Sii Poland

SII UKRAINE

SII SWEDEN

  • Trainings
  • Career
Join us Contact us
Back

Sii Poland

SII UKRAINE

SII SWEDEN

Back
logo

Cybersecurity and compliance remediation for the VIMS medical imaging system

Preparing VIMS for Class B and cybersecurity requirements

As regulatory expectations for medical device software and cybersecurity continued to evolve, Zimmer Biomet needed to strengthen the VIMS software lifecycle, cybersecurity posture, traceability, testing practices, and supporting documentation to maintain and expand market readiness. Existing processes and engineering practices required modernization, and additional evidence aligned with current regulatory expectations.

VIMS provides the primary visualization interface used by surgeons during minimally invasive procedures. Although the software does not control therapy, image delays, freezes, or distortions can indirectly affect clinical decisions. Following a reassessment of the system’s clinical role, post-market data, and risk documentation, Zimmer Biomet determined that the software should be reclassified from IEC 62304 Class A to Class B.

The transition required an auditable software lifecycle, documented cybersecurity risk management, verification of risk controls, and V&V evidence aligned with Class B expectations. It was also a prerequisite for continued access to key markets and future product scalability.

Zimmer Biomet needed to address these requirements within a fixed regulatory timeline while simultaneously executing remediation activities across compliance, cybersecurity, quality, and software engineering domains.

Five coordinated remediation workstreams

Sii carried out the program through five coordinated workstreams aligned with Zimmer Biomet’s Quality Management System and internal processes. A multidisciplinary team combined delivery and project management, security architecture, medical documentation, embedded cybersecurity, software engineering, DevSecOps, and V&V expertise. Sii and Zimmer Biomet worked as one integrated team through 2‑week sprints, technical workshops, regular synchronization meetings, shared project tools, and continuous knowledge transfer.

The scope of work included:

  • Software process remediation – compliance assessment, software lifecycle documentation remediation, requirements management, and bidirectional traceability across requirements, risks, controls, and tests
  • Cybersecurity process remediation – threat modeling, cybersecurity risk analysis, definition of security controls and countermeasures, and preparation of cybersecurity documentation aligned with regulatory expectations
  • Penetration testing – security test planning, vulnerability assessment, remediation verification, retesting, and preparation of certification-ready reports
  • Verification and validation – test strategy preparation, test design and execution, validation of risk controls, and delivery of objective evidence supporting regulatory compliance
  • Development Workstream – implementation of selected software remediation activities, including third-party software remediation, cybersecurity risk mitigation, unit testing and coverage improvement, new software preparation, configuration management, secure manufacturing and deployment, CI/CD implementation, and Medicapture-related development activities

The work was aligned with IEC 62304, IEC 81001-5-1, ISO 14971, the EU Medical Device Regulation, FDA cybersecurity guidance, and market-specific requirements for the United States and Japan.

Integrated compliance and engineering delivery

The cooperation evolved from a traditional remediation model into a mixed delivery model. In addition to defining cybersecurity and compliance improvements, Sii provided a dedicated engineering capacity to implement selected software changes, testing activities, and DevSecOps capabilities under Zimmer Biomet governance.

Across documentation, analysis, and testing activities, AI-assisted tools supported software design documentation, architecture descriptions, legacy code and requirements analysis, and unit-test generation followed by expert review and refactoring.

Regulatory readiness combined with remediation execution

The program provided Zimmer Biomet with both the framework and execution capacity required to progress remediation activities within the required timeline. By combining regulatory, cybersecurity, V&V, software engineering, and DevSecOps support, Sii delivered a single coordinated program addressing interdependent compliance and engineering challenges.

The engagement supported readiness for the European Union, United States, and Japanese markets, strengthened cybersecurity governance, and enabled the controlled transition from Class A to Class B expectations while modernizing selected engineering practices.

Key results

  • Complete, audit-ready software lifecycle framework covering requirements, architecture, design, verification, validation, and traceability
  • Formal cybersecurity risk management process with documented threat modeling, risk analysis, and mapping of risks to security controls and countermeasures
  • Independently validated security controls supported by vulnerability assessments, mitigation retesting, and certification-ready penetration-testing reports
  • V&V artifacts confirming that remediation-driven changes met regulatory, safety, and quality requirements
  • Additional software engineering capacity that accelerated remediation execution and reduced dependency on internal development resources
  • Implementation of selected software remediation, cybersecurity, testing, CI/CD, configuration management, and DevSecOps activities
  • Support for implementation of cybersecurity countermeasures identified through cybersecurity risk assessments and analyses
  • Improved readiness for the European Union, United States, and Japanese markets while supporting the transition from Class A to Class B
  • AI-assisted documentation reduced selected activities from several weeks to a few days, while unit-test preparation was estimated to be more than 50% faster than a fully manual approach

GET IN TOUCH

Let's start the conversation today

Your file

Uploaded file:
  • file_icon Created with Sketch.

Acceptable files: doc, docx, pdf. (max 5MB)
Please submit your file in DOC, DOCX or PDF format
The upload size is limited to 5 MB
File is empty
File was not uploaded

At any time, you may withdraw your consent to the processing of personal data, but such withdrawal shall not affect the legal compliance of any processing of such data, which had occurred before you withdrew your consent. Detailed information on the processing of your personal data is specified in the Sii Poland Group Privacy Policy.

Your message was sent successfully

We will look over your message and get back to you as soon as possible

Sorry, something went wrong and your message was not delivered

Refresh the page and try again. Contact us, if problem occurs again

We’re sorry, but the selected file appears to be damaged and we can't process it.

Please try uploading a different copy or a new version of the file. Contact us, if problem occurs again.

Processing...

Änderungen im Gange

Wir aktualisieren unsere deutsche Website. Wenn Sie die Sprache wechseln, wird Ihnen die vorherige Version angezeigt.

Ta treść jest dostępna tylko w jednej wersji językowej.
Nastąpi przekierowanie do strony głównej.

Czy chcesz opuścić tę stronę?

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden zur englischen Version der ausgewählten Seite weitergeleitet.

Möchten Sie fortfahren?

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden auf die deutsche Homepage weitergeleitet.

Möchten Sie fortsetzen?