LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (39)
Standards, Guidance & Notices
Showing 1–10 of 39
NIST
SP
SP 800-213 Rev. 1
IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements
DRAFT NEW Cybersecurity
Organizations increasingly use Internet of Things (IoT) products for the mission benefits they can offer, but care must be taken in the acquisition and implementation of this equipment. Understanding that an IoT product is a system element facilitates an understanding of how the IoT product must be considered in the risk management process. The acquisition and integration of an IoT product into an information system may alter the system’s risk assessment based on new risks introduced by the product. An updated risk assessment may require additional or new controls to be selected and implemented in the system. The guidelines in this publication focus on establishing product cybersecurity requirements to support security controls. This publication provides general considerations of how IoT products may impact an information system’s risk assessment and subsequent allocation of controls that may be necessary. Readers are encouraged to reference SP 800-30, Revision 1, Guide for
Published: 2026-06-24
NIST
IR
IR 8259 Rev. 1
Foundational Cybersecurity Activities for IoT Product Manufacturers
PUBLISHED Cybersecurity
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises.
Published: 2026-04-20
MHLW
Notice
Admin-Notice-2026-03-19_VPNSecurity
Notice on Strengthening Cybersecurity Measures for Network Devices such as VPN Equipment Connected to Medical Devices (Caution Alert) (Administrative Notice, March 19, 2026)
NEW Cybersecurity
Caution alert (administrative notice, 19 March 2026) issued by the Japanese Ministry of Health, Labour and Welfare (MHLW) in response to a rise in ransomware attacks that exploit VPN equipment and other network devices connected to medical devices. It calls on marketing authorization holders to (1) confirm, under maintenance contracts with healthcare facilities, who is responsible for managing attached network equipment such as VPN devices, (2) check that firmware is up to date and identify any devices that are no longer supported, and (3) strengthen security by informing facilities about unsupported devices and applying stronger authentication and access control.
Published: 2026-03-25
FDA
CDRH
FDA-2026-D-Cybersecurity-QMS
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FINAL Cybersecurity
Under Section 524B of the FD&C Act, added by the 2023 Consolidated Appropriations Act, this guidance requires SBOM submission, a vulnerability disclosure process, and coordinated vulnerability disclosure (CVD) planning as part of premarket review. The title change from "Quality System" to "Quality Management System" reflects FDA's move from the legacy QSR to the ISO 13485-based QMSR. IEC 81001-5-1 and AAMI TIR57 appear as two of several optional frameworks manufacturers may draw on for secure product development — alongside JSP2 and ISA/IEC 62443-4-1 — rather than as standards the guidance formally aligns with.
Published: 2026-02-03
AAMI
TIR
AAMI CR515:2025
AAMI CR515:2025 - Cybersecurity Considerations Specific to Machine Learning-enabled Medical Devices
PUBLISHED Cybersecurity
AAMI CR515:2025 establishes cybersecurity considerations specific to machine learning-enabled medical devices. Recognized by the FDA as a consensus standard (Recognition Number: 13-153) on December 22, 2025, the document serves as a normative reference in the Software/Informatics domain. The standard specifies security risk management requirements essential for the development and operational deployment of medical devices incorporating artificial intelligence and machine learning technologies. Manufacturers should implement the specified cybersecurity controls and risk management procedures to address vulnerabilities introduced by machine learning algorithms, including model drift, adversarial attacks, and data integrity threats. The document provides manufacturers with practical guidance for integrating cybersecurity considerations throughout the device lifecycle, from initial algorithm development through post-market surveillance and model updates.
Published: 2025-12-22
IEC
IEC TS 81001-2-2:2025
Health software and health IT systems safety, effectiveness and security — Part 2-2: Coordination — Guidance for the implementation, disclosure and communication of security needs, risks and controls
PUBLISHED Cybersecurity
Withdraws and replaces IEC TR 80001-2-2. Provides guidance for communication of security needs, risks and controls for health software connected to IT networks.
Published: 2025-10-01
NIST
IR
IR 8259 Rev. 1 (2pd)
Foundational Cybersecurity Activities for IoT Product Manufacturers
DRAFT Cybersecurity
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises.
Published: 2025-09-30
JFMDA
Notice
jfmda_20250929_33bce5c8
Alert Regarding the Expiration of Windows Secure Boot Certificates
PUBLISHED Cybersecurity
For medical devices running Windows under an embedded license agreement, from Windows Embedded 8 Standard onward, that use the Secure Boot function, the expiration of the Secure Boot certificates in June 2026 may have serious impacts, such as the devices no longer being able to receive subsequent security updates or becoming unstable all at once. JFMDA asks readers to read the attached alert and take action. Issued by the Medical Device Cybersecurity WG of the JFMDA Liaison and Coordination Meeting.
Published: 2025-09-29
NIST
CSWP
CSWP 33
Product Development Cybersecurity Handbook: Concepts and Considerations for IoT Product Manufacturers
DRAFT Cybersecurity
As interest in Internet of Things (IoT) technologies has grown, so have concerns and attention to cybersecurity of the newly network-connected products and services offered in many sectors, including energy services, water/waste-water services, automobiles, consumer electronics, and government. This Product Development Cybersecurity Handbook will describe concepts important to developing and deploying secure IoT products for any sector or use case, including discussion of IoT Product architecture, deployment, roles and cybersecurity perspectives. This publication extends and elaborates on NIST’s prior work related to development of IoT products. In addition to discussing the concepts, this publication also demonstrates their application and discusses how satisfaction of cybersecurity in IoT products can be approached.
Published: 2024-04-03
NIST
CSWP
CSWP 29
The NIST Cybersecurity Framework (CSF) 2.0
PUBLISHED Cybersecurity
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.
Published: 2024-02-26
1 2 3 4 ›