Executive Summary
This week’s medical device cybersecurity landscape was dominated by the publication of landmark MITRE research papers on evolving cyber risks (AI, cloud, and post-quantum). Regulatory compliance deadlines continue to intensify, with EUDAMED mandatory modules arriving May 28, 2026, and the EU AI Act’s major provisions set for August 2026. Manufacturers should treat this week’s developments as a call to action across their supply chains, SBOMs, incident response plans, and AI governance frameworks.
1. U.S. FDA — Regulatory Updates
1.1 Cybersecurity Premarket Guidance Aligned with QMSR (February 2026)
The FDA published a revised Cybersecurity in Medical Devices guidance on February 3, 2026, replacing the June 2025 version. The update does not introduce new technical requirements; instead it re-aligns all regulatory cross-references from 21 CFR Part 820 to the corresponding clauses of ISO 13485:2016, which is now incorporated by reference into the FDA Quality Management System Regulation (QMSR). The QMSR took full effect in February 2026, fundamentally restructuring FDA quality system requirements for device manufacturers.
Core elements carried forward from prior versions include:
Secure Product Development Framework (SPDF) as the overarching lifecycle approach.
Threat Modeling, Security Architecture documentation, and Security Risk Management Reports.
Software Bill of Materials (SBOM) requirement for all ‘cyber devices’.
Fourteen cybersecurity documentation deliverables expected in premarket submissions.
Coordinated Vulnerability Disclosure (CVD) processes and postmarket patch management plans.
Manufacturer Action: Manufacturers should update their Design History Files and QMS procedures to reference ISO 13485 clauses rather than 21 CFR 820 sub-sections. Premarket submissions filed after the QMSR effective date must reflect the updated cross-references to avoid rejection.
1.2 QMSR Integration & ISO 13485 Alignment
The convergence of the FDA QMSR with ISO 13485:2016 creates a de-facto harmonised international standard for quality and cybersecurity documentation. Manufacturers already certified to ISO 13485 will find the transition largely procedural, but gap analyses should verify that cybersecurity risk management activities are explicitly documented within the ISO 13485 framework rather than the legacy QSR structure. The FDA’s Compliance Program Manual has also been updated to reflect QMSR, meaning inspectors will be evaluating cybersecurity integration against ISO 13485 requirements during Quality System Inspections.
2. IMDRF — International Harmonisation
The International Medical Device Regulators Forum (IMDRF) cybersecurity framework, established in its foundational N60 document (March 2020), continues to serve as the international reference point underpinning regulatory guidance in the U.S., EU, Canada, Australia, Japan, and other major markets. The FDA’s 2026 updated premarket guidance explicitly aligns with or expands upon the IMDRF principles, reducing the compliance burden for manufacturers operating across multiple jurisdictions.
No new IMDRF cybersecurity working group documents were published this week; however, the IMDRF AI working group continues to develop a framework on best practices for AI in medical devices, which will have significant cybersecurity implications when finalised. Manufacturers developing AI-enabled devices should monitor IMDRF outputs closely in Q3 2026.
Manufacturer Action: Maintain a single harmonised cybersecurity technical file that satisfies IMDRF N60, FDA SPDF, and MDCG 2019-16 simultaneously. This avoids duplicative documentation across regulatory submissions.
3. EU — MDCG & EUDAMED Developments
3.1 EUDAMED Mandatory Modules — May 28, 2026 Deadline
The European Commission has confirmed that the first four EUDAMED modules will become mandatory for use as of May 28, 2026 — just 24 days away. The four mandatory modules are: Actor Registration, UDI/Device Registration, Notified Bodies & Certificates, and Market Surveillance. New devices placed on the EU market on or after that date must be fully registered in EUDAMED prior to placement.
While EUDAMED itself is not a cybersecurity-specific requirement, the registration data infrastructure is critical for postmarket surveillance and vigilance reporting — both of which intersect with cybersecurity incident reporting obligations under the MDR. Incomplete EUDAMED registration could impede a manufacturer’s ability to comply with cybersecurity incident reporting timelines.
Manufacturer Action: Verify that all EU-marketed devices are registered in EUDAMED before May 28. Assign a responsible person for ongoing EUDAMED data maintenance as part of postmarket cybersecurity surveillance.
3.2 MDCG 2019-16 — Current Cybersecurity Framework Status
No new MDCG cybersecurity guidance was published this week. MDCG 2019-16 remains the operative EU cybersecurity guidance document. Notified Bodies are increasingly scrutinising cybersecurity technical documentation in 2026, with missing or inadequate security documentation identified as one of the top five causes of Notified Body major non-conformities for Software as a Medical Device (SaMD). Manufacturers are advised to treat MDCG 2019-16 compliance as a minimum baseline.
3.3 EU AI Act — Cybersecurity Implications for AI-Enabled Devices
The majority of EU AI Act provisions come into force on August 2, 2026. For AI-enabled medical devices classified as ‘high-risk AI systems’, the AI Act introduces mandatory cybersecurity requirements that partially overlap with, but go beyond, MDCG 2019-16. Key cybersecurity obligations include:
Technical measures to prevent and control data poisoning attacks on AI training datasets.
Defences against adversarial input attacks designed to trick AI models.
Operational resilience requirements and cybersecurity risk assessments throughout the device lifecycle.
Human oversight mechanisms to detect and respond to AI-specific security failures.
The EU has signalled a preference for governing AI medical devices under existing MDR/IVDR frameworks rather than creating a separate AI regulatory pathway, reducing duplication but requiring manufacturers to integrate AI Act cybersecurity requirements into existing MDR technical files.
Manufacturer Action: Begin AI Act gap analyses now, particularly for AI-enabled SaMD products. Map AI Act cybersecurity obligations to existing MDCG 2019-16 and IEC 81001-5-1 controls to identify gaps before the August 2026 deadline.
4. MITRE — New Cybersecurity Risk Research (April 22, 2026)
MITRE published two significant documents on April 22, 2026, directly relevant to medical device manufacturers navigating AI, cloud, and post-quantum cryptography adoption.
4.1 Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies
This MITRE discussion paper maps how shared-responsibility gaps between device makers, health systems, and cloud providers create patient safety exposure. Key findings include:
Cloud Dependency Risk: As manufacturers shift device functionality to cloud platforms, single points of failure can cascade across dozens or hundreds of healthcare organisations simultaneously. MITRE cites the Elekta incident as a preview of how cloud infrastructure failures can interrupt patient care at scale.
AI/ML Component Threats: AI components embedded in medical devices introduce unique attack surfaces including model poisoning, inference attacks, and adversarial inputs that traditional cybersecurity controls may not address.
Post-Quantum Cryptography: Manufacturers should begin inventorying cryptographic algorithms used in device firmware and communications to prepare for post-quantum migration.
4.2 SBOM Data Normalisation White Paper
MITRE’s companion white paper, ‘Considerations for Managing Challenges in Software Bill of Materials (SBOM) Data Normalization,’ identifies significant inconsistency across SBOM generation tools that impedes efficient vulnerability management. MITRE’s recommendations for manufacturers:
Maintain a central ‘source of truth’ with canonical supplier names, component names, versions, and unique identifiers.
Include cloud-hosted components in device SBOMs — not just on-premises or embedded code.
Incorporate AI/ML models, cloud APIs, and cryptographic libraries explicitly into SBOMs and threat models.
Apply the principle of least privilege to AI components to limit attack surface.
Manufacturer Action: Review SBOM generation toolchains against MITRE’s normalisation recommendations. Ensure cloud components are captured in SBOMs submitted with FDA premarket applications and provided to healthcare customers for their asset management programmes.
5. Standards Landscape — IEC & ISO Updates
5.1 IEC 81001-5-1 — Health Software Security Lifecycle
IEC 81001-5-1 (EN IEC 81001-5-1:2022) remains the current international state of the art for health software cybersecurity lifecycle requirements. It is now cross-referenced in FDA cybersecurity guidance, enforced in Japan since 2024, and required under EU MDR for SaMD. Manufacturers not applying this standard must provide explicit justification in their technical files. No amendments were published this week.
5.2 IEC TS 81001-2-2:2025 — Security Communication Between Manufacturers and Operators
This technical specification, published in 2025, defines how manufacturers should communicate security needs, risks, and controls to healthcare operators. It complements the MDS2 (Manufacturer Disclosure Statement for Medical Device Security) format and provides a structured approach to postmarket security communication. Manufacturers should ensure their product security documentation packages align with this specification when provided to hospital customers.
5.3 IEC 62304 — Forthcoming Revision (Expected September 2026)
IEC 62304, the foundational standard for medical device software lifecycle processes, is under revision with publication expected in September 2026. The update is anticipated to incorporate modern secure development practices and align more closely with the ISO Harmonised Structure adopted by other management system standards. Manufacturers should monitor the FDIS stage for final content and begin gap analyses against their current software development processes.
5.4 ISO 13485 — Next Review Cycle in 2026
ISO 13485:2016 is due for its systematic review in 2026. Changes are expected to reflect the new ISO Harmonised Structure and may incorporate additional cybersecurity and digital health considerations. Given the FDA QMSR’s direct incorporation of ISO 13485, any revision will have direct implications for FDA-regulated manufacturers as well as those certified under the EU MDR quality management requirements.
6. Emerging Threat — AI-Powered Cyberattacks on Medical Devices
Multiple industry sources this week highlighted the accelerating risk posed by AI-powered cyberattack tools. Advanced AI models are demonstrably improving attacker capability to identify, chain, and exploit vulnerabilities at speeds that outpace traditional security operations. For medical device manufacturers, this creates two compounding risks:
Faster Vulnerability Exploitation: AI-assisted attack tools can find and exploit device vulnerabilities (including those in deployed legacy devices) significantly faster than manufacturers can develop and deploy patches, narrowing the effective response window.
Automated Attack Customisation: AI models can generate device-specific attack payloads tailored to known firmware versions, communication protocols, and software stacks — reducing the skill barrier for sophisticated attacks against specific device models.
Manufacturer Action: Accelerate TPAT (Total Product Lifecycle) vulnerability monitoring programmes. Implement runtime exploit protection where feasible. Ensure postmarket SBOM refresh cycles are frequent enough to support timely CVE correlation as AI-assisted attack tooling compresses the exploit timeline.
7. Sources & References
FDA Cybersecurity in Medical Devices — Digital Health Center of Excellence — https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
FDA Issues Revised Cybersecurity Premarket Submission Guidance (DLA Piper, Feb 2026) — https://www.dlapiper.com/en-us/insights/publications/2026/02/fda-issues-revised-cybersecurity-premarket-submission-guidance
FDA Reissues Cybersecurity Guidance to Align with QMSR (RAPS, 2026) — https://www.raps.org/news-and-articles/news-articles/2026/2/fda-reissues-cybersecurity-guidance-to-align-with
IMDRF Medical Device Cybersecurity Guide — https://www.imdrf.org/working-groups/medical-device-cybersecurity-guide
IMDRF Drafts Framework on Best Practices for AI in Medical Devices (RAPS) — https://www.raps.org/resource/imdrf-drafts-framework-on-best-practices-for-using-ai-in-medical-devices.html
EUDAMED — Four First Modules Mandatory from 28 May 2026 (European Commission) — https://health.ec.europa.eu/latest-updates/eudamed-four-first-modules-will-be-mandatory-use-28-may-2026-2025-11-27_en
EU MDR & AI Act Compliance for AI Medical Devices (IntuitionLabs) — https://intuitionlabs.ai/articles/ai-medical-device-compliance-eu-mdr-ai-act
MDCG 2019-16 Guidance on Cybersecurity for Medical Devices (European Commission) — https://ec.europa.eu/docsroom/documents/41863
MITRE: Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies (April 2026) — https://www.mitre.org/news-insights/publication/cybersecurity-risk-analysis-medical-devices-era-evolving-technologies
MITRE Flags Rising Cyber Risks as Medical Devices Adopt AI, Cloud and Post-Quantum Technologies (Industrial Cyber) — https://industrialcyber.co/medical/mitre-flags-rising-cyber-risks-as-medical-devices-adopt-ai-cloud-and-post-quantum-technologies/
Medical Device Cybersecurity: MITRE Warns of Cloud Risk (Health System CIO, April 28, 2026) — https://healthsystemcio.com/2026/04/28/medical-device-cybersecurity-cloud-mitre/
AI-Powered Medical Device Cyberattacks Are Coming Faster Than Expected (SoftwareCPR, May 2026) — https://www.softwarecpr.com/2026/05/ai-cyberattack-coming/
Cybersecurity Standards for Medical Software: IEC 81001-5-1 and IEC TR 60601-4-5 (D.med Software) — https://dmed-software.com/cybersecurity-standards-for-medical-software-2025-update/
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.