Overview

Medical-device cybersecurity is a safety, performance and lifecycle discipline. The same device can need FDA submission evidence, EU MDR technical documentation, health-software lifecycle controls, a threat model, an SBOM, labelling for users, and a postmarket vulnerability process. Those records are related, but they do not come from one global rule.

Medical-device topic map

This topic cluster treats cybersecurity as a device-domain problem rather than as one compliance checklist. Start with the jurisdiction that controls the decision in front of you, then use the lifecycle pages to connect the evidence.

FDA premarket evidence

Current FDA premarket guidance asks for secure product development evidence, security risk management, threat modelling, architecture views, SBOM information, security testing, labelling and a cybersecurity management plan. Section 524B adds statutory content for qualifying cyber devices.

FDA postmarket management

FDA postmarket guidance is organised around lifecycle monitoring, controlled and uncontrolled risk, routine updates, coordinated vulnerability disclosure, customer communication, ISAO participation and the 21 CFR part 806 reporting boundary.

EU MDR and MDCG evidence

EU work starts from MDR/IVDR general safety and performance requirements, including software lifecycle, information-security risk management, minimum IT requirements, user information, PMS, vigilance and technical documentation. MDCG 2019-16 explains how those obligations are commonly understood.

Lifecycle records

IEC 81001-5-1, SBOMs, architecture diagrams, threat models, vulnerability handling and security testing can support regulatory submissions, technical files and postmarket maintenance. They do not replace the legal requirements themselves.

Reading order

  1. FDA premarket cybersecurity for submission content, section 524B, security architecture, testing, labelling and management plans.
  2. FDA postmarket management for vulnerability monitoring, controlled and uncontrolled risk, routine updates, coordinated disclosure and field corrections.
  3. EU MDR and MDCG cybersecurity for Annex I software/security hooks, intended operating environment evidence, user information, PMS and vigilance.
  4. IEC 81001-5-1 for the secure health-software lifecycle process that can support FDA and EU evidence without replacing either framework.
  5. SBOMs and threat modelling for the two records most often confused with each other, and for how they connect to architecture, testing and postmarket monitoring.

Regulatory split

The practical boundary is simple: FDA sources govern FDA submissions and FDA postmarket expectations; MDR/IVDR sources govern EU conformity evidence; IEC and ISO standards describe lifecycle practices; SBOM and threat-modelling material describes evidence methods. A strong dossier keeps those layers connected without treating them as interchangeable.

Primary sources

Sources