Global Medical Device Cybersecurity Regulations & Guidances

This article lists key medical device cybersecurity regulations and guidance from major regulatory regions worldwide. Organizations working on bringing new medical devices containing software or firmware may be required to comply with one or more of these based on the country they are expected to be marketed.

Document TitleYearCountry / RegionDescription
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions (Final Guidance)June 2025United States (FDA)The 2025 FDA final guidance adds new statutory provisions under section 524B of the FD&C Act.
Federal Food, Drug, and Cosmetic Act (FD&C Act) section 524B,ย Ensuring Cybersecurity of Devices.Dec 2022United States (FDA)On December 29, 2022, the Consolidated Appropriations Act, 2023 (“Omnibus”) was signed into law amending FD&C Act to add section 524B.
Postmarket Management of Cybersecurity in Medical Devices (Guidance)2016United States (FDA)FDA postmarket cybersecurity guidance
Regulation (EU) 2017/745 on Medical Devices (MDR)2017European UnionMDR includes cybersecurity requirements in risk management Annexโ€ฏI ยง17.4
Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR)2017European UnionIVDR imposes cybersecurity obligations similar to MDR
Guidance of cybersecurity for medical devicesJuly 2020European UnionProvides manufacturers with guidance on how to fulfil all the relevant essential requirements of Annex I to the MDR and IVDR with regard to cybersecurity.ย 
Regulation (EU) 2024/2847 โ€“ Cyber Resilience Act2024 (comes into force 2027)European UnionHorizontal cybersecurity regulation covering digital products, including medical devices with digital elements
Directive (EU) 2022/2555 โ€“ NISโ€ฏ2 Directive2023European UnionExpands healthcare and medicalโ€‘device manufacturer obligations for cybersecurity risk management and incident reporting  
Essential Requirements โ€“ Articleโ€ฏ12 Clauseโ€ฏ3 on Cybersecurity (Japan)2023Japan (MHLW/PMDA)Amendment requiring compliance with JISโ€ฏTโ€ฏ81001โ€‘5โ€‘1 for internetโ€‘connected medical device software; enforcement began Aprilโ€ฏ1,โ€ฏ2023
โ€œEnsuring Cyber Security of Medical Devicesโ€ Notification (MHLW)2015JapanInitial notification on evaluating cybersecurity risk for devices
Guidance on Ensuring Cyber Security of Medical Devices (MHLW)2018JapanPractical guidance for preโ€‘market design and postโ€‘market cybersecurity risk management
Complying with Medical Device Cyber Security Requirements Guidance2022 (updated)Australia (TGA)TGA guidance; revised Essential Principleโ€ฏ12.1 from Febโ€ฏ25,โ€ฏ2021 
Best Practices Guide for Medical Device Cybersecurity (Draft)2025 (draft)Singapore (HSA/CSA)Public consultation document from March to Mayโ€ฏ2025
Cybersecurity Labelling Scheme for Medical Devices (CLSโ€ฏMD)2022Singapore (CSA/MOH/HSA)Voluntary multiโ€‘level label scheme launched 16โ€ฏOctโ€ฏ2024
Guidelines for the Security Assessment of Medical Devices2020China (NMPA/CAC)Cybersecurity assessment methodology for registration
Medical Device Cybersecurity Vulnerability Identification & Assessment Methodology (Draft)2022China (State Drug Administration)Published draft methodology in Novโ€ฏ2022 
Guidance Document: Pre-market Requirements for Medical Device Cybersecurity2019Canada (Health Canada)Health Canada pre-market cybersecurity guidance
Health Canada Cybersecurity Guidance2019CanadaHealth Canada pre-market cybersecurity guidance
MHRA & UK โ€“ Good Machine Learning Practice & Transparency Principles2024United Kingdom (UH MHRA)Joint GMLP / transparency principles for MLโ€‘enabled devices
  • United States: The 2025 FDA final guidance adds new statutory provisions under section 524B of the FD&C Act.
  • European Union: The MDR and IVDR embed cybersecurity requirements, while the NIS 2 and Cyber Resilience Act expand obligations for manufacturers and software products.
  • Japan: Starting from 2015, Japan developed formal requirements culminating in 2023 with mandatory cybersecurity conformance to JIS T 81001-5-1.

Last updated: July 2025