Resources

Weekly Medical Device Cybersecurity Briefing

Published every week: what's changing in regulation and standards, what it means for manufacturers, and the deadlines worth putting on your calendar. Compiled from primary regulatory and standards sources.

Upcoming Deadlines

What's on the calendar

Tracked as of the August 23, 2026 issue — refreshed every week.

30 Aug 2026 (proposed slip to 31 Oct 2026) 7d

EU CRA - horizontal Type A/B harmonised-standard drafts due

European Union
11 Sep 2026 19d

EU CRA - vulnerability & incident reporting obligations begin

European Union
14-18 Sep 2026

30th IMDRF Management Committee Meeting

IMDRF member jurisdictions
Early-to-mid Oct 2026 (est.) 39d

ISO/IEC 27090 formal publication

Global / ISO-IEC
Q4 2026 (TBD)

NIS2 - continued national transposition and CJEU enforcement

EU member states
Late 2026 (TBD)

IMDRF - Cybersecurity Controls & Testing guidance

IMDRF member jurisdictions
Early-to-mid 2027 (forecast)

IEC 62304 Edition 2 - publication

Global / IEC
Early 2027 (TBD)

UK MHRA - Future Regulation of Medical Devices cybersecurity requirements

United Kingdom
11 Dec 2027

EU CRA - main obligations apply

European Union
Latest issue

August 23, 2026

Coverage period: 17 August – 23 August 2026

This week was quiet on the regulatory front, so the briefing covers one substantive story: ISO/IEC 27090 (the AI cybersecurity standard) cleared its final ballot on 19 August and is now heading to publication — below is the breakdown of what it covers and what AI/ML medical device manufacturers should do now. There are changes in the calendar items too, with a new entry on the EU CRA’s harmonised-standards timeline slipping, plus the 30th IMDRF meeting and the 27090 publication date.

1. ISO/IEC 27090 AI Cybersecurity Standard Clears Final Ballot, Moves to Publication

The Final Draft International Standard (FDIS) ballot for ISO/IEC 27090, Cybersecurity — Artificial Intelligence — Addressing security threats and compromises to artificial intelligence systems, closed on 19 August 2026. ISO’s public lifecycle record now shows the document at stage 60.00, “International Standard under publication,” with final production steps expected to take up to seven weeks — putting formal publication around early-to-mid October 2026.

What the standard covers

Developed by ISO/IEC JTC 1/SC 27 (the committee responsible for the ISO 27000 information-security family), ISO/IEC 27090 is built around three substantive chapters. The first addresses how to apply core information-security principles — secure-by-design, zero trust, AI-specific governance, supply-chain traceability via an “AI Bill of Materials,” and data-minimization — across an AI system’s full lifecycle. The second catalogs threats specific to AI models: data poisoning, evasion attacks, membership inference, model inversion and exfiltration, direct model theft, training-data leaks, prompt injection, and output-injection attacks such as embedded cross-site scripting. The third sets out ten categories of mitigation measures, including monitoring for model degradation, securing the development environment, detecting anomalous or out-of-distribution inputs, and rate-limiting to blunt scraping and reverse-engineering attempts. The standard also distinguishes the obligations of an AI “provider” (the entity developing or marketing the model) from those of an “integrator” or deployer — a split that mirrors the role structure used in the EU AI Act. It is a guidance document rather than a certifiable management-system standard: adopting it does not by itself generate a presumption of conformity with the EU AI Act or the Cyber Resilience Act, and it is meant to complement, not replace, ISO/IEC 42001 (certifiable AI management systems) and ISO/IEC 42005 (AI impact assessment).

Manufacturer relevance

Manufacturers building AI- or ML-enabled software as a medical device now have a purpose-built threat taxonomy and control catalog for risks that existing device-security standards — IEC 62304, IEC 81001-5-1, ISO 14971 — do not explicitly enumerate, such as training-data poisoning in a diagnostic model’s development pipeline or model inversion that could re-expose patient data used in training. Because the EU AI Act’s obligations for high-risk AI systems (which include many AI-enabled medical devices) began applying from 2 August 2026, and because FDA’s premarket cybersecurity expectations already call for documented threat modeling and a security risk management report, manufacturers developing AI/ML SaMD should start mapping current AI threat models against the FDIS text now rather than waiting for the formal published version in October, since the underlying content is not expected to change materially between FDIS and publication. Citing ISO/IEC 27090 alongside ISO/IEC 42001 and ISO/IEC 42005 in premarket submissions and design-history documentation offers a defensible, internationally recognized way to demonstrate AI-specific threat coverage even though none of the three alone satisfies a conformity-assessment checkbox on its own.

Sources: ISO/IEC 27090 - ISO, lifecycle updated 19 August 2026; ISO 27090: Understanding the Future Cybersecurity Standard for AI Systems - FeelAgile

Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.

Want this tailored to your regulatory strategy?

Talk to our team about what recent developments mean for your specific device and timeline.

Schedule a Consultation