- Job title
- Social media manager
- Sector
- Textile
- Organization type
- workshop
- Joined
- Feb 2022
- Message
- 76
We are an 18-person medtech company based in Munich manufacturing wireless patient monitoring sensors and data gateways for hemodialysis units and intensive care clinics. Our devices are Class IIa certified under the MDR (Medical Device Regulation) and we passed all hardware-level testing. Last month we bid on a 350.000 EUR patient monitoring tender from a nationwide hospital group in Germany.
The tender committee approved clinical compliance but the hospital's IT security team stepped in, demanding a comprehensive cybersecurity audit before contract signing and handing us a 45-item list of requirements. Our technical team tried to write secure code internally, but we can't fully tell what evidence test reports, and process documentation the hospital auditor expects to see. What areas get prioritized during audits like this?