1. CISA Medical Device Advisories — June 25, 2026
CISA published two ICS Medical Advisories (ICSMA) affecting healthcare and public health critical infrastructure on 25 June 2026. Both relate to DICOM imaging ecosystem components widely used by medical device manufacturers and health systems.
ICSMA-26-176-01: pydicom / pynetdicom Library
Affected product: pynetdicom versions ≥ 1.0.0 to < 3.0.4
Severity: High — unauthenticated remote write to arbitrary file paths
The qrscp application’s C-STORE handler passes attacker-supplied DICOM dataset fields directly into os.path.join() without sanitisation, enabling an unauthenticated attacker to write files to arbitrary paths on the server. CISA notes the maintainer has not responded to coordinated disclosure requests.
Recommended action: restrict network access to qrscp endpoints; monitor CISA advisory for patch status.
Advisory: ICSMA-26-176-01
ICSMA-26-176-02: OHIF Viewers DICOM Web Viewer
Affected product: OHIF DICOM Web Viewer Framework ≤ 3.12.0
Severity: High — authenticated clinician OIDC Bearer token disclosure
Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default OHIF configuration fetch arbitrary URL parameters without validation. A global authentication service automatically injects the authenticated user’s OIDC Bearer token into resulting requests, forwarding it to an attacker-controlled server via a crafted link.
Fix available: upgrade to OHIF v3.12.2 (released 18 May 2026).
Manufacturers integrating OHIF into device software or clinical platforms should prioritise this update and assess SBOM entries accordingly.
Advisory: ICSMA-26-176-02
2. EU Cyber Resilience Act — 75-Day Warning: September 11, 2026 Deadline
With fewer than 75 days until the CRA’s first mandatory application date, legal counsel (Crowell & Moring) and standards bodies are issuing final preparation warnings. Manufacturers of products with digital elements shipping to the EU must be ready by 11 September 2026.
What takes effect on 11 September 2026
Mandatory reporting of actively exploited vulnerabilities to ENISA and designated national CSIRTs within 24 hours of becoming aware.
Full vulnerability notification within 72 hours; final report within 14 days of a corrective measure becoming available.
The EU’s Single Reporting Platform (SRP) will be operational by this date, with a testing window expected beforehand.
Medical device manufacturer implications
Medical devices regulated under EU MDR 2017/745 and IVDR 2017/746 are formally exempt from CRA product requirements. However, two critical indirect obligations remain:
Software supply chain: components and libraries embedded in your devices that are provided by third-party software vendors ARE subject to CRA. Those vendors must report exploited vulnerabilities within 24 hours. Manufacturers must have processes to receive and act on these upstream disclosures under their own MDR post-market surveillance obligations.
SBOM readiness: without a current, machine-readable SBOM (SPDX or CycloneDX), manufacturers cannot rapidly identify affected components when upstream CRA reports arrive.
CRA Reporting Obligations — European Commission
Crowell & Moring client alert — CRA countdown
3. IMDRF — New Work Item: Cybersecurity Controls & Testing
At the 29th IMDRF Management Committee Meeting (Singapore, March 2026), a New Work Item Proposal (NWIP) was approved to develop guidance on “Cybersecurity Controls and Testing Considerations.” This represents a significant expansion of the IMDRF cybersecurity framework beyond the existing N60 (principles), N70 (legacy devices), and N73 (SBOM) documents.
The new guidance will provide internationally harmonised expectations for specific security controls and testing methodologies, directly relevant to pre-market submissions across all IMDRF member jurisdictions (US, EU, Canada, Australia, Japan, Singapore, Brazil, UK, China, South Korea).
Draft publication timeline has not been formally announced; manufacturers should monitor the IMDRF website for public consultation periods.
IMDRF Medical Device Cybersecurity Guide working group
4. Global Regulatory Round-Up
United Kingdom — MHRA Draft Amendment Regulations 2026
The MHRA published the Medical Devices (Amendment) Regulations 2026 in draft, introducing explicit cybersecurity obligations for software medical devices and a Predetermined Change Control Plan (PCCP) pathway. A dedicated AI-as-a-Medical-Device regulatory framework including AI lifecycle cybersecurity requirements is expected to follow later in 2026.
UK MHRA 2026 Regulatory Roadmap
Australia — TGA SaMD Guidance (February 2026)
On 24 February 2026, the TGA released updated guidance on regulating software-based medical devices (SaMD), including AI and digital health technologies. The guidance explicitly requires manufacturers to incorporate cyber resilience in design and post-market monitoring, aligning with international IMDRF principles.
TGA Medical Device Cybersecurity
Canada — Health Canada Guidance Updates
Health Canada published new guidance in March–April 2026 lowering the threshold for what constitutes a ‘significant change’ to a licensed device, with cybersecurity and software changes explicitly called out. Post-market surveillance and lifecycle-based compliance requirements are strengthened.
Health Canada guidance updates
EU — NIS2 Directive Implementation
EU member states are progressing NIS2 national transposition. Medical device manufacturers classified as ‘important entities’ (most manufacturers) must complete full implementation of baseline cybersecurity measures by October 2026. Essential entities (devices critical during public health emergencies) face both ex ante and ex post supervisory measures.
Core obligations: proportionate risk-management measures, significant incident notification to national CSIRT, cybersecurity training for management and staff, strong authentication and encryption.
NIS2 and the healthcare sector
5. Standards Spotlight — IEC 81001-5-1 Harmonisation Timeline
IEC 81001-5-1:2021 (“Safety, effectiveness and security in the implementation and use of connected medical devices or connected health software — Part 5-1: Security”) is formally scheduled for EU harmonisation on 27 May 2028. Once harmonised under the MDR/IVDR, compliance will create a presumption of conformity with cybersecurity requirements in Annex I.
Manufacturers integrating IEC 81001-5-1 now will be positioned ahead of the harmonisation date and aligned with EU notified body expectations. The EU has already included IEC 81001-5-1 in its harmonisation application list, confirming the 2028 target is firm.
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.