← All resourcesGlobal Regulations
Global medical device cybersecurity regulations & guidance
Organizations bringing software- or firmware-containing medical devices to market may need to comply with these regulations depending on where the device is marketed. Requirements evolve quickly — treat this as a reference map, not a substitute for current legal/regulatory review.
| Document | Year | Region | Description |
|---|---|---|---|
| Best Practices Guide for Medical Device Cybersecurity, Revision 1 | Aug 2026 | Singapore (HSA) | The finalised Best Practices Guide for Medical Device Cybersecurity after incorporating feedback from public consultation |
| Guidance Document on Medical Device Software | Jul 2026 | India (CDSCO) | Final guidance under the Medical Devices Rules, 2017, covering software risk classification, cybersecurity risk assessment, penetration testing, and post-market surveillance for AI/ML and cloud-connected devices. |
| Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Final Guidance) | Feb 2026 | United States (FDA) | Adds statutory provisions under section 524B of the FD&C Act; the 2026 revision aligns to the QMSR. |
| Quality Management System Regulation (QMSR) | Feb 2026 | United States (FDA) | Replaced the legacy QSR effective February 2, 2026; incorporates ISO 13485:2016 and embeds cybersecurity into risk management, design controls, validation, and post-market surveillance. |
| Inspection of Medical Device Manufacturers (Compliance Program 7382.850) | Feb 2026 | United States (FDA) | QMSR-aligned inspection manual replacing QSIT (CP 7382.845) and the PMA inspection program (CP 7383.001); organizes inspections around six total-product-lifecycle QMS areas, including design/development and risk management, that intersect with cybersecurity obligations. |
| Digital Medical Products Act (DMPA) | 2024 / Jan 2026 | South Korea (MFDS) | Establishes a legal category for digital health products, mandating cybersecurity controls and SBOMs; the January 2026 amendment clarified the legal basis for wired/wireless communication devices. |
| Complying with Medical Device Cyber Security Requirements | 2022 (updated Oct 2025) | Australia (TGA) | TGA guidance on meeting cybersecurity requirements for medical device approval. |
| Digital Medical Device Electronic Intrusion Security Guidelines | Jan 2025 | South Korea (MFDS) | Sets technical and physical security requirements for connected devices: encryption, access controls, secure communication, lifecycle risk management, and vulnerability monitoring. |
| Management of Vulnerabilities to Ensure Cybersecurity of Medical Devices | Mar 2024 | Japan (MHLW) | Notification on post-market vulnerability management responsibilities for manufacturers. |
| Basic Principles for Adverse Events Reporting Regarding Cybersecurity of Medical Devices | Jan 2024 | Japan (MHLW) | Notification establishing when a cybersecurity vulnerability or incident must be reported as an adverse event. |
| Regulation (EU) 2024/2847 — Cyber Resilience Act | 2024 (in force 2027) | European Union | Horizontal cybersecurity regulation covering digital products; medical devices are largely governed by MDR/IVDR instead, but adjacent connected products can fall in scope. |
| Cybersecurity Labelling Scheme for Medical Devices (CLS MD) | 2024 | Singapore (CSA/MOH/HSA) | Voluntary multi-level cybersecurity label scheme for medical devices. |
| Good Machine Learning Practice & Transparency Principles | 2024 | United Kingdom (MHRA) | Joint principles for good machine learning practice and transparency in ML-enabled medical devices. |
| Transparency for Machine Learning-Enabled Medical Devices: Guiding Principles | 2024 | United States (FDA) | The FDA counterpart to the UK MHRA transparency principles above — joint guiding principles for transparency in ML-enabled medical devices. |
| Guidelines for Cybersecurity Approval and Review of Medical Devices (Guide-0095-03) | Jul 2023 | South Korea (MFDS) | Requires submission of a Cybersecurity Requirements Checklist and a Cyber Security Risk Management Document. |
| Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity (IMDRF/CYBER WG/N73 FINAL:2023 Edition 1) | Apr 2023 | IMDRF | Recommendations for SBOM generation, management, and distribution; includes recommendations for healthcare providers. |
| Principles and Practices for the Cybersecurity of Legacy Medical Devices (IMDRF/CYBER WG/N70 FINAL:2023 Edition 1) | Apr 2023 | IMDRF | Addresses legacy devices in a total-product-lifecycle context, with recommendations for manufacturers and healthcare providers. |
| Directive (EU) 2022/2555 — NIS 2 Directive | 2023 | European Union | Expands cybersecurity risk-management and incident-reporting obligations for healthcare and device manufacturer entities. |
| Essential Requirements — Article 12 Clause 3 on Cybersecurity | 2023 | Japan (MHLW/PMDA) | Amendment requiring JIS T 81001-5-1 compliance for internet-connected medical device software; enforcement began April 1, 2023. |
| Federal Food, Drug, and Cosmetic Act (FD&C Act) Section 524B, Ensuring Cybersecurity of Devices | Dec 2022 | United States (FDA) | Consolidated Appropriations Act, 2023, signed December 29, 2022, amended the FD&C Act to add Section 524B. |
| Medical Device Cybersecurity Vulnerability Identification & Assessment Methodology (Draft) | 2022 | China (State Drug Administration) | Draft methodology for identifying and assessing device cybersecurity vulnerabilities, published November 2022. |
| Guidance for Industry on Management of Cybersecurity in Medical Devices | May 2021 | Taiwan (TFDA) | Covers premarket cybersecurity review expectations, cybersecurity testing, and postmarket monitoring and hazard reporting. |
| Guidance on Cybersecurity for Medical Devices (MDCG) | Jul 2020 | European Union | Guidance on fulfilling the essential requirements of MDR/IVDR Annex I relating to cybersecurity. |
| Principles and Practices for Medical Device Cybersecurity (IMDRF/CYBER WG/N60 FINAL:2020) | Apr 2020 | IMDRF | General principles and best practices supporting international regulatory convergence. |
| Guidelines for the Security Assessment of Medical Devices | 2020 | China (NMPA/CAC) | Cybersecurity assessment methodology applied as part of device registration. |
| Principles and Practices of Cyber Security in Medical Devices (Guide No. 38/2020) | 2020 | Brazil (GGTPS) | Adopts IMDRF guidance via the General Management of Health Products Technology. |
| Guidance Document: Pre-market Requirements for Medical Device Cybersecurity | 2019 | Canada (Health Canada) | Pre-market cybersecurity expectations for medical device submissions. |
| Guidance to Post-Market Cybersecurity of Medical Devices (MDS-G37) | 2019 | Saudi Arabia (SFDA) | Post-market cybersecurity expectations for medical devices, part of the SFDA medical device guidance library. |
| Guidance to Pre-Market Cybersecurity of Medical Devices (MDS-G38) | 2019 | Saudi Arabia (SFDA) | Companion pre-market cybersecurity guidance to MDS-G37, covering security risk controls for networked medical devices. |
| Guidance on Ensuring Cyber Security of Medical Devices | 2018 | Japan (MHLW) | Practical guidance covering pre-market design and post-market cybersecurity risk management. |
| Cyber Security Requirements for Network-Connected Medical Devices | 2018 | Germany (BSI) | Recommendations for meeting cybersecurity expectations under the (now superseded) Medical Device Directive. |
| Regulation (EU) 2017/745 on Medical Devices (MDR) | 2017 | European Union | Cybersecurity requirements addressed within the risk management provisions of Annex I, §17.4. |
| Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR) | 2017 | European Union | Cybersecurity obligations broadly similar to those under the MDR. |
| Postmarket Management of Cybersecurity in Medical Devices (Guidance) | 2016 | United States (FDA) | FDA guidance covering post-market cybersecurity vulnerability and risk management. |
| HIPAA Security Rule (45 CFR Part 160, Part 164 Subparts A & C) | 2003 (amended 2013) | United States (HHS) | Administrative, physical, and technical safeguard requirements for electronic protected health information (ePHI) — applies to connected devices and systems that create, receive, maintain, or transmit ePHI. The 2013 HIPAA Omnibus Final Rule extended direct liability to business associates and updated breach notification and enforcement provisions. |
Last updated: August 2026
Not sure which regulations apply to you?
We'll map your target markets to the specific requirements you need to meet.
