A gap assessment asks one question per artifact: can you trace it to the standard that requires it, and forward to the decision it justifies?
Five standards feed one traceable chain: ISO 13485 (QMS and design controls), IEC 62304 (software lifecycle), ISO 14971 (risk management), AAMI SW96 (cybersecurity) and IEC 62366 (usability engineering). All of their artifacts have to trace into a single DHF.
The DHF is not a folder. It is a traceable evidence chain.
Where gaps hide
- DFMEA disconnected from architecture. Failure modes don't map to software items. ISO 14971 and IEC 62304 operate in separate documents with no shared thread.
- Risk controls in code, not in the RMF. Network segmentation, stateless tokens and failure-domain isolation are implemented, but nothing in the DHF shows they exist as formal risk controls.
- An incomplete SOUP assessment. Libraries named without versions, anomaly assessments or risk justification. Half complete is non-compliant under IEC 62304.
- UAT mistaken for summative validation. The interface was tested, but no critical tasks were defined and there is no use error analysis. The Usability Engineering File is missing from the DHF entirely.
The engineering work was done. The decisions were sound. What was missing was the traceable evidence connecting the work to the standard that required it.
Seen this differently?
Questions, corrections and counterexamples are welcome.


