Standards, Guidance & Notices
Showing 1–5 of 5
MHLW
Notice
Notice
MHLW-PFSB-MDED-0825-No.1
Guideline on the Introduction and Operation of SBOM for Medical Devices (1st Edition)
Guideline compiled under the FY2025 Medical Device Cybersecurity Promotion Project and circulated to industry by MHLW notice for reference. It covers all software contained in a medical device and sets out a stepwise adoption path according to organizational maturity: Stage 1 establishes the capability to create, update and change-manage SBOMs based on the NTIA minimum elements; Stage 2 integrates SBOMs into existing QMS and post-market safety processes, including vulnerability, license and EOL/EOS management, for lifecycle risk management. SPDX 2.2 or later and CycloneDX 1.6 or later are recommended for new adoption; where SWID is already in use, parallel use or conversion may be considered. As the disclosure baseline set by the guideline, manufacturers should be able to provide SBOMs to healthcare facilities, mainly at installation and upon significant software changes, and present them on request at least throughout the product support period. Intended readers span software development, quality assurance, regulatory affairs, PSIRT/information security and field service, as a shared cross-functional reference. Article 12(3) of the Essential Principles and FD&C Act Section 524B are cited as regulatory background.
Published: 2026-08-25
NIST
SP
SP
SP 800-161 Rev. 1
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
Organizations are concerned about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain. These risks are associated with an enterprise’s decreased visibility into and understanding of how the technology they acquire is developed, integrated, and deployed or the processes, procedures, standards, and practices used to ensure the security, resilience, reliability, safety, integrity, and quality of the products and services.
This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. The publication integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multilevel, C-SCRM-specific approach, including guidance on the development of C-SCRM strategy implementation
Published: 2024-11-01
MHLW
Notice
Notice
MHLW-PFSB-MDED-0328-No.1
Guidance on Vulnerability Management to Ensure Cybersecurity of Medical Devices
Notice on post-market vulnerability management framework. Requires manufacturers/distributors to integrate vulnerability monitoring, evaluation, response, and disclosure processes (including SBOM utilization) into quality management systems. Mandates establishment of PSIRT structure, clear vulnerability notification policies to customers, and practical end-of-life support management procedures.
Published: 2024-03-28
NIST
SP
SP
SP 800-82 Rev. 3
Guide to Operational Technology (OT) Security
This document provides guidance on how to secure operational technology (OT) while addressing their unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. The document provides an overview of OT and typical system topologies, identifies common threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks.
Published: 2023-09-28
IMDRF
IMDRF/CYBER WG/N73 FINAL:2023
Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity
Final document of the IMDRF Medical Device Cybersecurity Working Group on the Software Bill of Materials (SBOM), complementing the medical device cybersecurity principles set out in IMDRF N60. It provides recommendations for medical device manufacturers on creating, maintaining, and distributing SBOMs, and for healthcare providers on receiving and managing them. It also describes how both manufacturers and healthcare providers can use SBOMs in risk management, vulnerability management, and incident response across the total product life cycle.
Published: 2023-04-13
