LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 14, 2026
MSC Portal Regulatory Watch All Entries (146)
Standards, Guidance & Notices
Showing 121–130 of 146
NIST
IR
IR 8259A
IoT Device Cybersecurity Capability Core Baseline
PUBLISHED Cybersecurity
Device cybersecurity capabilities are cybersecurity features or functions that computing devices provide through their own technical means (i.e., device hardware and software). This publication defines an Internet of Things (IoT) device cybersecurity capability core baseline, which is a set of device capabilities generally needed to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the device cybersecurity capabilities for new IoT devices they will manufacture, integrate, or acquire. This publication can be used in conjunction with NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers.
Published: 2020-05-29
NIST
IR
IR 8259
Foundational Cybersecurity Activities for IoT Device Manufacturers
PUBLISHED Cybersecurity
Internet of Things (IoT) devices often lack device cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving how securable the IoT devices they make are by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using compromised devices.
Published: 2020-05-29
IMDRF
IMDRF/CYBER WG/N60 FINAL:2020
Principles and Practices for Medical Device Cybersecurity
PUBLISHED Cybersecurity
This core document establishes international principles and practices for medical device cybersecurity, covering the complete device lifecycle. It specifies requirements for security by design, vulnerability management, and incident response frameworks. Manufacturers should integrate cybersecurity considerations throughout product development, maintenance, and end-of-life phases. The document serves as the common foundation referenced in Japan's Basic Principles for Conformity Assessment of Medical Devices (Article 12, Paragraph 3), FDA 2023 final cybersecurity guidance, and EU MDCG cybersecurity guidance. Japanese regulatory authorities directly reference this document in official notifications, making it essential for regulatory compliance in multiple jurisdictions.
Published: 2020-04-20
EU
MDCG
MDCG 2020-1
Guidance on clinical evaluation (MDR) / Performance evaluation (IVDR) of medical device software
PUBLISHED AI / Machine Learning
MDCG 2020-1 — Guidance on clinical evaluation (MDR) / Performance evaluation (IVDR) of medical device software — (March 2020)
Published: 2020-03-01
ISO
ISO 14971:2019
Medical devices — Application of risk management to medical devices
PUBLISHED Risk Management
Specifies terminology, principles and a process for risk management of medical devices, including software-only medical devices. Confirmed as current in the 2025 systematic review.
Published: 2019-12-01
AAMI
TIR
AAMI TIR102:2019
U.S. FDA 21 CFR mapping to the applicable regulatory requirement references in ISO 13485:2016 Quality Management Systems
PUBLISHED Quality Management
Technical information report providing a mapping of US FDA 21 CFR 820 requirements to the regulatory requirement references in ISO 13485:2016. Developed by AAMI QM/WG 01 to help US industry identify applicable regulatory requirements through an ISO 13485 quality management system.
Published: 2019-08-30
NIST
FIPS
FIPS 140-3
Security Requirements for Cryptographic Modules
PUBLISHED Cybersecurity
The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems.   This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347.  This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract.  The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments.  The security requirements cover areas related to the s
Published: 2019-03-22
NIST
SP
SP 800-37 Rev. 2
Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
PUBLISHED NEW Risk Management
This publication describes the Risk Management Framework (RMF) and provides guidelines for applying the RMF to information systems and organizations. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. The RMF includes activities to prepare organizations to execute the framework at appropriate risk management levels. The RMF also promotes near real-time risk management and ongoing information system and common control authorization through the implementation of continuous monitoring processes; provides senior leaders and executives with the necessary information to make efficient, cost-effective, risk management decisions about the systems supporting their missions and business functions; and incorporates security and privacy into the system development life cycle. E
Published: 2018-12-20
AAMI
TIR
AAMI SW91 ED1:2018
AAMI SW91 ED1:2018
PUBLISHED Software Life Cycle
This AAMI technical information report establishes a standardized classification system for defects identified in health software, including software embedded in medical devices and Software as a Medical Device (SaMD). The document defines defect categories based on type, severity, and origin within the software development lifecycle, enabling consistent defect tracking, root cause analysis, and process improvement. The classification scheme supports compliance with IEC 62304 software lifecycle requirements and FDA quality system expectations, and is referenced in the context of cybersecurity vulnerability management and postmarket surveillance activities. Currently under reaffirmation review by the AAMI SM-WG08 Software Defect Classification Working Group (as of April 2025).
Published: 2018-11-02
EU
MDCG
MDCG 2018-5
UDI assignment to medical device software
PUBLISHED AI / Machine Learning
MDCG 2018-5 — UDI assignment to medical device software — (October 2018)
Published: 2018-10-01
1 11 12 13 14 15