Back
on
by

Continuous Delivery/Continuous Compliance in SaMD: When It’s Done, It’s Done

Continuous Delivery and Continuous Compliance in SaMD
Sequenex’s Continuous Delivery/Continuous Compliance methodology develops software and regulatory artifacts together, reducing documentation debt and ensuring each release is tested, documented, traceable, and complete.

In many medical device software programs, “done” only means that the code has been written.

The software may appear complete, but requirements, risk documentation, traceability, verification evidence, architecture records, and release documentation remain unfinished. Teams then spend weeks or months reconstructing the development history and trying to align regulatory artifacts with software that has continued to change.

At Sequenex, we take a different approach.

We use a methodology called Continuous Delivery/Continuous Compliance, in which the software and its supporting regulatory artifacts are developed together.

Our principle is simple:

When it’s done, it’s done.

What Is Continuous Delivery/Continuous Compliance?

Continuous Delivery/Continuous Compliance is an integrated approach to regulated software development.

At Sequenex, we use a Kanban-based workflow aligned with IEC 62304, ISO 14971, our ISO 13485-certified quality management system, and applicable regulatory requirements.

As the software moves through development, the related requirements, design information, risk controls, verification evidence, traceability, configuration records, and release documentation move with it.

A development item is not complete simply because the code works. It is complete when the applicable design, development, testing, risk-management, traceability, review, and documentation activities are also complete.

There is no separate documentation project waiting at the end.

Avoiding Documentation Debt

When documentation is postponed until the end of development, teams must reconstruct the history of the product after the work has already occurred.

They may need to determine:

  • Why a feature was developed
  • Which requirement it satisfies
  • Which risks it addresses
  • Which test verified it
  • Which software version was tested
  • How later changes affected the system

This process is time-consuming, expensive, and vulnerable to gaps.

With Continuous Delivery/Continuous Compliance, regulatory artifacts are developed alongside the software while the technical decisions and supporting information are still current.

Automation helps maintain the relationships among requirements, risks, code, tests, defects, builds, and releases. Reviews, approvals, risk decisions, and validation conclusions remain the responsibility of qualified personnel, but much of the supporting evidence can be generated and maintained through the development workflow.

The Benefits of Continuous Delivery/Continuous Compliance

The greatest benefit is a more meaningful definition of done.

A feature is not reported as complete while testing, traceability, risk documentation, and regulatory artifacts remain unfinished. Sponsors gain a clearer view of actual progress and product readiness.

This approach helps:

  • Reduce late-stage documentation and remediation
  • Keep software and regulatory records aligned
  • Identify quality, safety, and integration issues earlier
  • Maintain traceability across requirements, risks, code, and tests
  • Improve visibility into the true status of each release
  • Support clinical studies, regulatory submissions, and commercialization

The objective is not to eliminate regulatory work. It is to perform that work as part of development, when the relevant information is available.

How Sequenex Uses Continuous Delivery/Continuous Compliance

Sequenex integrates regulated software-development activities into a Kanban-based workflow.

Each work item progresses through the applicable requirements, design, risk-management, implementation, review, testing, traceability, and documentation activities before it is considered complete.

Our definition of done includes both the working software and its supporting development evidence.

Depending on the project, that evidence may include software requirements, architecture and design documentation, software risk analysis, verification results, traceability, configuration records, problem-resolution records, cybersecurity documentation, and release documentation.

These artifacts are not recreated after development. They are developed and maintained alongside the software.

When It’s Done, It’s Done

Continuous Delivery/Continuous Compliance gives medical device companies working software and a development record that accurately reflects it.

Compliance is not treated as a documentation phase that begins after development. It is integrated into how the software is planned, designed, built, tested, reviewed, and released.

When it’s done, it’s done.

Want to schedule a demo of NEX?

Contact us
SaMD and Connected Devices Software Experts
© 2025 Sequenex. All rights reserved.