Fda consultant specialist

FDA regulatory consultant for medical device companies.

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/fda-consultant-specialist, including the files SKILL.md points to.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit alirezarezvani/claude-skills/ra-qm-team/skills/fda-consultant-specialist#main ~/.claude/skills/fda-consultant-specialist

For one project only, change the path to .claude/skills/fda-consultant-specialist. This skill also uses fda_submission_guide.md, qsr_compliance_requirements.md, hipaa_compliance_framework.md, device_cybersecurity_guidance.md, fda_submission_tracker.py, qsr_compliance_checker.py — copying SKILL.md alone won't be enough. See the folder on GitHub.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Fda consultant specialist

Show the full text312 lines
namedescription
fda-consultant-specialistFDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QMSR (21 CFR 820, which incorporates ISO 13485:2016 by reference since 2026-02-02; formerly QSR) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QMSR, QSR, ISO 13485 for FDA, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity.

FDA Consultant Specialist

FDA regulatory consulting for medical device manufacturers covering submission pathways, the Quality Management System Regulation (QMSR, 21 CFR Part 820 — formerly the QSR), HIPAA compliance, and device cybersecurity requirements.

Table of Contents


FDA Pathway Selection

Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.

Decision Framework
Predicate device exists?
├── YES → Substantially equivalent?
│   ├── YES → 510(k) Pathway
│   │   ├── No design changes → Abbreviated 510(k)
│   │   ├── Manufacturing only → Special 510(k)
│   │   └── Design/performance → Traditional 510(k)
│   └── NO → PMA or De Novo
└── NO → Novel device?
    ├── Low-to-moderate risk → De Novo
    └── High risk (Class III) → PMA
Pathway Comparison
Pathway When to Use Timeline User Fee (FY2024)
510(k) Traditional Predicate exists, design changes 90 days $21,760 (FY2024)
510(k) Special Manufacturing changes only 30 days $21,760 (FY2024)
510(k) Abbreviated Guidance/standard conformance 30 days $21,760 (FY2024)
De Novo Novel, low-moderate risk 150 days $134,676 (FY2024)
PMA Class III, no predicate 180+ days $425,000+ (FY2024)

User fees are set annually under MDUFA. Verify current-fiscal-year fees at fda.gov (MDUFA user fee schedule) before budgeting; small-business rates differ.

Pre-Submission Strategy
  1. Identify product code and classification
  2. Search 510(k) database for predicates
  3. Assess substantial equivalence feasibility
  4. Prepare Q-Sub questions for FDA
  5. Schedule Pre-Sub meeting if needed

Reference: See fda_submission_guide.md for pathway decision matrices and submission requirements.


510(k) Submission Process

Workflow
Phase 1: Planning
├── Step 1: Identify predicate device(s)
├── Step 2: Compare intended use and technology
├── Step 3: Determine testing requirements
└── Checkpoint: SE argument feasible?

Phase 2: Preparation
├── Step 4: Complete performance testing
├── Step 5: Prepare device description
├── Step 6: Document SE comparison
├── Step 7: Finalize labeling
└── Checkpoint: All required sections complete?

Phase 3: Submission
├── Step 8: Assemble submission package
├── Step 9: Submit via eSTAR
├── Step 10: Track acknowledgment
└── Checkpoint: Submission accepted?

Phase 4: Review
├── Step 11: Monitor review status
├── Step 12: Respond to AI requests
├── Step 13: Receive decision
└── Verification: SE letter received?
Required Sections (21 CFR 807.87)
Section Content
Cover Letter Submission type, device ID, contact info
Form 3514 CDRH premarket review cover sheet
Device Description Physical description, principles of operation
Indications for Use Form 3881, patient population, use environment
SE Comparison Side-by-side comparison with predicate
Performance Testing Bench, biocompatibility, electrical safety
Software Documentation Level of concern, hazard analysis (IEC 62304)
Labeling IFU, package labels, warnings
510(k) Summary Public summary of submission
Common RTA Issues
Issue Prevention
Missing user fee Verify payment before submission
Incomplete Form 3514 Review all fields, ensure signature
No predicate identified Confirm K-number in FDA database
Inadequate SE comparison Address all technological characteristics

QMSR Compliance (formerly QSR)

Quality Management System Regulation (QMSR) requirements for medical device manufacturers under 21 CFR Part 820.

QMSR transition (effective 2026-02-02): FDA's QMSR final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure (820.20–820.198). Those subsection numbers are historical and no longer exist in the CFR; the corresponding requirements now flow from ISO 13485:2016 clauses plus the retained/renumbered sections 820.10 (requirements, incl. the ISO 13485 incorporation), 820.35 (records), and 820.45 (device labeling and packaging controls). 21 CFR Parts 801, 803, 806, and 830 are unchanged. Legacy QSR numbers below are kept only as a familiar index, each mapped to its current ISO 13485 clause.

Key Quality Subsystems (legacy QSR index → current ISO 13485:2016 clause)
Legacy QSR Section (historical, pre-2026) Title Current authority under QMSR Focus
820.20 Management Responsibility ISO 13485 §5.1, 5.5, 5.6 Quality policy, org structure, management review
820.30 Design Controls ISO 13485 §7.3 Input, output, review, verification, validation
820.40 Document Controls ISO 13485 §4.2.4 Approval, distribution, change control
820.50 Purchasing Controls ISO 13485 §7.4 Supplier qualification, purchasing data
820.70 Production Controls ISO 13485 §6.3, 6.4, 7.5 Process validation, environmental controls
820.100 CAPA ISO 13485 §8.5.2, 8.5.3 Root cause analysis, corrective actions
820.181 Device Master Record ISO 13485 §4.2.3 (medical device file) + 21 CFR 820.35 Specifications, procedures, acceptance criteria
Design Controls Workflow (ISO 13485 §7.3; legacy QSR 820.30)
Step 1: Design Input
└── Capture user needs, intended use, regulatory requirements
    Verification: Inputs reviewed and approved?

Step 2: Design Output
└── Create specifications, drawings, software architecture
    Verification: Outputs traceable to inputs?

Step 3: Design Review
└── Conduct reviews at each phase milestone
    Verification: Review records with signatures?

Step 4: Design Verification
└── Perform testing against specifications
    Verification: All tests pass acceptance criteria?

Step 5: Design Validation
└── Confirm device meets user needs in actual use conditions
    Verification: Validation report approved?

Step 6: Design Transfer
└── Release to production with DMR complete
    Verification: Transfer checklist complete?
CAPA Process (ISO 13485 §8.5.2/8.5.3; legacy QSR 820.100)
  1. Identify: Document nonconformity or potential problem
  2. Investigate: Perform root cause analysis (5 Whys, Fishbone)
  3. Plan: Define corrective/preventive actions
  4. Implement: Execute actions, update documentation
  5. Verify: Confirm implementation complete
  6. Effectiveness: Monitor for recurrence (30-90 days)
  7. Close: Management approval and closure

Reference: See qsr_compliance_requirements.md for the historical QSR structure with full QMSR/ISO 13485:2016 clause mapping.


HIPAA for Medical Devices

HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).

Applicability
Device Type HIPAA Applies
Standalone diagnostic (no data transmission) No
Connected device transmitting patient data Yes
Device with EHR integration Yes
SaMD storing patient information Yes
Wellness app (no diagnosis) Only if stores PHI
Required Safeguards
Administrative (§164.308)
├── Security officer designation
├── Risk analysis and management
├── Workforce training
├── Incident response procedures
└── Business associate agreements

Physical (§164.310)
├── Facility access controls
├── Workstation security
└── Device disposal procedures

Technical (§164.312)
├── Access control (unique IDs, auto-logoff)
├── Audit controls (logging)
├── Integrity controls (checksums, hashes)
├── Authentication (MFA recommended)
└── Transmission security (TLS 1.2+)
Risk Assessment Steps
  1. Inventory all systems handling ePHI
  2. Document data flows (collection, storage, transmission)
  3. Identify threats and vulnerabilities
  4. Assess likelihood and impact
  5. Determine risk levels
  6. Implement controls
  7. Document residual risk

Reference: See hipaa_compliance_framework.md for implementation checklists and BAA templates.


Device Cybersecurity

FDA cybersecurity requirements for connected medical devices.

Premarket Requirements
Element Description
Threat Model STRIDE analysis, attack trees, trust boundaries
Security Controls Authentication, encryption, access control
SBOM Software Bill of Materials (CycloneDX or SPDX)
Security Testing Penetration testing, vulnerability scanning
Vulnerability Plan Disclosure process, patch management
Device Tier Classification

Tier 1 (Higher Risk):

  • Connects to network/internet
  • Cybersecurity incident could cause patient harm

Tier 2 (Standard Risk):

  • All other connected devices
Postmarket Obligations
  1. Monitor NVD and ICS-CERT for vulnerabilities
  2. Assess applicability to device components
  3. Develop and test patches
  4. Communicate with customers
  5. Report to FDA per guidance
Coordinated Vulnerability Disclosure
Researcher Report
    ↓
Acknowledgment (48 hours)
    ↓
Initial Assessment (5 days)
    ↓
Fix Development
    ↓
Coordinated Public Disclosure

Reference: See device_cybersecurity_guidance.md for SBOM format examples and threat modeling templates.


Resources

scripts/
Script Purpose
fda_submission_tracker.py Track 510(k)/PMA/De Novo submission milestones and timelines
qsr_compliance_checker.py Assess QMS documentation against the legacy-QSR checklist mapped to ISO 13485:2016 (QMSR)
hipaa_risk_assessment.py Evaluate HIPAA safeguards in medical device software
references/
File Content
fda_submission_guide.md 510(k), De Novo, PMA submission requirements and checklists
qsr_compliance_requirements.md Historical QSR structure with QMSR/ISO 13485:2016 mapping, implementation templates
hipaa_compliance_framework.md HIPAA Security Rule safeguards and BAA requirements
device_cybersecurity_guidance.md FDA cybersecurity requirements, SBOM, threat modeling
fda_capa_requirements.md CAPA process, root cause analysis, effectiveness verification
Usage Examples
# Track FDA submission status
python scripts/fda_submission_tracker.py /path/to/project --type 510k

# Assess QMS documentation (legacy QSR section keys, mapped to ISO 13485 under QMSR)
python scripts/qsr_compliance_checker.py /path/to/project --section 820.30  # legacy checklist key = ISO 13485 §7.3 (design & development)

# Run HIPAA risk assessment
python scripts/hipaa_risk_assessment.py /path/to/project --category technical
1---
2name: "fda-consultant-specialist"
3description: FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QMSR (21 CFR 820, which incorporates ISO 13485:2016 by reference since 2026-02-02; formerly QSR) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QMSR, QSR, ISO 13485 for FDA, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity.
4---
5 
6# FDA Consultant Specialist
7 
8FDA regulatory consulting for medical device manufacturers covering submission pathways, the Quality Management System Regulation (QMSR, 21 CFR Part 820 — formerly the QSR), HIPAA compliance, and device cybersecurity requirements.
9 
10## Table of Contents
11 
12- [FDA Pathway Selection](#fda-pathway-selection)
13- [510(k) Submission Process](#510k-submission-process)
14- [QMSR Compliance (formerly QSR)](#qmsr-compliance-formerly-qsr)
15- [HIPAA for Medical Devices](#hipaa-for-medical-devices)
16- [Device Cybersecurity](#device-cybersecurity)
17- [Resources](#resources)
18 
19---
20 
21## FDA Pathway Selection
22 
23Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.
24 
25### Decision Framework
26 
27```
28Predicate device exists?
29├── YES → Substantially equivalent?
30│ ├── YES → 510(k) Pathway
31│ │ ├── No design changes → Abbreviated 510(k)
32│ │ ├── Manufacturing only → Special 510(k)
33│ │ └── Design/performance → Traditional 510(k)
34│ └── NO → PMA or De Novo
35└── NO → Novel device?
36 ├── Low-to-moderate risk → De Novo
37 └── High risk (Class III) → PMA
38```
39 
40### Pathway Comparison
41 
42| Pathway | When to Use | Timeline | User Fee (FY2024) |
43|---------|-------------|----------|-------------------|
44| 510(k) Traditional | Predicate exists, design changes | 90 days | $21,760 (FY2024) |
45| 510(k) Special | Manufacturing changes only | 30 days | $21,760 (FY2024) |
46| 510(k) Abbreviated | Guidance/standard conformance | 30 days | $21,760 (FY2024) |
47| De Novo | Novel, low-moderate risk | 150 days | $134,676 (FY2024) |
48| PMA | Class III, no predicate | 180+ days | $425,000+ (FY2024) |
49 
50> User fees are set annually under MDUFA. Verify current-fiscal-year fees at fda.gov (MDUFA user fee schedule) before budgeting; small-business rates differ.
51 
52### Pre-Submission Strategy
53 
541. Identify product code and classification
552. Search 510(k) database for predicates
563. Assess substantial equivalence feasibility
574. Prepare Q-Sub questions for FDA
585. Schedule Pre-Sub meeting if needed
59 
60**Reference:** See [fda_submission_guide.md](references/fda_submission_guide.md) for pathway decision matrices and submission requirements.
61 
62---
63 
64## 510(k) Submission Process
65 
66### Workflow
67 
68```
69Phase 1: Planning
70├── Step 1: Identify predicate device(s)
71├── Step 2: Compare intended use and technology
72├── Step 3: Determine testing requirements
73└── Checkpoint: SE argument feasible?
74 
75Phase 2: Preparation
76├── Step 4: Complete performance testing
77├── Step 5: Prepare device description
78├── Step 6: Document SE comparison
79├── Step 7: Finalize labeling
80└── Checkpoint: All required sections complete?
81 
82Phase 3: Submission
83├── Step 8: Assemble submission package
84├── Step 9: Submit via eSTAR
85├── Step 10: Track acknowledgment
86└── Checkpoint: Submission accepted?
87 
88Phase 4: Review
89├── Step 11: Monitor review status
90├── Step 12: Respond to AI requests
91├── Step 13: Receive decision
92└── Verification: SE letter received?
93```
94 
95### Required Sections (21 CFR 807.87)
96 
97| Section | Content |
98|---------|---------|
99| Cover Letter | Submission type, device ID, contact info |
100| Form 3514 | CDRH premarket review cover sheet |
101| Device Description | Physical description, principles of operation |
102| Indications for Use | Form 3881, patient population, use environment |
103| SE Comparison | Side-by-side comparison with predicate |
104| Performance Testing | Bench, biocompatibility, electrical safety |
105| Software Documentation | Level of concern, hazard analysis (IEC 62304) |
106| Labeling | IFU, package labels, warnings |
107| 510(k) Summary | Public summary of submission |
108 
109### Common RTA Issues
110 
111| Issue | Prevention |
112|-------|------------|
113| Missing user fee | Verify payment before submission |
114| Incomplete Form 3514 | Review all fields, ensure signature |
115| No predicate identified | Confirm K-number in FDA database |
116| Inadequate SE comparison | Address all technological characteristics |
117 
118---
119 
120## QMSR Compliance (formerly QSR)
121 
122Quality Management System Regulation (QMSR) requirements for medical device manufacturers under 21 CFR Part 820.
123 
124> **QMSR transition (effective 2026-02-02):** FDA's QMSR final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate **ISO 13485:2016 by reference** and removed the legacy QSR subsection structure (820.20–820.198). Those subsection numbers are **historical** and no longer exist in the CFR; the corresponding requirements now flow from ISO 13485:2016 clauses plus the retained/renumbered sections 820.10 (requirements, incl. the ISO 13485 incorporation), 820.35 (records), and 820.45 (device labeling and packaging controls). 21 CFR Parts 801, 803, 806, and 830 are unchanged. Legacy QSR numbers below are kept only as a familiar index, each mapped to its current ISO 13485 clause.
125 
126### Key Quality Subsystems (legacy QSR index → current ISO 13485:2016 clause)
127 
128| Legacy QSR Section (historical, pre-2026) | Title | Current authority under QMSR | Focus |
129|-------------------------------------------|-------|------------------------------|-------|
130| 820.20 | Management Responsibility | ISO 13485 §5.1, 5.5, 5.6 | Quality policy, org structure, management review |
131| 820.30 | Design Controls | ISO 13485 §7.3 | Input, output, review, verification, validation |
132| 820.40 | Document Controls | ISO 13485 §4.2.4 | Approval, distribution, change control |
133| 820.50 | Purchasing Controls | ISO 13485 §7.4 | Supplier qualification, purchasing data |
134| 820.70 | Production Controls | ISO 13485 §6.3, 6.4, 7.5 | Process validation, environmental controls |
135| 820.100 | CAPA | ISO 13485 §8.5.2, 8.5.3 | Root cause analysis, corrective actions |
136| 820.181 | Device Master Record | ISO 13485 §4.2.3 (medical device file) + 21 CFR 820.35 | Specifications, procedures, acceptance criteria |
137 
138### Design Controls Workflow (ISO 13485 §7.3; legacy QSR 820.30)
139 
140```
141Step 1: Design Input
142└── Capture user needs, intended use, regulatory requirements
143 Verification: Inputs reviewed and approved?
144 
145Step 2: Design Output
146└── Create specifications, drawings, software architecture
147 Verification: Outputs traceable to inputs?
148 
149Step 3: Design Review
150└── Conduct reviews at each phase milestone
151 Verification: Review records with signatures?
152 
153Step 4: Design Verification
154└── Perform testing against specifications
155 Verification: All tests pass acceptance criteria?
156 
157Step 5: Design Validation
158└── Confirm device meets user needs in actual use conditions
159 Verification: Validation report approved?
160 
161Step 6: Design Transfer
162└── Release to production with DMR complete
163 Verification: Transfer checklist complete?
164```
165 
166### CAPA Process (ISO 13485 §8.5.2/8.5.3; legacy QSR 820.100)
167 
1681. **Identify**: Document nonconformity or potential problem
1692. **Investigate**: Perform root cause analysis (5 Whys, Fishbone)
1703. **Plan**: Define corrective/preventive actions
1714. **Implement**: Execute actions, update documentation
1725. **Verify**: Confirm implementation complete
1736. **Effectiveness**: Monitor for recurrence (30-90 days)
1747. **Close**: Management approval and closure
175 
176**Reference:** See [qsr_compliance_requirements.md](references/qsr_compliance_requirements.md) for the historical QSR structure with full QMSR/ISO 13485:2016 clause mapping.
177 
178---
179 
180## HIPAA for Medical Devices
181 
182HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).
183 
184### Applicability
185 
186| Device Type | HIPAA Applies |
187|-------------|---------------|
188| Standalone diagnostic (no data transmission) | No |
189| Connected device transmitting patient data | Yes |
190| Device with EHR integration | Yes |
191| SaMD storing patient information | Yes |
192| Wellness app (no diagnosis) | Only if stores PHI |
193 
194### Required Safeguards
195 
196```
197Administrative (§164.308)
198├── Security officer designation
199├── Risk analysis and management
200├── Workforce training
201├── Incident response procedures
202└── Business associate agreements
203 
204Physical (§164.310)
205├── Facility access controls
206├── Workstation security
207└── Device disposal procedures
208 
209Technical (§164.312)
210├── Access control (unique IDs, auto-logoff)
211├── Audit controls (logging)
212├── Integrity controls (checksums, hashes)
213├── Authentication (MFA recommended)
214└── Transmission security (TLS 1.2+)
215```
216 
217### Risk Assessment Steps
218 
2191. Inventory all systems handling ePHI
2202. Document data flows (collection, storage, transmission)
2213. Identify threats and vulnerabilities
2224. Assess likelihood and impact
2235. Determine risk levels
2246. Implement controls
2257. Document residual risk
226 
227**Reference:** See [hipaa_compliance_framework.md](references/hipaa_compliance_framework.md) for implementation checklists and BAA templates.
228 
229---
230 
231## Device Cybersecurity
232 
233FDA cybersecurity requirements for connected medical devices.
234 
235### Premarket Requirements
236 
237| Element | Description |
238|---------|-------------|
239| Threat Model | STRIDE analysis, attack trees, trust boundaries |
240| Security Controls | Authentication, encryption, access control |
241| SBOM | Software Bill of Materials (CycloneDX or SPDX) |
242| Security Testing | Penetration testing, vulnerability scanning |
243| Vulnerability Plan | Disclosure process, patch management |
244 
245### Device Tier Classification
246 
247**Tier 1 (Higher Risk):**
248- Connects to network/internet
249- Cybersecurity incident could cause patient harm
250 
251**Tier 2 (Standard Risk):**
252- All other connected devices
253 
254### Postmarket Obligations
255 
2561. Monitor NVD and ICS-CERT for vulnerabilities
2572. Assess applicability to device components
2583. Develop and test patches
2594. Communicate with customers
2605. Report to FDA per guidance
261 
262### Coordinated Vulnerability Disclosure
263 
264```
265Researcher Report
266 ↓
267Acknowledgment (48 hours)
268 ↓
269Initial Assessment (5 days)
270 ↓
271Fix Development
272 ↓
273Coordinated Public Disclosure
274```
275 
276**Reference:** See [device_cybersecurity_guidance.md](references/device_cybersecurity_guidance.md) for SBOM format examples and threat modeling templates.
277 
278---
279 
280## Resources
281 
282### scripts/
283 
284| Script | Purpose |
285|--------|---------|
286| `fda_submission_tracker.py` | Track 510(k)/PMA/De Novo submission milestones and timelines |
287| `qsr_compliance_checker.py` | Assess QMS documentation against the legacy-QSR checklist mapped to ISO 13485:2016 (QMSR) |
288| `hipaa_risk_assessment.py` | Evaluate HIPAA safeguards in medical device software |
289 
290### references/
291 
292| File | Content |
293|------|---------|
294| `fda_submission_guide.md` | 510(k), De Novo, PMA submission requirements and checklists |
295| `qsr_compliance_requirements.md` | Historical QSR structure with QMSR/ISO 13485:2016 mapping, implementation templates |
296| `hipaa_compliance_framework.md` | HIPAA Security Rule safeguards and BAA requirements |
297| `device_cybersecurity_guidance.md` | FDA cybersecurity requirements, SBOM, threat modeling |
298| `fda_capa_requirements.md` | CAPA process, root cause analysis, effectiveness verification |
299 
300### Usage Examples
301 
302```bash
303# Track FDA submission status
304python scripts/fda_submission_tracker.py /path/to/project --type 510k
305 
306# Assess QMS documentation (legacy QSR section keys, mapped to ISO 13485 under QMSR)
307python scripts/qsr_compliance_checker.py /path/to/project --section 820.30 # legacy checklist key = ISO 13485 §7.3 (design & development)
308 
309# Run HIPAA risk assessment
310python scripts/hipaa_risk_assessment.py /path/to/project --category technical
311```
312 

Discussion

Alternatives

Also in Regulation & privacySee all 23 in Legal & compliance →
Gdpr data handlingImplement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.Business & ops · MITPci complianceImplement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.Business & ops · MIT/cs:ciso-review — CISO Forcing Questions/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.Business & ops · MITCompliance OS — Meta-OrchestratorCompliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).Business & ops · MIT