1. FDA — UNITED STATES
February 2026 Guidance: Cybersecurity and the QMSR
The FDA’s final guidance “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions” (February 2026) supersedes the June 27, 2025 version. It aligns cybersecurity recommendations with the Quality Management System Regulation (QMSR), which took effect on February 2, 2026.
| “Cybersecurity is Part of Device Safety and the Quality Management System Regulation (QMSR). A Secure Product Development Framework (SPDF) may be one way to satisfy the QMSR.” — FDA guidance, February 2026 — Section IV.A |
|---|
| “This final rule took effect on February 2, 2026, and amends the majority of the requirements previously in 21 CFR Part 820 (Part 820) and incorporates by reference the 2016 edition of ISO 13485, Medical devices — Quality management systems — Requirements for regulatory purposes.” — FDA guidance, February 2026 — footnote 11 |
|---|
The guidance describes a Secure Product Development Framework (SPDF) as “a set of processes that reduces the number and severity of vulnerabilities in products throughout the device lifecycle.” Use of an SPDF is positioned as one way — though not the only way — to satisfy the QMSR cybersecurity expectations.
SBOM Requirements for Cyber Devices (Section 524B)
For devices meeting the statutory definition of a “cyber device” under Section 524B of the FD&C Act, an SBOM is a legal requirement. For all other software-containing devices, the guidance strongly recommends an SBOM as good practice.
| “For cyber devices, an SBOM is required (see section 524B(b)(3) of the FD&C Act and Section VII.C.3 of this guidance). SBOMs can also be an important tool for transparency with users of potential risks as part of labeling.” — FDA guidance, February 2026 — Section V (SBOM) |
|---|
| “An SBOM helps facilitate risk management processes by providing a mechanism to identify devices and the systems in which they operate that might be affected by vulnerabilities in the software components, both during development when software is being chosen as a component and after it has been placed into the market throughout all other phases of a product’s life.” — FDA guidance, February 2026 — Section V (SBOM) |
|---|
| NOTE: The February 2026 FDA guidance contains no reference to VEX (Vulnerability Exploitability eXchange) documents. Claims to this effect that appeared in industry commentary have not been confirmed in the primary source text and are not included in this briefing. |
|---|
Source: FDA, “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions,” February 2026. https://www.fda.gov/media/119933/download
2. EU — CYBER RESILIENCE ACT: REPORTING DEADLINE APPROACHING
September 11, 2026: Reporting Obligations Enter Application
The European Commission’s official CRA implementation page (updated 8 June 2026) confirms that reporting obligations under the Cyber Resilience Act enter application on 11 September 2026. The CRA Single Reporting Platform (SRP), being built by ENISA, will be operational by that date.
| “As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements.” — European Commission, CRA Reporting Obligations page (updated 8 June 2026) |
|---|
| “They need to submit an early warning within 24 hours of becoming aware, and a full notification within 72 hours. A final report needs to be submitted no later than 14 days after a corrective measure is available for actively exploited vulnerabilities and within a month for severe incidents.” — European Commission, CRA Reporting Obligations page (updated 8 June 2026) |
|---|
Note on medical device exemption: The CRA explicitly lists medical devices regulated under MDR (2017/745) and IVDR (2017/746) among products exempted from CRA product requirements. However, the scope of the reporting obligation relative to MDR/IVDR-exempt devices and the implications for software supply chains are addressed in secondary regulatory commentary rather than the official CRA reporting page. Manufacturers should consult the CRA legal text (Regulation (EU) 2024/2847) and ENISA’s SRP FAQ directly for their specific position.
Source: European Commission, “Cyber Resilience Act — Reporting obligations,” last updated 8 June 2026. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
3. EU — AI ACT: REVISED APPLICATION TIMELINE (AI OMNIBUS)
Key Timeline Update — Political Agreement of 7 May 2026
The European Commission’s AI Act policy page (updated 11 May 2026) confirms a revised application timeline following the political agreement on the “AI omnibus” simplification package reached on 7 May 2026. This directly affects AI-enabled medical devices.
| “The AI Act entered into force on 1 August 2024, and will be fully applicable 2 years later on 2 August 2026, with some exceptions: … the rules for high-risk AI systems — embedded into regulated products — have an extended transition period until 2 August 2028 (as a result of the political agreement on the proposal to simplify the AI Act — ‘AI omnibus’).” — European Commission, AI Act policy page (updated 11 May 2026) |
|---|
| “Rules for systems used in certain high-risk areas — including biometrics, critical infrastructure, education, employment, migration, asylum and border control — will apply from 2 December 2027. For systems integrated into products such as lifts or toys, the rules will apply from 2 August 2028.” — European Commission, AI Act policy page (updated 11 May 2026) — AI omnibus timeline |
|---|
For manufacturers of AI-enabled medical devices: AI systems “integrated into products” — which includes AI-based safety components such as those used in robot-assisted surgery, as cited in the official text — fall under the 2 August 2028 deadline. The transparency rules of the AI Act (Article 50 obligations) are confirmed to come into effect in August 2026.
| CORRECTION vs. PRIOR BRIEFING: The previous edition of this briefing stated the AI Act Article 6(1) deadline for AI embedded in CE-marked medical devices was “August 2, 2027.” The primary source confirms this has been updated to 2 August 2028 per the AI omnibus political agreement of 7 May 2026. |
|---|
Source: European Commission, “AI Act,” last updated 11 May 2026. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
4. UK MHRA — DRAFT MEDICAL DEVICES (AMENDMENT) REGULATIONS 2026
Stakeholder Consultation Closed 19 June 2026
The MHRA published draft Medical Devices (Amendment) Regulations 2026 on the WTO notification portal on 8 May 2026 and invited stakeholder views via an impact survey. The consultation closed on 19 June 2026.
| “New pre-market regulatory requirements for medical devices and in vitro diagnostic devices entering the GB market have been published by the Medicines and Healthcare products Regulatory Agency (MHRA) on the World Trade Organisation notification portal on Friday 8th May 2026.” — MHRA, GOV.UK news release, published 11 May 2026 |
|---|
The MHRA’s official announcement lists the following objectives of the draft regulations:
Give faster access to safe and innovative medical devices and support economic growth and innovation in the UK MedTech sector.
Introduce a framework to enable swifter access for devices already approved by regulators in Australia, Canada and the USA.
Require healthcare organisations that implant medical devices to give patients implant cards.
Make unique device identifiers (UDI) compulsory to enable precise identification and traceability throughout the device lifecycle.
Align classifications of IVD devices with IMDRF standards.
Align essential requirements for medical devices in Great Britain with best international practice.
Strengthen requirements for technical documentation retention.
Include new requirements for custom-made devices to improve traceability and enable electronic prescriptions.
| NOTE: The MHRA’s official announcement does not specifically enumerate cybersecurity as a named requirement of the draft regulations. Claims regarding explicit cybersecurity provisions or a PCCP pathway in the draft regulations are sourced from secondary commentary and are not reproduced here. Manufacturers should read the draft regulations directly via the WTO notification portal for the full technical requirements. |
|---|
Source: MHRA, “MHRA invites views on proposed changes to medical device regulation,” GOV.UK, published 11 May 2026. https://www.gov.uk/government/news/mhra-invites-views-on-proposed-changes-to-medical-device-regulation
5. INDUSTRY INTELLIGENCE [SECONDARY SOURCES]
The following items are drawn from industry reports and news coverage, not verified against primary regulatory sources. They are included for situational awareness only.
Reported Incidents (News Sources)
A Class 2 recall of a diagnostic imaging viewer platform was reported due to software vulnerabilities. Manufacturers should check the FDA recall database directly for current status: https://www.fda.gov/medical-devices/medical-device-recalls
Source: MedTech Dive, MDDIOnline, and industry press coverage; not independently verified against FDA primary sources.
6. UPCOMING REGULATORY DEADLINES
Key milestones over the next 3–6 months, drawn from verified primary sources where noted.
| Date | Milestone | Jurisdiction | Primary Source |
|---|---|---|---|
| 2 August 2026 | EU AI Act fully applicable. Transparency obligations (Article 50) come into effect. Prohibition and general obligations already in force from February/August 2025. | EU | EC AI Act page (updated 11 May 2026) |
| 11 September 2026 | EU CRA Article 14 reporting obligations enter application. Manufacturers must report actively exploited vulnerabilities within 24 hours and severe incidents within 72 hours via the CRA Single Reporting Platform. | EU | EC CRA Reporting page (updated 8 June 2026) |
| 11 December 2027 | Full application of the Cyber Resilience Act (all product requirements). | EU | EC CRA Implementation page (updated 23 April 2026) |
| 2 August 2028 | EU AI Act rules for high-risk AI systems integrated into products (including AI-enabled medical devices) apply — per AI omnibus political agreement of 7 May 2026. | EU | EC AI Act page (updated 11 May 2026) |
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.