LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 13, 2026
MSC Portal Regulatory Watch All Entries (49)
Standards, Guidance & Notices
Showing 1–10 of 49
FDA
CDRH
fda_20260625_Notification_on_Data_Integrity
Notification on Data Integrity
PUBLISHED NEW Cybersecurity
The FDA CDRH remains vigilant in ensuring the reliability of data submitted in support of medical device submissions. The Agency has determined that CCIC Huatongwei International Inspection (Suzhou) Co., Ltd. generated false, copied, or otherwise invalid test data submitted to FDA across multiple studies. Consequently, all study data from this testing facility will be rejected until the firm adequately addresses these data integrity issues. Device manufacturers and sponsors are reminded to conduct rigorous evaluation and oversight of third-party testing facilities to ensure compliance with FDA data integrity standards and Good Laboratory Practice requirements.
Published: 2026-06-25
NIST
SP
SP 800-213 Rev. 1
IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements
DRAFT NEW Cybersecurity
Organizations increasingly use Internet of Things (IoT) products for the mission benefits they can offer, but care must be taken in the acquisition and implementation of this equipment. Understanding that an IoT product is a system element facilitates an understanding of how the IoT product must be considered in the risk management process. The acquisition and integration of an IoT product into an information system may alter the system’s risk assessment based on new risks introduced by the product. An updated risk assessment may require additional or new controls to be selected and implemented in the system. The guidelines in this publication focus on establishing product cybersecurity requirements to support security controls. This publication provides general considerations of how IoT products may impact an information system’s risk assessment and subsequent allocation of controls that may be necessary. Readers are encouraged to reference SP 800-30, Revision 1, Guide for
Published: 2026-06-24
NIST
SP
SP 800-172A Rev. 3
Assessing Enhanced Security Requirements for Controlled Unclassified Information
PUBLISHED NEW Cybersecurity
The protection of controlled unclassified information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with assessment procedures for the enhanced security requirements in NIST SP 800-172. The assessment procedures are flexible and can be tailored to the needs of federal agencies and assessors. Security requirement assessments can be conducted as (1) self-assessments; (2) independent, third-party assessments; or (3) government-sponsored assessments. The assessments can be conducted with varying degrees of rigor based on federal agency-defined depth and coverage attributes. The findings and evidence produced during the assessments can be used to facilitate risk-based decisions by organizations related to the security requirements.
Published: 2026-05-13
NIST
SP
SP 800-172 Rev. 3
Enhanced Security Requirements for Protecting Controlled Unclassified Information
PUBLISHED NEW Cybersecurity
The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with a set of recommended enhanced security requirements for providing additional protection to the confidentiality, integrity, and availability of CUI when it is resident in a nonfederal system and organization and associated with a critical program or high value asset (HVA). It is designed as a supplement to NIST Special Publication (SP) 800-171 to protect against advanced persistent threats (APTs). The security requirements apply to the components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components only when selected and required by federal agencies to manage risks to CUI. The enhanced security requirements are i
Published: 2026-05-13
NIST
IR
IR 8259 Rev. 1
Foundational Cybersecurity Activities for IoT Product Manufacturers
PUBLISHED Cybersecurity
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises.
Published: 2026-04-20
MHLW
Notice
Admin-Notice-2026-03-19_VPNSecurity
Notice on Strengthening Cybersecurity Measures for Network Devices such as VPN Equipment Connected to Medical Devices (Caution Alert) (Administrative Notice, March 19, 2026)
NEW Cybersecurity
MHLW caution alert regarding cybersecurity measures for VPN devices and network equipment connected to medical devices, emphasizing the need for strengthened security protocols to protect medical device networks from cyber threats.
Published: 2026-03-25
FDA
CDRH
FDA-2026-D-Cybersecurity-QMS
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FINAL NEW Cybersecurity
Replaces the September 2023 final guidance. Title updated from "Quality System" to "Quality Management System" reflecting the QMSR final rule (21 CFR Part 820, effective February 2, 2026), which incorporates ISO 13485:2016 by reference. Core requirements for SPDF, premarket cybersecurity documentation, SBOM submission, and CVD policy remain. Adds terminology (Threat surface, Quality of Service) in Appendix 5.
Published: 2026-02-03
AAMI
TIR
AAMI CR515:2025
AAMI CR515:2025 - Cybersecurity Considerations Specific to Machine Learning-enabled Medical Devices
PUBLISHED Cybersecurity
AAMI CR515:2025 establishes cybersecurity considerations specific to machine learning-enabled medical devices. Recognized by the FDA as a consensus standard (Recognition Number: 13-153) on December 22, 2025, the document serves as a normative reference in the Software/Informatics domain. The standard specifies security risk management requirements essential for the development and operational deployment of medical devices incorporating artificial intelligence and machine learning technologies. Manufacturers should implement the specified cybersecurity controls and risk management procedures to address vulnerabilities introduced by machine learning algorithms, including model drift, adversarial attacks, and data integrity threats. The document provides manufacturers with practical guidance for integrating cybersecurity considerations throughout the device lifecycle, from initial algorithm development through post-market surveillance and model updates.
Published: 2025-12-22
IEC
IEC TS 81001-2-2:2025
Health software and health IT systems safety, effectiveness and security — Part 2-2: Coordination — Guidance for the implementation, disclosure and communication of security needs, risks and controls
PUBLISHED NEW Cybersecurity
Withdraws and replaces IEC TR 80001-2-2. Provides guidance for communication of security needs, risks and controls for health software connected to IT networks.
Published: 2025-10-01
JFMDA
Notice
jfmda_20250929_33bce5c8
Alert Regarding Validity Period of Windows Secure Boot Certificate
PUBLISHED Cybersecurity
Alert for medical devices running embedded Windows (Standard Edition 8 or later) with Secure Boot functionality enabled. Device manufacturers should verify secure boot certificate validity and plan for potential renewal to prevent operational disruptions in 2025.
Published: 2025-09-29
1 2 3 5