Overview
Medical-device cybersecurity is a safety, performance and lifecycle discipline. The same device can need FDA submission evidence, EU MDR technical documentation, health-software lifecycle controls, a threat model, an SBOM, labelling for users, and a postmarket vulnerability process. Those records are related, but they do not come from one global rule.
Medical-device topic map
This topic cluster treats cybersecurity as a device-domain problem rather than as one compliance checklist. Start with the jurisdiction that controls the decision in front of you, then use the lifecycle pages to connect the evidence.
FDA premarket evidence
Current FDA premarket guidance asks for secure product development evidence, security risk management, threat modelling, architecture views, SBOM information, security testing, labelling and a cybersecurity management plan. Section 524B adds statutory content for qualifying cyber devices.
FDA postmarket management
FDA postmarket guidance is organised around lifecycle monitoring, controlled and uncontrolled risk, routine updates, coordinated vulnerability disclosure, customer communication, ISAO participation and the 21 CFR part 806 reporting boundary.
EU MDR and MDCG evidence
EU work starts from MDR/IVDR general safety and performance requirements, including software lifecycle, information-security risk management, minimum IT requirements, user information, PMS, vigilance and technical documentation. MDCG 2019-16 explains how those obligations are commonly understood.
Lifecycle records
IEC 81001-5-1, SBOMs, architecture diagrams, threat models, vulnerability handling and security testing can support regulatory submissions, technical files and postmarket maintenance. They do not replace the legal requirements themselves.
Reading order
- FDA premarket cybersecurity for submission content, section 524B, security architecture, testing, labelling and management plans.
- FDA postmarket management for vulnerability monitoring, controlled and uncontrolled risk, routine updates, coordinated disclosure and field corrections.
- EU MDR and MDCG cybersecurity for Annex I software/security hooks, intended operating environment evidence, user information, PMS and vigilance.
- IEC 81001-5-1 for the secure health-software lifecycle process that can support FDA and EU evidence without replacing either framework.
- SBOMs and threat modelling for the two records most often confused with each other, and for how they connect to architecture, testing and postmarket monitoring.
Regulatory split
The practical boundary is simple: FDA sources govern FDA submissions and FDA postmarket expectations; MDR/IVDR sources govern EU conformity evidence; IEC and ISO standards describe lifecycle practices; SBOM and threat-modelling material describes evidence methods. A strong dossier keeps those layers connected without treating them as interchangeable.
Primary sources
Sources
- FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, final guidance, February 2026
- FDA, Postmarket Management of Cybersecurity in Medical Devices, final guidance, December 2016
- European Commission, MDCG guidance documents and MDCG 2019-16 cybersecurity guidance
- EUR-Lex, Regulation (EU) 2017/745 on medical devices
- IEC, IEC 81001-5-1:2021 Health software and health IT systems safety, effectiveness and security