Standards, Guidance & Notices
Showing 1–10 of 129
FDA
CDRH
CDRH
FDA-2026-N-9505
FDA Issues Draft Guidance on Robotically-Assisted Surgical Devices, Announces December Workshop
On September 25, 2026, FDA released a draft guidance, "Robotically-Assisted Surgical Devices – Premarket Submissions" (Document ID: GUI01500081; Docket No. FDA-2026-N-9505). The guidance applies to teleoperated, software-controlled RASDs directly controlled by a qualified practitioner; fully autonomous and remotely teleoperated RASDs are explicitly out of scope, with manufacturers of such systems directed to the Q-Submission Program. Topics addressed include cybersecurity (network vulnerability assessment and penetration testing under FD&C Act Section 524B), human factors (use-error identification, training validation, multi-user team dynamics), software verification/validation, substantial equivalence comparisons for 510(k) submissions, reliability testing, wireless coexistence risk management per AAMI TIR69, and reprocessing validation. The public comment period closes November 24, 2026. FDA's Center for Devices and Radiological Health will separately hold a public workshop, "Evaluating Benefit-Risk in Robotic Medical Devices with Autonomous or Remote Teleoperation Capabilities" — addressing the very categories excluded from this guidance — on December 2-3, 2026, in person and virtually.
Published: 2026-09-25
EU
MDCG
MDCG
MDCG 2020-16 rev.5
Guidance on Classification Rules for in vitro Diagnostic Medical Devices under Regulation (EU) 2017/746
Revision 5 (September 2026) of the MDCG guidance on interpreting the classification rules in Annex VIII of the IVDR (Regulation (EU) 2017/746). It sets out the principles for classifying IVDs into classes A to D based on intended purpose and inherent risk, and provides the rationale and non-exhaustive examples for each of Rules 1 to 7. Software that drives or influences the use of a device falls within the same class as the device, while software independent of any other device is classified in its own right, with reference to MDCG 2019-11. Annexes provide examples of classifying IVDs used in combination and a flowchart to help determine whether an IVD is a companion diagnostic. Revision 5 clarifies the rationale of Rule 7 (controls without an assigned value) and revises its examples. The guidance is not legally binding.
Published: 2026-09-01
MHLW
Notice
Notice
MHLW-PFSB-MDED-0825-No.1
Guideline on the Introduction and Operation of SBOM for Medical Devices (1st Edition)
Guideline compiled under the FY2025 Medical Device Cybersecurity Promotion Project and circulated to industry by MHLW notice for reference. It covers all software contained in a medical device and sets out a stepwise adoption path according to organizational maturity: Stage 1 establishes the capability to create, update and change-manage SBOMs based on the NTIA minimum elements; Stage 2 integrates SBOMs into existing QMS and post-market safety processes, including vulnerability, license and EOL/EOS management, for lifecycle risk management. SPDX 2.2 or later and CycloneDX 1.6 or later are recommended for new adoption; where SWID is already in use, parallel use or conversion may be considered. As the disclosure baseline set by the guideline, manufacturers should be able to provide SBOMs to healthcare facilities, mainly at installation and upon significant software changes, and present them on request at least throughout the product support period. Intended readers span software development, quality assurance, regulatory affairs, PSIRT/information security and field service, as a shared cross-functional reference. Article 12(3) of the Essential Principles and FD&C Act Section 524B are cited as regulatory background.
Published: 2026-08-25
NIST
CSF 2.0
CSF 2.0
NIST SP 1353 (Initial Public Draft)
NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting
Illustrates structured AI prompts for CSF 2.0 policy review, Current State Profile, and Target State Profile drafting; comments due Oct 15, 2026.
Published: 2026-08-19
FDA
CDRH
CDRH
fda_20260819_Considerations_Regulation_Gene
Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback
Discussion paper led by the Digital Health Center of Excellence (DHCoE) within FDA CDRH, seeking stakeholder input on the challenges of generative AI (GenAI)-enabled medical devices, which may introduce unique risks compared with traditional software and AI-enabled devices, and on ways to advance regulatory approaches for them. It poses questions on four topics: risk assessment, premarket evaluation, postmarket monitoring, and other topics relevant to regulation. FDA states that the paper is for discussion purposes only, does not represent draft or final guidance, and does not communicate the proposed or final regulatory expectations of CDRH. Feedback may be submitted to docket FDA-2026-N-7874 on Regulations.gov by October 19, 2026.
Published: 2026-08-19
IMDRF
IMDRF/SaMD WG/N90 FINAL:2026
Essential Principles and Content of Predetermined Change Control Plans
Final document of the IMDRF Software as a Medical Device Working Group setting out high-level principles for Predetermined Change Control Plans (PCCPs), through which manufacturers can seek authorization in advance for certain planned modifications to medical device software (as defined in N81) that remain within the original intended use or intended purpose. It identifies five essential principles (focused and bounded, risk-based, evidence-based, transparent, and TPLC perspective) and three interconnected elements: Description of Changes, Change Plan (performance evaluation methods with pre-specified acceptance criteria, and update procedures including labelling and communication to users), and Impact Assessment (individual and cumulative benefits, risks and mitigations). Changes are expected to be implemented under the quality management system of the manufacturer, in line with standards such as IEC 62304. It also discusses benefits and challenges, including more complex submissions and differing adoption across jurisdictions. The document aims to support international convergence and does not establish regulatory requirements or serve as regulation or guidance in any jurisdiction.
Published: 2026-08-06
ISO
ISO 81001-1 Ed.2
ISO 81001-1 Ed.2 - Health Software and Health IT Systems - Safety, Effectiveness and Security - Part 1: Principles and Concepts
ISO 81001-1 Edition 2 establishes fundamental principles and conceptual frameworks for ensuring safety, effectiveness, and security of health software and health information technology systems. Currently in Committee Draft (CD) stage under ISO/TC 210/WG1, the document is undergoing international standardization review with a voting deadline of March 27, 2026. This standard serves as a foundational framework supporting medical device software regulation globally, providing overarching principles that align with and complement harmonized standards including IEC 62304, ISO 14971, and others. The document addresses the integrated governance of safety, effectiveness, and cybersecurity across the health software lifecycle. Manufacturers should reference this standard to establish consistent quality management approaches and risk governance frameworks applicable to health software and IT systems. Edition 2 reflects evolving regulatory expectations regarding artificial intelligence, machine learning, and connected health technologies in the medical device ecosystem.
Published: 2026-08-05
NIST
SP
SP
SP 800-213 Rev. 1
IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements
Organizations increasingly use Internet of Things (IoT) products for the mission benefits they can offer, but care must be taken in the acquisition and implementation of this equipment. Understanding that an IoT product is a system element facilitates an understanding of how the IoT product must be considered in the risk management process. The acquisition and integration of an IoT product into an information system may alter the system’s risk assessment based on new risks introduced by the product. An updated risk assessment may require additional or new controls to be selected and implemented in the system. The guidelines in this publication focus on establishing product cybersecurity requirements to support security controls. This publication provides general considerations of how IoT products may impact an information system’s risk assessment and subsequent allocation of controls that may be necessary. Readers are encouraged to reference SP 800-30, Revision 1, Guide for
Published: 2026-06-24
ISO
ISO/TS 24971-2:2026
Medical devices — Guidance on the application of ISO 14971 — Part 2: Machine learning in artificial intelligence
Provides guidance on risks specific to artificial intelligence and machine learning, and on how to apply the risk management process of ISO 14971 to machine learning-enabled medical devices (MLMD). Intended to be used in conjunction with ISO 14971 and does not alter its requirements.
Published: 2026-06-17
MHLW
Notice
Notice
MHLW-PFSB-MDED-0615-No.1
Pilot Implementation of Prioritized Review and Other Measures for Software as a Medical Device and Related Products (MHLW Notice No. 0615-1, June 15, 2026)
MHLW notice continuing the pilot of prioritized review for software as a medical device (SaMD), conducted since FY2022 following a June 2022 Cabinet decision on the New Capitalism action plan, by setting designation requirements and accepting applications on a rolling basis. Eligible products are SaMD and physical medical devices with SaMD-equivalent program functions; products seeking approval under the rebalancing notice or the two-stage approval notice are excluded. All three requirements must be met: (1) innovativeness of the treatment, diagnostic or preventive method (programs that deliver content equivalent to clinical patient guidance to prompt behavior change at home are, in principle, not considered innovative); (2) medical usefulness for the target disease; and (3) intent and capability to file in Japan first or simultaneously (within three months), using the PMDA SAKIGAKE comprehensive evaluation consultation. Designated products receive priority consultation, priority review under Article 23-2-5, paragraph 10 of the PMD Act, coordination by a concierge, and eligibility for the support program for consultation and applications for innovative medical devices, with the aim of shortening the review period to six months or less after adequate pre-submission evaluation. The procedure runs from registration, hearing and preliminary screening to formal application and PMDA evaluation, with results reported to the Pharmaceutical Affairs Council and then published. Conditions for revoking designation are also specified.
Published: 2026-06-15
