← All briefings Weekly Briefing

Issue: June 10, 2026

Regulatory Intelligence for Medical Device Manufacturers

Executive Summary

This week’s briefing highlights an imminent EU Cyber Resilience Act deadline (11 June 2026), new CISA medical device advisories targeting Bluetooth vulnerabilities, and continued FDA enforcement pressure on premarket cybersecurity submissions. MITRE’s landmark report on AI, cloud, and post-quantum risks continues to shape manufacturer risk frameworks globally. Upcoming deadlines through December 2026 are tracked in the final section.

U.S. FDA

Enforcement Focus: Cybersecurity Top Cause of Premarket Rejections

The FDA’s Refuse to Accept (RTA) policy under Section 524B of the FD&C Act continues to be enforced aggressively in 2026. Cybersecurity deficiencies have emerged as the single most common reason for premarket submission rejections, with inadequate Software Bills of Materials (SBOMs), missing threat models, and absent post-market vulnerability management plans cited most frequently.

The February 2026 guidance update — which aligned cybersecurity requirements with the Quality Management System Regulation (QMSR, effective 2 February 2026) — is now the operative standard for all premarket submissions. Key expectations under this guidance include:

Integration of cybersecurity into the Secure Product Development Framework (SPDF) across the full device lifecycle

Documented SBOM with all software components, including third-party and open-source libraries

Threat modeling, penetration testing evidence, and cybersecurity risk assessment aligned with ISO 14971

Post-market vulnerability monitoring and coordinated disclosure plans

The FDA has signaled a further shift from documentation review toward operational assessment of manufacturers’ post-market cybersecurity response capabilities.

CISA — Medical Device Advisories

ICSMA-26-148-01: Fourth Frontier Frontier X / Frontier X2 (28 May 2026)

CISA issued an ICS Medical Advisory for the Fourth Frontier Frontier X wearable cardiac monitor and Frontier X2 device. The advisory discloses an unauthenticated Bluetooth Low Energy (BLE) vulnerability affecting all Frontier X2 hardware versions and mobile app versions below Frontier X Android 15.0.0 / iOS 25.0.0.

Key risk details:

Unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization

Attackers within BLE range can read and write arbitrary handle values, alter clinical readings, start/stop device activity, trigger denial-of-service, or induce unexpected behavior via fuzzing

CVSS assessment indicates potential for direct patient harm

Manufacturer mitigation: Update to Frontier X Android app v15.0.0+ or iOS app v25.0.0+. No patch exists for Frontier X2 hardware; compensating controls and environment management are advised.

ICSMA-26-146-01: Eppendorf BioFlo 320 (26 May 2026)

CISA also issued an advisory for the Eppendorf BioFlo 320 bioprocess controller. Full advisory details are available on the CISA website. Manufacturers using this device in connected lab or manufacturing environments should review the advisory and apply available mitigations.

European Union

EU Cyber Resilience Act — IMMINENT: Chapter IV Deadline 11 June 2026

Effective 11 June 2026 — tomorrow at time of publication — EU Member States must have designated notifying authorities responsible for assessing, designating, and notifying conformity assessment bodies (CABs) under Chapter IV of the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847).

While medical devices regulated under EU MDR 2017/745 and IVDR 2017/746 are exempted from CRA product requirements, medical device manufacturers are directly affected in two ways:

Software supply chain exposure: Third-party software component suppliers (e.g., operating systems, middleware, connectivity stacks) embedded in medical devices are subject to CRA and must comply with Chapter IV and the September 2026 reporting obligations

Notified Body alignment: CABs that will be notified under CRA may overlap with notified bodies performing conformity assessments under MDR/IVDR, and manufacturers should monitor designation status in their jurisdictions

The European Commission’s draft guidance clarifying CRA scope and obligations (published March 2026, consultation closed 31 March 2026) is expected to be finalized in the coming months.

EU CRA Article 14 Reporting Obligations — September 11, 2026

Manufacturers and importers of products with digital elements — including software suppliers in the medical device supply chain — must be fully prepared for Article 14 incident and vulnerability reporting obligations effective 11 September 2026. The timeline requires:

Early warning to national CSIRT and ENISA within 24 hours of awareness of an actively exploited vulnerability

Full notification within 72 hours

Final report within 14 days of availability of a corrective measure (or within 1 month for severe incidents)

Reporting is made through the CRA Single Reporting Platform. Medical device manufacturers should audit their software supply chains immediately to identify CRA-subject components and ensure suppliers have compliant vulnerability disclosure processes in place.

EU MDR/IVDR Cybersecurity Amendment Proposals

The European Commission has put forward amendment proposals to the MDR and IVDR that would explicitly reference cybersecurity in Annex I (General Safety and Performance Requirements) and introduce enhanced vigilance reporting obligations for ‘serious incidents’ with a cybersecurity dimension. Proposed changes include:

Mandatory notification to CSIRTs and ENISA of actively exploited vulnerabilities and severe incidents affecting device security

Incident reports to be submitted via the Eudamed platform within 30 days of awareness

These proposals are under consideration by the European Parliament and Council. Final adoption timelines remain uncertain. Manufacturers should track legislative progress and assess gap impacts on existing post-market surveillance systems.

Industry Research & Emerging Threats

MITRE: Cybersecurity Risks from AI, Cloud, and Post-Quantum Technologies

MITRE published a major report in April 2026 — “Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies” — examining how the integration of AI/ML, cloud computing, and post-quantum cryptography is reshaping the threat landscape for medical device manufacturers. Key findings:

AI and cloud adoption: Over 57% of healthcare organizations have deployed AI-enabled or AI-assisted medical systems, yet 80% report moderate-to-high cybersecurity concern about these technologies. Cloud-based device architectures introduce shared responsibility models that complicate traditional device-centric risk management under ISO 14971 and IEC 62304

Post-quantum cryptography: MITRE flags the ‘harvest-now, decrypt-later’ threat as an acute risk for long-lifecycle medical devices. With NIST finalizing post-quantum encryption standards in 2024 and planning to disallow current vulnerable algorithms by 2035, manufacturers of devices with 10+ year lifecycles must begin cryptographic inventory and migration planning now

SBOM inconsistency: Significant inconsistency in how SBOMs are generated and parsed across tooling continues to impede vulnerability management; MITRE recommends automated discovery and standardized SBOM formats as a priority

The report recommends a phased strategic approach: establish cryptographic inventory, allocate resources for post-quantum migration, and integrate cloud security assessments into device risk management processes.

Standards (IEC / ISO)

IEC 81001-5-1 — Interpretation Sheet (December 2025)

In December 2025, the IEC released an interpretation sheet for IEC 81001-5-1:2021 (Health software and health IT systems — Security activities in the product lifecycle). The interpretation sheet clarifies:

How security responsibilities are delineated between manufacturers and operators/healthcare delivery organizations throughout the software lifecycle

The conditions under which risk transfer is acceptable once a product is deployed in a clinical environment

This guidance is particularly relevant given the FDA’s recognition of IEC 81001-5-1 as a recommended framework in the February 2026 QMSR-aligned cybersecurity guidance. Manufacturers should review their existing IEC 81001-5-1 implementation plans against the interpretation sheet to identify any gaps, especially in operator security responsibility documentation within Instructions for Use.

Global Regulatory Developments

Australia (TGA)

The TGA released updated guidance in early 2026 specifically addressing AI-based Software as a Medical Device (SaMD), following its 2025 final report on AI in healthcare. The TGA is also consulting on revisions to its Essential Principles, with greater emphasis on software lifecycle management, cybersecurity, and change control for AI-enabled devices. Manufacturers with Australian market presence should monitor the consultation and assess alignment gaps.

Japan (MHLW / PMDA)

Japan continues to develop its SHIELD for Medical Devices framework (Security in Healthcare Intelligence, Electronics, Legacy systems, and Digital transformation), with ongoing collaboration between JFMDA, MHLW, PMDA, and AMED. Manufacturers operating in the Japanese market should monitor publication of draft SHIELD guidance and anticipate alignment requirements with IEC 81001-5-1 and IEC 62304 as baseline expectations.

UK (MHRA)

The MHRA has published a draft Statutory Instrument outlining its Future Regulatory Framework for Medical Devices. Cybersecurity requirements are expected to align with the UK PSTI Act (Product Security and Telecommunications Infrastructure) for connected devices, and manufacturers should assess whether existing MDR-aligned cybersecurity documentation will satisfy UK-specific requirements post-divergence.

Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.

Want this tailored to your regulatory strategy?

Talk to our team about what this week's developments mean for your specific device and timeline.

Schedule a Consultation