Fixed price. 3–4 weeks. Software class A / B / C
IEC 62304 and IEC 81001-5-1 impose documentation obligations that most development teams are not fully meeting, and most don't find out until a notified body or customer audit reveals it.
This sprint reviews your project documentation against the exact requirements of both standards — before the auditor does.
Documentation gaps we identify:
SW lifecycle plan missing or not IEC 62304 class-appropriate
No cybersecurity risk file aligned to IEC 81001-5-1
SOUP documentation incomplete or unverified
Verification & validation records missing for current SW release
What we review — and what you receive
MODULE 1 — IEC 62304
Software Lifecycle Documentation Review
Software development plan (class-appropriate scope)
Software requirements specification (SRS) and architecture
SOUP list — identification, risk assessment, and verification records
Software unit implementation and verification records
Software integration and system testing evidence
Problem resolution process and change management records
Release documentation and version control artefacts
MODULE 2 — IEC 81001-5-1
Cybersecurity Documentation Review
Security risk assessment and threat modelling documentation
Security requirements and controls specification
Vulnerability management process and SBOM documentation
Cybersecurity testing evidence (penetration testing records)
Post-market cybersecurity monitoring plan
Alignment check: IEC 81001-5-1 vs MDCG 2019-16 /FDA 2023
What you receive
Documentation Gap Report
Structured gap analysis ranked Critical / Major /Minor against IEC 62304 and/or IEC 81001-5-1. Scoped to your software class and selected module(s).
Risk-Ranked Remediation Plan
Prioritised action plan with recommended owners, effort estimates, and logical sequencing — ready to execute directly or with Thaumatec support.
Technical Review Session
2-hour live review with your engineering and regulatory leads. We walk through findings, challenge your evidence, and identify narrative gaps.
Written Findings Report
Formal deliverable suitable for sharing with your board, notified body liaison, or FDA - with compliance status, all gaps, and agreed remediation actions.
Fixed-price tiers by software class (IEC 62304)
Software Class A Low Risk SaMD
Module 1 IEC 62304 Only
€4,000
EUR 5,000/ Standard Price
Module 2 IEC 81001-5-1 Only
€2,800
EUR 3,500/ Standard Price
Bundle Package
€6,320
EUR 7,900/ Standard Price
Software Class B Medium Risk SaMD
Module 1 IEC 62304 Only
€8,000
EUR 10,000/ Standard price
Module 2 IEC 81001-5-1 Only
€6,400
EUR 8,000/ Standard price
Bundle Package
€13,520
EUR 16,900/ Standard Price
Software Class C High Risk SaMD
Module 1 IEC 62304 Only
€13,600
EUR 17,000/ Standard price
Module 2 IEC 81001-5-1 Only
€10,400
EUR 13,000/ Standard price
Bundle Package
€20,720
EUR 25,900 / Standard price
We need 30 minutes to explore how to accelerate your project.
Lock in your assessment.
Engagement details
Typical timeline
Kick-off, document intake, scope confirmation per module
Document review & evidence gap analysis
Technical review session with your team
Written findings report + remediation plan delivered
Who this is for
SaMD teams preparing for IEC 62304 audit or gap closure
Products with connected/IoMT features (IEC 81001-5-1)
FDA 510(k) or De Novo pre-submission preparation
MDR Class IIa–III technical file readiness
Series A/B investor due diligence preparation
Terms
All prices are fixed fees excluding VAT.
Every engagement includes:
30-minute discovery call
Written scope
Senior QA/RA review
Our Partners















