Executive Summary
This week’s key developments include a major political agreement to delay EU AI Act high-risk obligations for medical device manufacturers (now deferred to August 2028), and continued enforcement focus on the FDA’s February 2026 QMSR/cybersecurity guidance. Manufacturers should prioritize SBOM implementation, assess EU AI Act exposure under the revised Omnibus timeline, and begin preparations for the EU Cyber Resilience Act Article 14 reporting requirement taking effect September 11, 2026.
1. U.S. FDA
QMSR & Revised Cybersecurity Premarket Guidance — Enforcement Underway
The FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, replaced 21 CFR Part 820 and incorporates ISO 13485:2016 by reference. Simultaneous with QMSR enforcement, the FDA issued revised guidance on February 3, 2026 — “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions” — superseding the June 2025 version. Key requirements now in effect include:
A Security Risk Management Report and machine-readable Software Bill of Materials (SBOM) as mandatory premarket submission elements.
Implementation of a Secure Product Development Framework (SPDF) across the total product lifecycle.
A Cybersecurity Management Plan with Coordinated Vulnerability Disclosure processes for postmarket surveillance.
Cybersecurity embedded into QMS design controls, risk management (ISO 14971), and validation activities.
FDA inspections are now being conducted under the updated Compliance Program 7382.850, with cybersecurity documentation gaps identified as a leading cause of non-conformities.
MITRE/FDA Report: Evolving Technology Cyber Risks (April 2026)
Although published in late April 2026, the FDA-commissioned MITRE report “Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies” continues to drive industry discussion this week. The report flags three technology-specific risk areas:
Cloud dependency: Unavailability of cloud services can prevent care delivery, creating indirect patient harm pathways.
AI/ML vulnerabilities: Data poisoning and prompt injection attacks present novel risks for AI-integrated devices; the stochastic nature of AI outputs complicates traditional risk assessment.
Post-quantum cryptography: “Harvest-now, decrypt-later” attacks are an active threat requiring manufacturers to plan PQC migration now.
2. European Union
EU AI Act Omnibus Agreement — Medical Device Deadlines Postponed (May 7, 2026)
On May 7, 2026, the EU Council and Parliament reached provisional political agreement on revisions to the AI Act as part of the broader EU Omnibus simplification package. This is the most significant regulatory development this week for medical device manufacturers with AI-integrated products. Key changes:
Annex I high-risk AI obligations (covering AI embedded in CE-marked medical devices and IVDs under MDR/IVDR) are now deferred from August 2, 2027 to August 2, 2028 — a 12-month extension.
The definition of “safety component” is being narrowed: AI components that merely assist users or optimize performance without creating health or safety risks will not be subject to high-risk obligations.
Stand-alone Annex III high-risk AI systems (non-product-embedded) deadline moves to December 2, 2027.
Note: The agreement is provisional and requires formal endorsement by the Council, European Parliament ratification, legal-linguistic revision, and publication in the Official Journal. Adoption is expected before the original August 2, 2026 deadline. Manufacturers should monitor for final text, particularly regarding the narrowed “safety component” definition and any changes to cybersecurity requirements under Article 15.
EU MDR / MDCG 2019-16 — Notified Body Enforcement
Notified Bodies continue to intensify scrutiny of cybersecurity documentation under MDCG 2019-16. Missing or inadequate security documentation remains one of the top causes of major non-conformities for software-as-a-medical-device (SaMD). Current focus areas include security architecture documentation (network interfaces, data flows, trust boundaries), coordinated vulnerability disclosure processes, and patch deployment documentation.
EU Cyber Resilience Act — Article 14 Reporting Obligation Approaching
While medical devices regulated under MDR/IVDR are exempted from the CRA’s product requirements, manufacturers face CRA compliance exposure through five pathways: components purchased from CRA-covered suppliers, IT infrastructure products, dual-use software, NIS2 overlap, and supply chain obligations. The Article 14 vulnerability and incident notification requirement applies from September 11, 2026 to all manufacturers (including those supplying to health delivery organizations). Requirements include:
Initial report within 24 hours of discovering an actively exploited vulnerability or severe incident.
Further information within 72 hours if available.
Final vulnerability report within 14 days of issuing a security update or workaround.
3. Standards — IEC & ISO
IEC 81001-5-1 — EU Harmonization Timeline Confirmed for 2028
IEC 81001-5-1:2021 (Health software and health IT systems safety, effectiveness and security — Cybersecurity) remains the primary international standard for medical device product cybersecurity. The standard is confirmed for formal harmonization under EU MDR/IVDR on May 27, 2028. Until harmonization, compliance with IEC 81001-5-1 is the recommended (though not mandatory) approach for demonstrating conformity with MDCG 2019-16 and FDA’s SPDF requirements. The standard requires product-specific threat modeling, security risk management, and SBOM — activities not covered by ISO/IEC 27001 (which governs enterprise information security management).
Recommended Standards Stack (2026)
The current regulatory-aligned cybersecurity standards stack for medical device manufacturers is:
IEC 81001-5-1:2021 — Product cybersecurity lifecycle (FDA-aligned, pre-harmonization under EU MDR)
ISO 14971:2019 — Medical device risk management (required by FDA QMSR and EU MDR)
ISO/IEC 27001:2022 — Enterprise information security management (recommended; complementary to IEC 81001-5-1)
AAMI TIR57 — Principles for medical device security risk management (US market, aligns with ISO 14971)
4. U.S. HIPAA Security Rule Update
The HHS proposed HIPAA Security Rule amendments (published January 2025) are expected to be finalized by mid-2026. The proposed rule eliminates the “addressable” vs. “required” distinction, making encryption, multi-factor authentication, and vulnerability scanning mandatory. Specific medical device implications:
MFA will be required for access to systems containing ePHI, with limited exceptions for certain medical device form factors.
Network segmentation to isolate medical devices on separate VLANs will be a compliance expectation.
Automated vulnerability scans at least every six months and penetration testing at least annually will be required.
Manufacturers should ensure their premarket cybersecurity documentation addresses HIPAA Security Rule compliance for devices that access or process ePHI.
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.