And What About Us? Yes, we, PragmaCert Ltd, are in the middle of a REAL quality management definition & implementation initiative adapted to the size & the needs of our small company and we don't want an ISOxxxxx certificate to be part of the "ISO Butchery".

We already work with state-of-the-art practices and tools, just like we use to do it with our clients, we just need to formalize it in our QMS handled mainly under Confluence and Google Drive as stated in the following section.

We have 2 kind of objectives, at corporate level and at individual one.

For the objectives at individual level, please refer to the Continuous Certification/Training page where we describe our certification strategy quite in details.

Regarding the objectives at corporate level, the size of the company makes it quite simple: the ISO9001:2015 certification is the one that we need first and that will allow us to make the difference with the other competitors with a similar size. The timing is still difficult to define due to the typical constraints of our jobs which is "work anytime, anywhere!", therefore it's quite hard to know when we'll get the required time to define the Quality Management System (QMS), even though numerous documentation and management, finance, admin, auditing, configuration/version management and technological state-of-art tools and practices are already in place.

We are now in a bottom-up approach where a lot of policies/procedures, practices, tools are in place but we need to document the related processes required by the ISO9001:2015 standard to formalize a corporate QMS which we'll continuously improve. And let's be honest, we need to perform a Gap Analysis which will identify still quite a lot of QMS items and practices that are missing to completely cover the ISO9001:2015 standard.

Antoine, our Managing Director, would like to achieve this certification by the end of 2025, considering he's got a strong experience in both definining / implementing ISO9001:2015 from scratch and auditing/maintaining the compliance with this standard. He is also attending the IRCA accredited ISO9001 Lead Auditor training course and exam Mid-July 2025 in order to be able to properly implement the standard within PragmaCert and of course to provide official ISO9001 Audits to our clients.

Then, another certification that would make sense for our company is the ISO27001:2022 information security compliance. We work with clients that handle very sensitive data (may require secret clearance or similar process) and we must show that we have a strong ISMS (Information Security Management System) which protects PragmaCert and its clients from any security breach, hacking, etc. One of our PragmaCert Team Member, Jesus, is a certified ISO27001 Lead Implementer (TÜV SÜD); on my side, I've already performed a Security Audit on an Air Transport Management System against an ISO27001 compliant ISMS, I've documented a common ISO21434 & ISO26262 compliant Item definition for the "Motor Control" Item of an Electric/Hydrogen Powertrain as main input to the HARA and TARA in collaboration with a young FuSa & CS Engineer working under my supervision and I performed a detailed review of the "ASPICE for Cybersecurity" standard (on top of that, I stated in the continuous training program page, I already registered for the Automotive Cybersecurity Training Course on Udemy website thanks to my annual subscription) so we already have the required skills in-house to help us!

Our Quality Management System is, at the moment, composed of:

Leadership Process - Management Policies:

  • COMPANY MANAGEMENT POLICY for PRAGMACERT CONSULTANT ENGAGEMENT, ORGANIZATION CONTINUOUS IMPROVEMENT & CUSTOMER SATISFACTION:

    • The 7 Key Mindset Values:

      • COMMON SENSE over politics & corporatism;

      • STATE-OF-THE-ART METHODS & TOOLS over conservatism;

      • PRAGMATISM & FLEXIBILTY WITHIN AN APPROVED PROCESS FRAMEWORK over legacy "set-in-stone" rules and chao;

      • SPEAKING WITH DATA & FORMALIZING rather than 'thinking/believing' and meeting without writing formal reports/MoMs;

      • TAKING & KEEPING YOUR COMMITMENTS rather than never making/updating plans;

      • BEING ALWAYS UP-TO-DATE ON WHAT'S HAPPENING ON THE FIELD (GEMBA) rather than at artificial intelligence conferences and 4-stars hotels

      • PROVIDING ALL (INT/EXT) STAKEHOLDERS WITH COMPLETE VISIBILITY and with an INTERNATIONAL MINDSET instead of maintaing opacity at all levels of the organization

  • Code of Ethics and Professional Conduct: defines the ethical and professional requirements that a PragmaCert Team Member shall comply with when providing PRAGMARC services to our clients (Performance Improvement, Reviews, Audits/Assessments/Appraisals, Guidance for Management Approach, Risk Mitigation & Certification); the main topics are professionalism, conflict of interest, objectivity, data integrity, confidentiality, adaptability, respect for intellectual property, security, respect for the audited organization, and each of its members.

  • PRAGMARC Requirements Procedure: defines the minimum technical requirements that a PragmaCert Team Member shall comply with when providing PRAGMARC services to our clients (Performance Improvement, Reviews, Audits/Assessments/Appraisals, Guidance for Management Approach, Risk Mitigation & Certification): this will typically includes, as stated in the home page, a strong experience on the field (we don't "tick-the-box" consultants), a relevant set of certifications from accredited certification bodies (VDA-QMC, TÜV, PMI, IRCA, etc.) and successful professional experience in the fields of auditing/assessment/performance improvement/coaching/training against the main applicable standards/models/regulations in Quality Assurance, Functional Safety, Cybersecurity, Management, Agility (SCRUM, SAFe), French & UK GAAP, etc.

  • Company Website - Home Page Introduction with a Clear Company Business Strategy including the Rejection of both Stagnation with the Continuous Training & Certification program and the ISO/Quality/Safety Butchery, a Transparent Top Manager Culture (Asperger's for Excellence), a Ethics page where the "Code of Ethics and Profesionnal Conduct", integral part of PragmaCert Ltd QMS is addressed and a dedicated page to the on-going implementation of a Management System

Support Process - Documentation/Configuration Management System (including storage, versioning, baselining, archiving, retrieving of the QMS items):

  • Google Drive including online templates for:

    • QA/FuSa/CS services Legal Offer (Terms & Conditions covering UK & European regulations)

    • Engineering & Safety Advisor services Legal Offer (Terms & Conditions covering UK & European regulations)

    • Web Development services Legal Offer (Terms & Conditions covering UK & European regulations)

    • Technical & Financial Offer (for Tendering process purpose - before establishing legal offer)

    • A folder dedicated to the active and applicable standards that PragmaCert uses for its services: ISO9001, ISO9001, ISO19011, ISO17021, IAF MD5, ECSS Active Standards, ISO26262, IEC61508, EN50126, EN50128, etc.

  • Confluence

    • Introduction to PragmaCert QMS

    • Draft of QMM

    • Draft of Process Map

Support Process - Finance/Accountancy/Sales/Quote/Invoicing/Time Tracking/Customer Approval Online Management System:

  • Zoho Books including different online templates for different types of services:

    • QA/FuSA/CS services quote, timesheet & invoice templates

    • Engineering & Safety Advisor services quote & invoice templates

    • Web Development services quote & invoice templates

Operation Process - Quality/Safety Auditing System:

  • SafetyCulture ALM including online templates for:

    • ISO9001:2015, IATF16949:2016, ISO27001:2022, AS9102 Form 1/2/3, ISO13485:2016, ISO14001:2015 Audit Checklists & Reports

    • Started to manually create template for ECSS SW Product Assurance Audit ECSS-Q-ST-80C Rev.1 checklist (objective would be to collborate with buho AI startup or another one to fill in SafetyCulture ALM checklists automatically with the missing standards like ASPICE/ISO15504, CMMI, ECSS, DO178C, EN5012X, IEC60128, etc using their adapted AI tool

    • EN50128:2011 Assessment Checklist in Excel format

Operation Process - Engineering / R&D / Product Development:

  • ENCO SOX (System Design and Safety/Security Tool):

    • Official Partnership between the Managing Director of this German SW Company and Antoine, our Managing Director (who selected SOX as the MBSE/MBSA tool when he used to be in charge of creating the Functional Safety Department in QEV Technologies) which allows us to get (on an as needed basis) a free license of the full workbench of this very interesting MBSE/MBSA/HARA/TARA/FMEA/FTA/FMEDA tool used by very well-established industrial companies like BOSCH, HARMAN, EMBITEL...

  • "Generic MBSA Process for the Concept Phase from Item Definition to HARA and FSC using SysML". Implementation of this process on an ISO26262 ASILD "Motor Control" Item of an Hybrid Electric/Hydrogen Powertrain and for the documentation of a Proof of Concept for the tendering process on EN50128 SIL4 IXL Gateway SW RFQ from a major confidential Rail OEM (see an extract of this PoC without the HARA)

  • NI LabView Community: free version of LabView that we will use in our Pragma::SafeV&V project (see introduction)

  • NUCLEO-F103RB HW board with STM32F103 microcontroller: initially acquired to perform the training course from Openclassroom website Develop in C for Embedded Software prepared by the INSA Toulouse and the Ecole Centrale de Nantes, it is also used to emulate a generic ECU for the Pragma::SafeV&V project (see introduction)

  • Keil µVision5: Open Source IDE used in the training course from Openclassroom website Develop in C for Embedded Software prepared by the INSA Toulouse and the Ecole Centrale de Nantes

  • Code::Blocks: Open Source IDE used in the training course from Openclassroom website C programming

  • WordPress & Elementor (+HTML/CSS programming): used by the "web design and security team" to design, develop and maintain professional websites for our clients

  • Hostinger WebBuilder (+HTML/CSS programming): used by the "web design and security team" to design, develop and maintain professional websites for our clients

  • Titan Mail: used by the "web design and security team" to provide our clients with a secured and professional email account (as opposed to Gmail, Hotmail, etc.) associated with their website

  • ... To be continued

Planning Process - Internal & External Tasks/Risks/Issues Management

  • ClickUp: Online Project Management tool allowing internal management of the tasks, risks, issues, changes and bugs as well as the tracking of the customer requests/issues during the different phases of the project:

    • Proposal, Offer/Quote, Mockup, Beta release, Final release, corrective and evolutive maintenance in case of web development services

    • Proposal, Offer/Quote, Readiness Review, Audit/Assessment/Appraisal in case of auditing services

    • etc.

Performance Evaluation Process - Internal & External Continuous Assessment and corrective action

  • SafetyCulture ALM will be used to perform regular internal audit against ISO9001:2015 and our internal QMS:

    • ISO9001:2015, ISO 9000-2015, ISO 19011-2018, ISO_IEC 17021-1_2015 are all available on our Documentation Management System (Google Drive) to perform the internal audit properly

    • ISO9001:2015 Audit checklist & report templates are available in SafetyCulture ALM

    • We need to select the best stakeholder to perform the internal audits