home / case studies / European healthcare software vendor (composite)
DevOps Platform

CI/CD Modernisation with Compliance Evidence for a Regulated Software Vendor

We replaced a manual, document-heavy release process with automated pipelines that generate compliance evidence as they run. Releases went from a quarterly event to a routine activity.

European healthcare software vendor (composite) · DevOps Platform

CI/CD Modernisation with Compliance Evidence for a Regulated Software Vendor

Challenge

Satisfying auditors that automated evidence was equivalent to (or better than) the previous manual records. We worked with the QA/RA team to map each control to a pipeline artifact and ran parallel releases for two cycles.

Approach

We consolidated legacy Jenkins jobs into GitLab CI pipelines with reusable templates. Each pipeline links commits to requirements and tickets, runs automated test suites, and stores test reports, approvals, SBOMs and deployment records in an immutable evidence store. Release approvals are captured as electronic sign-offs. Blue-green deployments with automated smoke tests and one-click rollback reduced release risk.

Outcome

Illustratively ~60–80% less effort to assemble release evidence Smaller, more frequent releases with lower change-failure rates Full traceability from requirement to deployed build Faster, repeatable rollback Audit preparation shifted from weeks to days

~60–80%Illustratively less effort to assemble release evidence
✓Smaller, more frequent releases with lower change-failure rates
✓Full traceability from requirement to deployed build

Problem solved

Audit requirements meant every release needed weeks of manual evidence gathering, so releases were rare, large and risky.

What we built

We consolidated legacy Jenkins jobs into GitLab CI pipelines with reusable templates. Each pipeline links commits to requirements and tickets, runs automated test suites, and stores test reports, approvals, SBOMs and deployment records in an immutable evidence store. Release approvals are captured as electronic sign-offs. Blue-green deployments with automated smoke tests and one-click rollback reduced release risk.

Benefits

Illustratively ~60–80% less effort to assemble release evidence Smaller, more frequent releases with lower change-failure rates Full traceability from requirement to deployed build Faster, repeatable rollback Audit preparation shifted from weeks to days

GitLab CIJenkins migrationSBOMBlue-green deploymentImmutable evidenceRollback

Talk to us