Technology Due Diligence

IEC 62304 · IEC 81001-5-1 · Codebase · Architecture · Infrastructure

Structured assessment. Written risk report. Investor & acquirer ready.

This service combines the depth of the Audit Readiness Sprint (IEC 62304 + IEC 81001-5-1 project documentation) with hands-on codebase quality, scalability, and infrastructure investigation - delivered as a single risk-graded written report.

What this assessment covers:

IEC 62304: Software lifecycle documentation — class-appropriate gap analysis

IEC 81001-5-1: Cybersecurity documentation - STRIDE, SBOM, controls evidence

Codebase: Quality, maintainability, test coverage, dependency hygiene

Architecture: Scalability, modularity, cloud/device boundary design

Infrastructure: Deployment, CI/CD, monitoring, data residency, security posture

Assesment scope - Five investigation workstreams

Workstream 1 - IEC 62304

Software Lifecycle Documentation Review

Software Development Plan — class-appropriate completeness

Software Requirements Specification and architecture evidence

SOUP list — identification, risk assessment, verification records

Unit implementation, integration and system testing records

Change management, release artefacts and version control

Workstream 2 — IEC 81001-5-1

Cybersecurity Documentation Review

Security risk assessment and threat modelling documentation

SBOM completeness and vulnerability management evidence

Security requirements, controls specification and testing records

Gap analysis vs MDCG 2019-16 and FDA 2023 Cybersecurity Guidance

Workstream 3 - Codebase Quality

Codebase Quality & Technical Debt Assessment

Static analysis — maintainability index, code complexity, duplication

Test coverage assessment — unit, integration, system test completeness

Dependency hygiene — outdated libraries, licence risks, CVE exposure

Technical debt inventory — ranked by remediation effort and risk

Workstream 4 - Architecture

Architecture & Scalability Review

Architectural fitness for SaMD regulatory lifecycle

Modularity and maintainability — separation of concerns

Scalability — load, data volume, and user growth projections

Cloud/device boundary — security, data flow, latency risk

Workstream 5 - Infrastructure

Infrastructure, CI/CD & Security Posture Review

Deployment architecture — cloud, environment segregation, IaC

CI/CD pipeline — test gates, release controls, rollback

Data residency — GDPR, HIPAA, MDR Article 83

Security posture — access controls, secrets management

We need 30 minutes to explore how to accelerate your project.

Lock in your assessment.

Engagement details

Typical timeline

Week 1

Kick-off, document intake, codebase access setup

Week 2

Documentation review + static analysis (WS 1–3)

Week 3

Infrastucture review (WS 4-5)

Week 4

Risk-graded report + remediation roadmap delivered

Who this is for

PE/VC funds assessing digital health acquisition targets

Series A–C investors requiring pre-investment technical assurance

Medtech acquirers evaluating target company technology risk

Founders preparing for investor due diligence data room

Companies preparing for MDR notified body or FDA pre-submission

Terms

All prices are fixed fees excluding VAT.

Every engagement includes:

30-min discovery call

Written scope

Senior QA/RA review

Request custom pricing by email

Our Partners

Chamber logo
Cherry logo
Fittech logo
HTS logo
ITCorner logo
MDG logo
Medical Valley logo
Medlink logo
Medvia logo
MTC logo
Polish-Netherlands Chamber of Commerce logo
PWR logo
SIBB logo
Task Force logo
Biocom logo