Standards, Guidance & Notices
Showing 11–20 of 146
NIST
SP
SP
SP 800-213 Rev. 1
IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements
Organizations increasingly use Internet of Things (IoT) products for the mission benefits they can offer, but care must be taken in the acquisition and implementation of this equipment. Understanding that an IoT product is a system element facilitates an understanding of how the IoT product must be considered in the risk management process. The acquisition and integration of an IoT product into an information system may alter the system’s risk assessment based on new risks introduced by the product. An updated risk assessment may require additional or new controls to be selected and implemented in the system. The guidelines in this publication focus on establishing product cybersecurity requirements to support security controls. This publication provides general considerations of how IoT products may impact an information system’s risk assessment and subsequent allocation of controls that may be necessary. Readers are encouraged to reference SP 800-30, Revision 1, Guide for
Published: 2026-06-24
JFMDA
Notice
Notice
jfmda_20260617_emc2
[MHLW Radio Wave Utilization Portal] Release of FY2025 Survey Report on Impact of Radio Waves on Medical Devices
The MHLW Radio Wave Utilization Portal has released the FY2025 survey report on the impact of radio waves on medical devices. This report presents findings from comprehensive investigations conducted by the EMC subcommittee regarding electromagnetic compatibility and radio wave interference with medical device operations.
Published: 2026-06-17
ISO
ISO/TS 24971-2:2026
Medical devices — Guidance on the application of ISO 14971 — Part 2: Machine learning in artificial intelligence
Provides guidance on risks specific to artificial intelligence and machine learning, and on how to apply the risk management process of ISO 14971 to machine learning-enabled medical devices (MLMD). Intended to be used in conjunction with ISO 14971 and does not alter its requirements.
Published: 2026-06-17
FDA
CDRH
CDRH
medical-devices-software-medical-device-samd-artificial-intelligence-enabled-medical-devices
Artificial Intelligence Enabled Medical Devices
FDA CDRH provides regulatory guidance for artificial intelligence-enabled medical devices, addressing the unique oversight considerations for AI/machine learning-based Software as a Medical Device (SaMD). The resource covers quality management systems, validation methodologies, performance monitoring, and cybersecurity requirements aligned with IEC 62304 standards. It serves as a reference document for manufacturers developing AI-integrated medical devices authorized for U.S. marketing, emphasizing transparency, safety evaluation, and ongoing post-market surveillance protocols.
Published: 2026-06-17
FDA
CDRH
CDRH
fda_20260305_digital_health_lists
FDA Updates Lists of Medical Devices that Incorporate Digital Health Technology
The FDA has updated its comprehensive searchable databases of medical devices incorporating digital health technologies authorized for U.S. marketing. These updated lists encompass artificial intelligence and machine learning-enabled devices, augmented and virtual reality medical devices, and sensor-based digital health technology solutions. This resource provides manufacturers, healthcare professionals, and regulatory stakeholders transparent access to cleared and approved AI/digital health-integrated medical devices, supporting informed decision-making and regulatory compliance efforts while facilitating continued innovation in the digital health medical device sector.
Published: 2026-06-17
NIST
SP
SP
SP 800-172A Rev. 3
Assessing Enhanced Security Requirements for Controlled Unclassified Information
The protection of controlled unclassified information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with assessment procedures for the enhanced security requirements in NIST SP 800-172. The assessment procedures are flexible and can be tailored to the needs of federal agencies and assessors. Security requirement assessments can be conducted as (1) self-assessments; (2) independent, third-party assessments; or (3) government-sponsored assessments. The assessments can be conducted with varying degrees of rigor based on federal agency-defined depth and coverage attributes. The findings and evidence produced during the assessments can be used to facilitate risk-based decisions by organizations related to the security requirements.
Published: 2026-05-13
NIST
SP
SP
SP 800-172 Rev. 3
Enhanced Security Requirements for Protecting Controlled Unclassified Information
The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with a set of recommended enhanced security requirements for providing additional protection to the confidentiality, integrity, and availability of CUI when it is resident in a nonfederal system and organization and associated with a critical program or high value asset (HVA). It is designed as a supplement to NIST Special Publication (SP) 800-171 to protect against advanced persistent threats (APTs). The security requirements apply to the components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components only when selected and required by federal agencies to manage risks to CUI. The enhanced security requirements are i
Published: 2026-05-13
NIST
IR
IR
IR 8259 Rev. 1
Foundational Cybersecurity Activities for IoT Product Manufacturers
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises.
Published: 2026-04-20
EU
MDCG
MDCG
Borderline Manual
Manual on borderline and classification under Regulations (EU) 2017/745 and 2017/746 v5 Background note on the use of the Manual on borderline and classification for medical devices under the Directives.
Manual on borderline and classification under Regulations (EU) — Manual on borderline and classification under Regulations (EU) 2017/745 and 2017/746 v5 Background note on the use of the Manual on borderline and classification for medical devices under the Directives. — (April 2026)
Published: 2026-04-01
EU
MDCG
MDCG
Borderline Background Note
Background note — Manual on borderline and classification under Regulations (EU) 2017/745 and 2017/746 v5 Background note on the use of the Manual on borderline and classification for medical devices under the Directives.
Background note — Background note — Manual on borderline and classification under Regulations (EU) 2017/745 and 2017/746 v5 Background note on the use of the Manual on borderline and classification for medical devices under the Directives. — (April 2026)
Published: 2026-04-01
