Summary
Key results
Improved regulatory readiness for the European Union, United States, and Japanese markets
Software development and cybersecurity remediation activities supporting the transition to Class B expectations and evolving cybersecurity requirements
Preparing VIMS for Class B and cybersecurity requirements
As regulatory expectations for medical device software and cybersecurity continued to evolve, Zimmer Biomet needed to strengthen the VIMS software lifecycle, cybersecurity posture, traceability, testing practices, and supporting documentation to maintain and expand market readiness. Existing processes and engineering practices required modernization, and additional evidence aligned with current regulatory expectations.
VIMS provides the primary visualization interface used by surgeons during minimally invasive procedures. Although the software does not control therapy, image delays, freezes, or distortions can indirectly affect clinical decisions. Following a reassessment of the system’s clinical role, post-market data, and risk documentation, Zimmer Biomet determined that the software should be reclassified from IEC 62304 Class A to Class B.
The transition required an auditable software lifecycle, documented cybersecurity risk management, verification of risk controls, and V&V evidence aligned with Class B expectations. It was also a prerequisite for continued access to key markets and future product scalability.
Zimmer Biomet needed to address these requirements within a fixed regulatory timeline while simultaneously executing remediation activities across compliance, cybersecurity, quality, and software engineering domains.
Five coordinated remediation workstreams
Sii carried out the program through five coordinated workstreams aligned with Zimmer Biomet’s Quality Management System and internal processes. A multidisciplinary team combined delivery and project management, security architecture, medical documentation, embedded cybersecurity, software engineering, DevSecOps, and V&V expertise. Sii and Zimmer Biomet worked as one integrated team through 2‑week sprints, technical workshops, regular synchronization meetings, shared project tools, and continuous knowledge transfer.
The scope of work included:
- Software process remediation – compliance assessment, software lifecycle documentation remediation, requirements management, and bidirectional traceability across requirements, risks, controls, and tests
- Cybersecurity process remediation – threat modeling, cybersecurity risk analysis, definition of security controls and countermeasures, and preparation of cybersecurity documentation aligned with regulatory expectations
- Penetration testing – security test planning, vulnerability assessment, remediation verification, retesting, and preparation of certification-ready reports
- Verification and validation – test strategy preparation, test design and execution, validation of risk controls, and delivery of objective evidence supporting regulatory compliance
- Development Workstream – implementation of selected software remediation activities, including third-party software remediation, cybersecurity risk mitigation, unit testing and coverage improvement, new software preparation, configuration management, secure manufacturing and deployment, CI/CD implementation, and Medicapture-related development activities
The work was aligned with IEC 62304, IEC 81001-5-1, ISO 14971, the EU Medical Device Regulation, FDA cybersecurity guidance, and market-specific requirements for the United States and Japan.
Integrated compliance and engineering delivery
The cooperation evolved from a traditional remediation model into a mixed delivery model. In addition to defining cybersecurity and compliance improvements, Sii provided a dedicated engineering capacity to implement selected software changes, testing activities, and DevSecOps capabilities under Zimmer Biomet governance.
Across documentation, analysis, and testing activities, AI-assisted tools supported software design documentation, architecture descriptions, legacy code and requirements analysis, and unit-test generation followed by expert review and refactoring.
Regulatory readiness combined with remediation execution
The program provided Zimmer Biomet with both the framework and execution capacity required to progress remediation activities within the required timeline. By combining regulatory, cybersecurity, V&V, software engineering, and DevSecOps support, Sii delivered a single coordinated program addressing interdependent compliance and engineering challenges.
The engagement supported readiness for the European Union, United States, and Japanese markets, strengthened cybersecurity governance, and enabled the controlled transition from Class A to Class B expectations while modernizing selected engineering practices.
Key results
- Complete, audit-ready software lifecycle framework covering requirements, architecture, design, verification, validation, and traceability
- Formal cybersecurity risk management process with documented threat modeling, risk analysis, and mapping of risks to security controls and countermeasures
- Independently validated security controls supported by vulnerability assessments, mitigation retesting, and certification-ready penetration-testing reports
- V&V artifacts confirming that remediation-driven changes met regulatory, safety, and quality requirements
- Additional software engineering capacity that accelerated remediation execution and reduced dependency on internal development resources
- Implementation of selected software remediation, cybersecurity, testing, CI/CD, configuration management, and DevSecOps activities
- Support for implementation of cybersecurity countermeasures identified through cybersecurity risk assessments and analyses
- Improved readiness for the European Union, United States, and Japanese markets while supporting the transition from Class A to Class B
- AI-assisted documentation reduced selected activities from several weeks to a few days, while unit-test preparation was estimated to be more than 50% faster than a fully manual approach