← All briefings Weekly Briefing

Issue: May 24, 2026

For medical device manufacturers – regulatory, standards, and threat intelligence update

1. United States – FDA

Revised Premarket Cybersecurity Guidance (QMSR-Aligned): Industry Absorption Phase

The FDA’s February/March 2026 revised premarket cybersecurity guidance — issued to align with the Quality Management System Regulation (QMSR) effective February 2, 2026 — continues to be the defining regulatory driver for US submissions. Industry is now in full implementation mode, and this week’s environment reflects intensifying scrutiny in 510(k) and PMA interactions.

Key requirements now in force:

Manufacturers of “cyber devices” must embed cybersecurity into their Quality Management Systems, aligned with ISO 13485:2016 as incorporated by reference into the QMSR.

Premarket submissions must include a Security Risk Management Report and a machine-readable Software Bill of Materials (SBOM) with lifecycle metadata including end-of-support dates.

VEX (Vulnerability Exploitability eXchange) files are required as of March 2026 — manufacturers must accompany SBOMs with VEX data to enable healthcare delivery organizations to rapidly triage newly disclosed vulnerabilities in device software components.

A Secure Product Development Framework (SPDF) must be documented across the total product lifecycle, with security artifacts generated during development rather than retrofitted pre-submission.

A Coordinated Vulnerability Disclosure (CVD) process and a Cybersecurity Management Plan are mandatory postmarket requirements; uncontrolled vulnerabilities must be communicated to customers within 30 days and resolved within 60 days.

Manufacturer Action: Ensure VEX files are integrated into your SBOM submission pipeline. Submissions lacking VEX data alongside SBOMs are increasingly flagged as deficient by FDA reviewers.

2. European Union – MDCG / EC

EUDAMED Four Modules Become Mandatory: May 28, 2026 ✔ Imminent

The European Commission has confirmed that four EUDAMED modules become mandatory for all economic operators effective 28 May 2026 — this Thursday. The four mandatory modules are: Actor Registration, UDI/Device Registration, Notified Bodies and Certificates, and Market Surveillance.

Critical compliance obligations:

All new devices placed on the EU market from 28 May 2026 must be registered in the UDI & Device module before first market placement. Devices not in EUDAMED may not be placed on the market.

All economic operators (manufacturers, authorized representatives, importers, distributors) must have completed Actor Registration and hold a Single Registration Number (SRN) before 28 May 2026.

Legacy devices already on the market before 28 May 2026 have until 28 November 2026 to complete full EUDAMED registration.

Notified Bodies must upload all certificates issued prior to the mandatory date by 28 May 2027.

Urgent: If your organization has not yet completed Actor Registration or obtained an SRN, this is an immediate priority. Any new device not registered in EUDAMED after May 28 cannot be legally placed on the EU market.

EU AI Act: Council and Parliament Agree Provisional Deadline Extensions (May 7, 2026)

On 7 May 2026, the Council of the EU and the European Parliament reached a provisional political agreement on targeted amendments to the EU AI Act under the European Commission’s Digital Omnibus initiative. The agreement grants meaningful deadline relief for medical device manufacturers developing AI-enabled products.

Revised compliance timeline for medical device manufacturers:

Annex III – Standalone high-risk AI systems (including SaMD not subject to third-party conformity assessment under MDR/IVDR): compliance deadline moved from 2 August 2026 to 2 December 2027 — a 16-month extension.

Annex I – AI embedded in products regulated under EU MDR or IVDR (Class IIb/III devices; Class C/D IVDs): compliance deadline moved from 2 August 2027 to 2 August 2028 — a 12-month extension.

The provisional agreement must still be formally endorsed and adopted by both co-legislators. Given the proximity of the original August 2026 deadline, the legislative process is expected to proceed on an accelerated schedule.

Core cybersecurity obligations under the EU AI Act for medical devices remain unchanged and include: resilience against adversarial inputs, data poisoning, and model evasion; accuracy and robustness performance metrics declared in instructions for use; and traceability and human oversight mechanisms.

Note: Although deadlines are being extended, the EU Commission has emphasized that compliance preparation should already be underway. The additional time is intended to accommodate technical standards development, not to delay program initiation.

3. United Kingdom – MHRA

Draft Medical Devices (Amendment) Regulations 2026 and AI Framework

The MHRA has published the Medical Devices (Amendment) Regulations 2026, a draft statutory instrument reforming pre-market requirements for medical devices and IVDs in Great Britain. From a cybersecurity perspective, the draft introduces several notable provisions:

A Predetermined Change Control Plan (PCCP) pathway for software medical devices is included, intended to streamline regulated software updates — including security patches — without requiring full re-submission.

Explicit cybersecurity obligations are introduced as pre-market requirements, moving beyond existing post-market vigilance obligations.

Cybersecurity vulnerabilities are now formally recognized as potential “serious incidents” under the UK post-market vigilance system. A security flaw that could lead to serious deterioration in patient health triggers mandatory reporting to the MHRA and requires a Field Safety Corrective Action (FSCA) process including Field Safety Notices (FSNs).

The MHRA has also confirmed it will publish a dedicated regulatory framework for AI as a Medical Device (AIaMD) in 2026, introducing structured requirements for AI lifecycle governance, transparency, and cybersecurity for AI-enabled devices sold in Great Britain.

4. Industry Research & Threat Intelligence

Health-ISAC May 2026 Newsletter: Q1 Threat Insights

Health-ISAC’s May 2026 newsletter features Q1 2026 threat intelligence for the health sector, including a case study on IT/OT boundary risk: an enterprise IT compromise at a medtech company served as the entry vector for a wiper attack, with potential pathways toward operational and device-connected environments — though no patient-related services or connected medical products were directly affected. The incident underscores the need for manufacturers to maintain network segmentation between enterprise IT systems, manufacturing OT systems, and connected device management infrastructure.

Q1 2026 Health Sector Threat Landscape:

AI-enabled attacks have been identified as the leading threat vector for 2026, followed by zero-day exploits, ransomware deployments, third-party breaches, and phishing campaigns.

Health sector cyber incidents rose 21% year-over-year in 2025 (476 to 585 incidents), and the trend is projected to continue into 2026.

Internet of Medical Things (IoMT) devices — including infusion pumps, patient monitors, and diagnostic equipment — remain high-value targets, frequently running outdated software and lacking robust security controls.

Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.

Want this tailored to your regulatory strategy?

Talk to our team about what this week's developments mean for your specific device and timeline.

Schedule a Consultation