checklists and SOP templates, then run gap analysis against them like any built-in standard.

    CustomCompany-wide

    Need a framework that isn't listed?

    Build your own controlled checklist with the Custom Framework Studio, or talk to us about adding a standard to the catalogue.