Company · Quality

Quality you can check.

Sales, development and manufacturing of electronic and electromechanical assemblies and systems are certified to ISO 9001. Our information security management system is built to ISO/IEC 27001 and is currently going through certification.

Evidence

Certificates

Certification status, with registration number, scope and validity.

  • ISO 9001:2015

    Certified
    Details of the ISO 9001:2015 evidence
    IssuerTÜV SÜD Management Service GmbH
    Registration no.12 100 67760 TMS
    ScopeSales, development and manufacturing of electronic and electromechanical assemblies and systems
    Valid untilJune 18, 2027
  • ISO/IEC 27001:2022

    In certification audit

    The information security management system is built to ISO/IEC 27001 and is run and audited together with quality management. There is no certificate yet.

Evidence

Standards and management system

  • Standards we develop to

    Our management system conforms to ISO 13485. IEC 62304 and ISO 14971 for medical devices, IEC 61508 and ISO 13849 for safety-related systems, IEC 62443 and the Cyber Resilience Act for connected devices. We work to these standards. Neither a product nor the company is certified by that; product approval stays with the manufacturer.

  • Integrated management system

    Quality and information security run in one integrated management system: one document control, one joint internal audit per year, one management review. The manual is kept as Markdown in Git and is versioned and reviewed like source code.

Development

How quality is built into a project

  • Requirements traced to test results

    Every system requirement leads to software requirements, test cases and test results. In medical and safety projects this chain is demonstrable in both directions and is part of the evidence package as a baseline.

  • Four eyes on every merge request

    No code is integrated without review by a second person. The pipeline builds, runs static analysis and tests; if a step fails, it blocks the merge.

  • Reviews at phase transitions

    Design reviews before architecture decisions, sprint or milestone reviews on a fixed cadence. For medical devices, every phase transition is a documented gate review with entry and exit criteria.

  • Independent verification for safety

    Whoever created a safety-relevant artefact does not verify it. Static analysis to MISRA, test coverage by SIL level, FMEDA for the hardware. Who checks what is set out in the project's safety plan.

To verification

Release

When something ships to you

A release or an acceptance is only approved once four conditions are met. Every approval records who granted it, when, and for which build.

  1. Criteria met

    Definition of done, pipeline without blocking errors, all code reviews closed, internal system test passed.

  2. Open items assessed

    Known defects are classified. No critical or major defect is left without a plan to fix it.

  3. Release notes and evidence

    Release notes, test report and, for medical and safety projects, the evidence package for the baseline with version and commit.

  4. Your acceptance

    You approve after a passed system test. CE marking and the technical file stay with the manufacturer; we deliver our contributions to them.

Management system

What the system also covers

  • Suppliers

    Assembly houses, component suppliers and external service providers are assessed before being commissioned and kept in the supplier register. Every purchase order is approved, above 5,000 euros by two people.

  • Traceability

    Every assembly carries a qde serial number and is tracked in Odoo, including customer-supplied ones. Software releases are tied to a Git tag; build artefacts carry version and commit hash.

  • Customer property

    Source code, keys, test equipment and data are stored with access limited to project members. After the project we return or verifiably delete them, as agreed in the contract.

  • Audit and improvement

    Once a year an internal audit covering quality and information security together, in the fourth quarter the management review. Anyone can log an improvement directly as a task, with no approval needed.

Supplier audit

Questions purchasing and quality teams ask

Can we audit you?

Yes, on site in Offenburg or remotely. You see the management system manual and the evidence for your project: requirements, reviews, test reports, approvals.

Are you certified to ISO 13485?

We are certified to ISO 9001; beyond that, our management system conforms to ISO 13485. We develop electronics and software for medical devices to IEC 62304 and ISO 14971 as a supplier. Manufacturer responsibility, technical file and CE marking stay with you.

What happens if a defect shows up after delivery?

Every nonconformity is recorded and classified. A critical defect after delivery always triggers a root cause analysis, with a corrective action and a check that it worked.

Who is responsible for quality and information security?

Florian Seibold, who is managing director and quality management representative. For safety projects, a functional safety manager is appointed in addition.

Read on

  • About qde

    Who we are and how we work.

  • Verification

    Test setups, evidence and traceability as a service.

  • Functional safety

    Development to IEC 61508 and ISO 13849.

  • Cyber security

    IEC 62443 and the Cyber Resilience Act in product development.

Your contact

Quality we are proud of.

Our management system is as short as the standard allows and as precise as the product demands. Auditors and customers tell us they value that. Florian Seibold is responsible for the system as managing director. Write to him if you need the certificate, excerpts from the manual or an audit date.

Florian Seibold

Managing Director

info@querdenkerengineering.de

+49 7807 890 80 10