Executive Summary
This week’s briefing highlights a significant EU Cyber Resilience Act (CRA) milestone — the June 11 entry into force of Conformity Assessment Body notification procedures — bringing the September 11, 2026 mandatory incident-reporting deadline for connected products into sharp focus. CISA continued its cadence of ICS medical advisories through the week. IEC 62304 Edition 2 remains on track for publication in August 2026 following approval-phase completion in late May.
1. U.S. Food & Drug Administration (FDA / CDRH)
QMSR Inspection Enforcement Under CP 7382.850
FDA’s Compliance Program Manual 7382.850, which took effect February 2, 2026 concurrent with QMSR, formally embeds cybersecurity review into routine quality system inspections. Field investigators are now required to assess “cyber devices” and other software-enabled medical devices for conformity with Section 524B of the FD&C Act. Non-conformance is classified as a Situation 1 finding eligible for Official Action Indicated (OAI) treatment. Manufacturers should prepare integrated quality and cybersecurity documentation that can withstand this unified inspection approach.
SBOM and VEX Requirements in Active Enforcement
FDA reviewers are actively flagging premarket submissions that lack complete and accurate Software Bills of Materials (SBOMs). The February 2026 guidance cycle expanded SBOM expectations to include lifecycle metadata — specifically, end-of-support dates for all third-party components — and mandated the use of Vulnerability Exploitability eXchange (VEX) files to communicate the exploitability status of known vulnerabilities. Submissions deficient in these areas are being returned to applicants during interactive review. The NTIA Minimum Elements document remains the baseline SBOM format expectation.
2. European Union — Cyber Resilience Act (CRA)
June 11, 2026: Conformity Assessment Body Notifications Now Active
This week’s most notable regulatory milestone: Article 35 of the EU Cyber Resilience Act entered into application on June 11, 2026, meaning Notifying Authorities across EU Member States are now formally assessing, designating, and notifying Conformity Assessment Bodies (CABs) under the CRA framework. This paves the way for CRA conformity assessments for products in scope — including wearable health devices and software components in medical device supply chains — ahead of the September 11, 2026 reporting deadline.
September 11, 2026 Incident/Vulnerability Reporting Deadline — 88 Days Away
With the September 11 deadline now less than 100 days away, manufacturers of connected products with digital elements (PDEs) that are in scope of the CRA must establish processes for reporting actively exploited vulnerabilities and severe incidents to ENISA’s single reporting platform within 24 hours. Key scope clarifications remain critical for medical device manufacturers:
Medical devices regulated under EU MDR 2017/745 and IVDR 2017/746 are excluded from CRA product requirements.
Wearables with health-monitoring functions (e.g., consumer smartwatches) ARE in scope.
Software supply chain vendors providing components to medical device manufacturers ARE subject to the CRA’s September 11 reporting obligations — creating upstream notification flows that device manufacturers must be prepared to receive and act upon for post-market surveillance.
The September 11 deadline triggers only Article 14 reporting obligations. Full vulnerability handling and product security requirement compliance is not required until December 11, 2027.
3. EU — Medical Device Coordination Group (MDCG) & MDR
Notified Body Scrutiny of Cybersecurity Documentation Intensifying
Notified Bodies are reporting increased scrutiny of cybersecurity technical documentation in MDR and IVDR conformity assessment dossiers in 2026. MDCG 2019-16 (Guidance on Cybersecurity for Medical Devices) remains the primary EU reference; manufacturers should ensure conformity against its pre-market and post-market requirements. Cybersecurity is a General Safety and Performance Requirement (GSPR) and Notified Bodies are assessing the following areas particularly closely: secure design documentation, minimum IT configuration requirements, postmarket security plans with defined vulnerability management timelines, and IFU content covering data protection, update procedures, and decommissioning guidance.
EU AI Act Cybersecurity Obligations — August 2026
The EU AI Act’s requirements for high-risk AI systems — which include AI-enabled medical devices — begin applying in August 2026. These obligations include cybersecurity governance requirements specific to AI systems. Manufacturers of AI-enabled medical devices must ensure their Technical Documentation and risk management documentation addresses AI-specific cybersecurity threats alongside existing MDR GSPR cybersecurity requirements.
4. United Kingdom — MHRA
Draft 2026 Regulations and International Reliance Framework
The MHRA has published draft 2026 medical device regulations that are expected to introduce an International Reliance Framework by Autumn 2026, enabling UK market access pathways leveraging approvals from trusted regulators including the US, Canada, and Australia. The draft regulations include a Predetermined Change Control Plan (PCCP) pathway for software medical devices — directly analogous to the FDA’s PCCP approach — with explicit cybersecurity obligations for software updates managed under a PCCP. MHRA is also developing a dedicated AI medical device framework, with cybersecurity and lifecycle governance under increased scrutiny for AI-enabled devices.
PMS Cybersecurity: Vulnerabilities as Serious Incidents
UK post-market surveillance regulations now explicitly recognize cybersecurity flaws as potential device incidents. Where a security vulnerability could lead to serious deterioration in health, it must be treated as a “serious incident” and reported to the MHRA. Manufacturers with devices on the UK market should ensure their vigilance and PMS systems capture cybersecurity vulnerability data and apply the same incident reporting thresholds as for hardware or software safety defects.
5. Australia — Therapeutic Goods Administration (TGA)
AI Medical Software Guidance Published; Hardware Cybersecurity Mandate Active
The TGA published new guidance in February 2026 on the regulation of AI-based software medical devices (SaMD), clarifying when and how AI-enabled software is regulated as a medical device. Cybersecurity, post-market monitoring, and data management are key compliance areas addressed in the guidance. Separately, effective May 2026, TGA has moved to mandatory hardware-based security measures, requiring manufacturers to provide evidence that devices cannot be physically tampered with by nearby actors — a shift from previously advisory best practices. Manufacturers supplying the Australian market should update technical documentation to address these hardware security requirements explicitly.
6. CISA — ICS and Medical Device Advisories
Multiple ICS and Medical Advisories Issued This Week
CISA continued its regular cadence of Industrial Control Systems (ICS) and ICS Medical advisories this week, with advisories dated June 9–12, 2026 covering vulnerabilities in critical infrastructure and medical systems. Recent CISA medical device advisories have addressed issues including use of default credentials in Becton, Dickinson and Company (BD) diagnostic systems (BACTEC, COR, EpiCenter, MAX, Phoenix M50, and Synapsys), potentially enabling unauthorized access, modification, or deletion of sensitive patient data. Manufacturers should monitor the CISA ICS Advisories page (cisa.gov/news-events/ics-advisories) and assess whether their products or supply chain components are affected by newly published advisories.
CISA Implements OASIS CSAF 2.0 for Medical Device Advisories
CISA has implemented the OASIS Common Security Advisory Framework (CSAF) 2.0 standard for its ICS, OT, and medical device security advisories, enabling machine-readable vulnerability disclosures. Manufacturers should ensure their vulnerability management processes are capable of ingesting CSAF 2.0 formatted advisories to facilitate timely assessment of component-level vulnerabilities disclosed by CISA.
7. Standards — IEC & ISO
IEC 62304 Edition 2: Approval Phase Complete, Publication Expected August 2026
IEC 62304 Edition 2 — the major revision to the international standard for medical device software lifecycle processes — completed its approval voting phase on May 22, 2026, with publication targeted for August 12, 2026. This edition introduces significant changes that affect cybersecurity planning and compliance:
Simplified safety classification: Three-class system (A/B/C) replaced by two process rigor levels — Level I (replaces Class A) and Level II (replaces Classes B and C).
Expanded scope: Standard now covers all health software, not only formally regulated medical devices, broadening the population of software subject to its requirements.
AI/ML provisions: A defined AI development lifecycle is introduced, with explicit security and validation requirements for AI-enabled software.
“Harm” definition expanded to include property and environmental damage alongside patient harm, aligning with ISO 14971:2019.
Clarified distinction between Development and Maintenance processes, with Maintenance permitting a streamlined process for rapid changes.
Manufacturers should begin gap assessments against the draft text now. FDA has indicated it will recognize IEC 62304 Edition 2 as a consensus standard upon publication; submissions referencing Edition 1 will continue to be accepted during a transition period.
IEC 81001-5-1: Health Software Cybersecurity Standard — Harmonization Pathway
IEC 81001-5-1, the first international standard specifically targeting cybersecurity for health software and Software as a Medical Device (SaMD), is scheduled for formal EU harmonization on May 27, 2028. The standard introduces 64 additional cybersecurity requirements beyond baseline development process controls, covering secure design, vulnerability management, and cryptographic controls. It aligns with ISO/IEC 27001:2022 for organizational security management context and with ISO 14971 for risk management integration. Manufacturers developing SaMD or embedded medical device software should begin incorporating IEC 81001-5-1 requirements into design and development procedures to prepare for its eventual harmonized status under EU MDR.
IEC 62443 — OT Security Standard Update
The IEC 62443 series for industrial automation and control system cybersecurity has been updated to explicitly include Industrial IoT (IIoT) and cloud-based analytics that interact with field devices. Parts 4-1 (Secure Product Development Lifecycle) and 4-2 (Technical Security Requirements for IACS components) remain the most applicable for medical device manufacturers with networked device components. FDA continues to recognize IEC 62443-4-1 as a consensus standard for medical device premarket submissions.
8. Industry Intelligence
Hospital Mortality Correlation with Ransomware Incidents
A joint study by Halcyon and Health-ISAC published earlier in 2026 found that in-hospital mortality increased by 33% during ransomware incidents affecting healthcare facilities. This data is being cited by regulators globally to justify mandatory cybersecurity requirements and faster disclosure timelines. Manufacturers should incorporate this evidence into their internal risk justification for cybersecurity investment and ensure their postmarket surveillance plans adequately address ransomware and denial-of-service scenarios affecting devices.
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.