Standards, Guidance & Notices
Showing 11–20 of 27
MHLW
Notice
Notice
Admin-Notice-2023-07-20
Q&A on Application of Essential Principles Article 12(3) for Medical Devices
Q&A addressing application and conformance assessment of Essential Principles Article 12(3). Covers transition period marketing approval application handling, submission documentation methods, third-party agency utilization for JIS T 81001-5-1 conformance, and reliability document review scope. References regulatory notices 薬生機審発0331第8号 and 0523第1号.
Published: 2023-07-20
FDA
CDRH
CDRH
FDA-Device-Software-Functions-2023
Content of Premarket Submissions for Device Software Functions
This FDA final guidance (2023) specifies required documentation content for software in premarket submissions including 510(k), PMA, and De Novo pathways. The guidance provides structured requirements based on software risk level (minor, moderate, major) classification, recognizing that documentation scope should be proportionate to patient risk. For each software risk category, the document delineates specific submission requirements for design specifications, system architecture, verification and validation (V&V) documentation, cybersecurity considerations, and unmet need summaries. Manufacturers must provide detailed design specifications describing intended functionality and performance parameters, system architecture documentation explaining software structure and interfaces, comprehensive V&V documentation demonstrating safety and effectiveness testing, and cybersecurity management plans addressing relevant threats. The guidance replaces the previous "Content of Premarket Submissions for Software" document, incorporating contemporary regulatory expectations including artificial intelligence considerations, interoperability requirements, and cybersecurity standards. Compliance with these content requirements streamlines FDA review and supports timely device approval decisions.
Published: 2023-06-14
MHLW
Notice
Notice
Admin-Notice-2023-05-29
Publication of Guidance on Appropriate and Expedited Approval and Development of Software as Medical Devices (SaMD)
Practical guidance on expedited regulatory approval for SaMD including two-stage approval processes. Clarifies early marketing approval application handling across different development stages while maintaining consistent pre- and post-market safety/effectiveness assurance. Developed through public-private-academic collaboration as part of DASH for SaMD strategy, applicable to AI/ML-enabled SaMD.
Published: 2023-05-29
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0523-No.1
Conformance Assessment Procedures for Essential Principles Article 12(3) of Medical Devices
Notice specifying concrete compliance assessment considerations for Essential Principles Article 12(3). Details additional verification items against JIS T 81001-5-1 provisions (general requirements, maintenance processes, configuration management). Requires demonstration of intended use environment through system/network architecture diagrams and integration of vulnerability notification activities into quality management systems.
Published: 2023-05-23
IMDRF
IMDRF/CYBER WG/N73FINAL:2023
Principles and Practices for Software Bill of Materials (SBOM) in Medical Device Cybersecurity (FINAL 2023)
This document specifies IMDRF guidance on creating, managing, and sharing Software Bill of Materials (SBOM) for medical devices. It defines minimum SBOM elements, acceptable formats, and lifecycle management approaches necessary for effective cybersecurity management. Manufacturers should develop and maintain accurate SBOMs documenting all software components and dependencies throughout product lifecycle. The document provides the practical foundation for FDA 2023 final guidance SBOM submission requirements and supports implementation of Japan's vulnerability management notification requirements from the Ministry of Health, Labour and Welfare. SBOMs enable manufacturers, regulators, and healthcare organizations to identify and respond rapidly to software vulnerabilities affecting medical devices.
Published: 2023-04-01
IMDRF
IMDRF/CYBER WG/N70FINAL:2023
Principles and Practices for Cybersecurity of Legacy Medical Devices (FINAL 2023)
This document provides IMDRF guidance on managing cybersecurity risks in legacy medical devices that are end-of-life (EOL) or difficult to maintain. It clarifies responsibilities and practical mitigation strategies for both manufacturers and healthcare facilities. The document establishes frameworks for EOL management planning, identifying alternative solutions, and making informed risk acceptance decisions. As a complementary document to N60, it addresses the specific challenges posed by legacy systems that cannot be readily updated with security patches or improvements. Manufacturers and healthcare organizations should use this guidance to systematically assess legacy device risks and implement appropriate risk mitigation measures aligned with current cybersecurity standards.
Published: 2023-04-01
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.1
Partial Amendment of Guideline on Software as a Medical Device Classification
Revision of 2021 SaMD classification guideline (2023 version). Clarifies and refines classification criteria based on accumulated consultation cases. Adds judgment criteria for AI/ML-enabled software, cloud-based programs, and wellness applications. Maintains alignment with IMDRF N10 and N12. Updates judgment flow based on intended use and risk.
Published: 2023-03-31
MHLW
Notice
Notice
医政参発0331-No.1
Guideline for Ensuring Cybersecurity of Medical Devices in Healthcare Facilities
MHLW notification of Cybersecurity Guideline for healthcare facility administrators and staff. Presents practical procedures for information collection from manufacturers, risk assessment, pre-implementation verification, vulnerability response during operation, and EOL management. Positioned as healthcare facility version of manufacturer guideline (薬生機審発0331第11号), structured to promote coordination between both parties.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.11
Revision of Cybersecurity Implementation Guideline for Medical Devices
MHLW notification of revised Cybersecurity Guideline for Medical Device Manufacturers (2nd Edition). Updated to align with Essential Principles Article 12(3) implementation. Provides practical procedures for security requirements identification, architecture design, SBOM, PSIRT establishment, and vulnerability disclosure. Functions as specific guidance for JIS T 81001-5-1 application.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.8
Notice on Application of Essential Principles Article 12(3) for Medical Devices
Interpretation notice accompanying April 1, 2023 enforcement of Essential Principles Article 12(3) cybersecurity requirements. Mandates three elements for network-connected medical devices: lifecycle cybersecurity planning, risk reduction design, and minimum operational environment specifications. Recognizes JIS T 81001-5-1 conformance as equivalent to Article 12(3) compliance. Provides transition period until March 31, 2024.
Published: 2023-03-31
