Standards, Guidance & Notices
Showing 101–110 of 129
EU
MDCG
MDCG
MDCG 2019-16 rev.1
Guidance on cybersecurity for medical devices
Explains how manufacturers meet the cybersecurity-related general safety and performance requirements (GSPRs) in Annex I of the MDR (2017/745) and IVDR (2017/746) across the full device lifecycle, for medical devices and IVDs that include programmable electronic systems or software -- SaMD, embedded software, mobile apps, networked devices, and systems relying on hospital networks or cloud services. Its central principle is that "security is part of safety and risk management," and it distinguishes between (1) built-in security capabilities -- authentication, authorization, integrity protection, logging, backup/recovery, and secure update mechanisms -- and (2) security information that must be documented, covering the operating environment, configuration, accounts, network controls, updates and residual risk. Pre-market expectations include linking threat analysis to the safety risk management file, applying defence-in-depth controls (least privilege, strong identity management, protected communications, audit logging), and defining testable operating-environment requirements. Post-market expectations include active monitoring of vulnerability sources (databases, researcher reports, supplier notices, threat intelligence), risk assessment, coordinated disclosure, security updates and communication to users. The guidance frames cybersecurity as a shared responsibility between manufacturer and healthcare provider, while stressing that a manufacturer cannot transfer its own design and regulatory obligations to the hospital or user, and aligns with IMDRF's international guidance on medical device cybersecurity.
Published: 2020-07-01
IEC
IEC 62366-1:2015+AMD1:2020
Medical devices — Part 1: Application of usability engineering to medical devices
Specifies a process for a manufacturer to analyse, specify, develop and evaluate the usability of a medical device as it relates to safety.
Published: 2020-06-01
ISO
ISO/TR 24971:2020
Medical devices — Guidance on the application of ISO 14971
Provides guidance on the application of ISO 14971:2019 for risk management of medical devices, including practical examples and clarifications.
Published: 2020-06-01
NIST
IR
IR
IR 8259A
IoT Device Cybersecurity Capability Core Baseline
Device cybersecurity capabilities are cybersecurity features or functions that computing devices provide through their own technical means (i.e., device hardware and software). This publication defines an Internet of Things (IoT) device cybersecurity capability core baseline, which is a set of device capabilities generally needed to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the device cybersecurity capabilities for new IoT devices they will manufacture, integrate, or acquire. This publication can be used in conjunction with NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers.
Published: 2020-05-29
NIST
IR
IR
IR 8259
Foundational Cybersecurity Activities for IoT Device Manufacturers
Internet of Things (IoT) devices often lack device cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving how securable the IoT devices they make are by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using compromised devices.
Published: 2020-05-29
IMDRF
IMDRF/CYBER WG/N60 FINAL:2020
Principles and Practices for Medical Device Cybersecurity
The first IMDRF document to focus exclusively on medical device cybersecurity. It provides concrete recommendations to all responsible stakeholders, including manufacturers, healthcare providers, and regulators, on the general principles and best practices for the cybersecurity of medical devices, including IVD medical devices. It sets out four general principles (global harmonization, total product life cycle, shared responsibility, and information sharing) and organizes premarket considerations (e.g., building security in at the design stage through threat modeling, and preparing customer security documentation) and postmarket considerations (e.g., vulnerability monitoring and remediation, information sharing, and incident response). It is intended to be considered together with the IMDRF Essential Principles of Safety and Performance (N47) throughout the total product life cycle.
Published: 2020-04-20
EU
MDCG
MDCG
MDCG 2020-1
Guidance on clinical evaluation (MDR) / Performance evaluation (IVDR) of medical device software
Sets out how manufacturers determine the level of clinical evidence needed for medical device software (MDSW) under the MDR (2017/745) and IVDR (2017/746), built around three components: (1) valid clinical association / scientific validity -- whether the software's output is meaningfully linked, per accepted medical knowledge or peer-reviewed literature, to the targeted clinical or physiological state; (2) technical/analytical performance -- whether the software accurately, reliably and precisely generates the intended output from its input data; and (3) clinical performance -- whether the software yields a clinically relevant result in line with its intended purpose. The required evidence level scales with device classification: MDR Class III and implantable devices generally require clinical investigation data (subject to the Article 61(4)-(6)/(10) exceptions), while IVDR generally requires performance studies regardless of class, unless an alternative evidentiary route is justified. Clinical evaluation is treated as part of the quality management system and as an iterative, ongoing process across the software's lifecycle, supported by Post-Market Clinical Follow-up (PMCF) / Post-Market Performance Follow-up (PMPF) to keep the evidence current. Annex II gives six worked examples -- covering a sleep-quality analyser, an image segmentation tool, a semi-quantitative IVD calprotectin detector, embedded device-driving software, an insulin-pump companion app, and closed-loop ventilator CO2-control software -- illustrating when MDSW can be evaluated independently versus when it must be evaluated jointly with the hardware it drives or influences.
Published: 2020-03-01
ISO
ISO 14971:2019
Medical devices — Application of risk management to medical devices
Specifies terminology, principles and a process for risk management of medical devices, including software-only medical devices. Confirmed as current in the 2025 systematic review.
Published: 2019-12-01
AAMI
TIR
TIR
AAMI TIR102:2019
U.S. FDA 21 CFR mapping to the applicable regulatory requirement references in ISO 13485:2016 Quality Management Systems
Technical information report providing a mapping of US FDA 21 CFR 820 requirements to the regulatory requirement references in ISO 13485:2016. Developed by AAMI QM/WG 01 to help US industry identify applicable regulatory requirements through an ISO 13485 quality management system.
Published: 2019-08-30
NIST
FIPS
FIPS
FIPS 140-3
Security Requirements for Cryptographic Modules
The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems. This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347.
This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract. The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments. The security requirements cover areas related to the s
Published: 2019-03-22
