LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (39)
Standards, Guidance & Notices
Showing 11–20 of 39
MHLW
Notice
Admin-Notice-2024-01-31
Q&A on Cybersecurity of Medical Devices (2024 Version)
PUBLISHED Cybersecurity
Expanded Q&A set on application and conformance assessment of Essential Principles Article 12(3). Provides guidance on system architecture diagram formats, post-transition application handling, third-party testing utilization, SBOM documentation scope, and legacy product compliance strategies based on practical implementation experience.
Published: 2024-01-31
JFMDA
Notice
jfmda_20240129_f5a055dd
English Translation of Cybersecurity and Usability Notification
PUBLISHED Cybersecurity
Notice (29 January 2024) from the JFMDA Legislative Affairs Committee, Review-Related Subcommittee, announcing unofficial English translations, prepared by the PMDA Office of Medical Devices, of three MHLW notifications concerning medical device cybersecurity and usability: (1) Application of Article 12-3 of the Essential Principles for Medical Devices (PSEHB MDED Notification No. 0331-8, 31 March 2023); (2) Confirmation of compliance with Article 12-3 of the Essential Principles for Medical Devices (PSEHB MDED Notification No. 0523-1, 23 May 2023); and (3) Handling of the revised Japanese Industrial Standard (JIS) on usability engineering requirements for medical devices (PSEHB MDED and CND Notification No. 0930-1, 30 September 2022). The page notes that the translations are provided for reference only and that only the original Japanese texts have legal effect.
Published: 2024-01-29
MHLW
Notice
MHLW-PSEHB-PSD-0115-No.2
Fundamental Approach to Adverse Event Reporting Related to Medical Device Cybersecurity
PUBLISHED Cybersecurity
Notice clarifying handling of cybersecurity events in adverse event/serious adverse event reporting systems. Addresses reporting applicability for patient harm from cyber attacks or vulnerability exploitation, decision-making flowcharts, and manufacturer response procedures. Serves as foundational regulatory documentation for post-market cybersecurity management.
Published: 2024-01-15
MHLW
Notice
Admin-Notice-2023-07-20
Q&A on Application of Essential Principles Article 12(3) for Medical Devices
PUBLISHED Cybersecurity
Q&A addressing application and conformance assessment of Essential Principles Article 12(3). Covers transition period marketing approval application handling, submission documentation methods, third-party agency utilization for JIS T 81001-5-1 conformance, and reliability document review scope. References related MHLW regulatory notices issued in March and May 2023.
Published: 2023-07-20
MHLW
Notice
MHLW-PSEHB-MDED-0523-No.1
Conformance Assessment Procedures for Essential Principles Article 12(3) of Medical Devices
PUBLISHED Cybersecurity
Notice specifying concrete compliance assessment considerations for Essential Principles Article 12(3). Details additional verification items against JIS T 81001-5-1 provisions (general requirements, maintenance processes, configuration management). Requires demonstration of intended use environment through system/network architecture diagrams and integration of vulnerability notification activities into quality management systems.
Published: 2023-05-23
IMDRF
IMDRF/CYBER WG/N70 FINAL:2023
Principles and Practices for the Cybersecurity of Legacy Medical Devices
PUBLISHED Cybersecurity
Final document of the IMDRF Medical Device Cybersecurity Working Group on the cybersecurity of legacy medical devices, complementing IMDRF N60. It divides the total product life cycle for cybersecurity into four stages (Development, Support, Limited Support, and End of Support (EOS)) and sets out the responsibilities and expectations of medical device manufacturers and healthcare providers at each stage in three areas: communication, risk management, and transfer of responsibility. Responsibility shifts from the manufacturer to the healthcare provider as the life cycle progresses, and cybersecurity responsibility for devices used beyond the EOS communicated by the manufacturer rests entirely with the healthcare provider. The document also notes that the end of life or end of support of a software or firmware component can prematurely move the device itself into a later stage, which manufacturers should address in advance.
Published: 2023-04-11
MHLW
Notice
医政参発0331-No.1
Guideline for Ensuring Cybersecurity of Medical Devices in Healthcare Facilities
PUBLISHED Cybersecurity
MHLW notification of Cybersecurity Guideline for healthcare facility administrators and staff. Presents practical procedures for information collection from manufacturers, risk assessment, pre-implementation verification, vulnerability response during operation, and EOL management. Positioned as the healthcare facility counterpart to the related manufacturer-directed guideline, structured to promote coordination between both parties.
Published: 2023-03-31
MHLW
Notice
MHLW-PSEHB-MDED-0331-No.11
Revision of Cybersecurity Implementation Guideline for Medical Devices
PUBLISHED Cybersecurity
MHLW notification of revised Cybersecurity Guideline for Medical Device Manufacturers (2nd Edition). Updated to align with Essential Principles Article 12(3) implementation. Provides practical procedures for security requirements identification, architecture design, SBOM, PSIRT establishment, and vulnerability disclosure. Functions as specific guidance for JIS T 81001-5-1 application.
Published: 2023-03-31
MHLW
Notice
MHLW-PSEHB-MDED-0331-No.8
Notice on Application of Essential Principles Article 12(3) for Medical Devices
PUBLISHED Cybersecurity
Interpretation notice accompanying April 1, 2023 enforcement of Essential Principles Article 12(3) cybersecurity requirements. Mandates three elements for network-connected medical devices: lifecycle cybersecurity planning, risk reduction design, and minimum operational environment specifications. Recognizes JIS T 81001-5-1 conformance as equivalent to Article 12(3) compliance. Provides transition period until March 31, 2024.
Published: 2023-03-31
JIS
Std
JIS T 81001-5-1:2023
JIS T 81001-5-1:2023 Health software and health IT system safety, efficacy and security - Part 5-1: Security - Activities in the product lifecycle (equivalent to IEC 81001-5-1:2021)
PUBLISHED Cybersecurity
This JIS standard specifies cybersecurity activities that medical device manufacturers must implement in addition to the software lifecycle processes defined in JIS T 2304, corresponding to IEC 81001-5-1:2021. The document establishes requirements for managing security risks throughout the product lifecycle, addressing threats related to unauthorized access, data integrity, and system availability. Enacted on February 25, 2023, and effective from April 1, 2024, this standard was developed by JEITA (Japan Electronics and Information Technology Industries Association) as a draft originator. The standard is positioned as a conformance specification for Article 12, Paragraph 3 of Japan's Medical Device Basic Requirements Standards (Yakuhin Kikai Kihon Youken Kijun). Manufacturers should integrate the cybersecurity activities outlined herein with their existing software development processes to ensure comprehensive protection against evolving security threats throughout the device lifecycle.
Published: 2023-02-25
‹ 1 2 3 4 ›