LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (129)
Standards, Guidance & Notices
Showing 21–30 of 129
MHLW
Notice
MHLW-PSEHB-PSD-0210-No.3
Notice on Partial Revision of 'Reporting of Medical Device Defects and Other Incidents' (Notice MHLW-PSEHB-PSD-0210-No.3, February 10, 2026)
NEW Post-Market Surveillance
Notice (MHLW-PSEHB-PSD-0210-No.3, 10 February 2026) partially revising the attachment to the 2020 notice on Reporting of Medical Device Defects and Other Incidents (No. 0131-1, 31 January 2020). Issued in connection with the 2025 amendment to the PMD Act (Act No. 37 of 2025) and the related 2025 ministerial ordinance (Ordinance No. 117 of 2025), the revision removes known deaths or serious cases involving foreign medical devices and foreign regenerative medicine products from the scope of the 30-day reporting requirement, while newly requiring 15-day reporting for defects in such foreign products that are not readily foreseeable, whose occurrence trend is unclear, or that suggest a risk of harm to public health and hygiene, along with other technical revisions. The notice takes effect on 1 May 2026.
Published: 2026-02-13
FDA
CDRH
FDA-2026-D-Cybersecurity-QMS
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FINAL Cybersecurity
Under Section 524B of the FD&C Act, added by the 2023 Consolidated Appropriations Act, this guidance requires SBOM submission, a vulnerability disclosure process, and coordinated vulnerability disclosure (CVD) planning as part of premarket review. The title change from "Quality System" to "Quality Management System" reflects FDA's move from the legacy QSR to the ISO 13485-based QMSR. IEC 81001-5-1 and AAMI TIR57 appear as two of several optional frameworks manufacturers may draw on for secure product development — alongside JSP2 and ISA/IEC 62443-4-1 — rather than as standards the guidance formally aligns with.
Published: 2026-02-03
FDA
CDRH
FDA-2022-D-0795
Computer Software Assurance for Production and Quality Management System Software
FINAL Quality Management
FDA final guidance (Feb 2026) on risk-based assurance for software used in medical device production and quality management systems. Supersedes the September 24, 2025 version, with the title updated from "Quality System Software" to "Quality Management System Software" to align with the QMSR (21 CFR Part 820 / ISO 13485:2016 harmonization effective February 2, 2026). Replaces Section 6 of the 2002 GPSV. Does NOT apply to SaMD/SiMD.
Published: 2026-02-03
FDA
CDRH
FDA-2026-D-CDS
Clinical Decision Support Software
FINAL AI / Machine Learning
FDA final guidance (issued January 6, 2026, reissued January 29, 2026, superseding the 2022 version) setting out the approach to clinical decision support (CDS) software functions excluded from the device definition under the criteria of section 520(o)(1)(E) of the FD&C Act. It clarifies the distinction between device CDS and non-device CDS. Where only one recommendation is clinically appropriate, FDA intends to exercise enforcement discretion for CDS that outputs that single recommendation, provided the other non-device CDS criteria are met.
Published: 2026-01-29
JFMDA
Notice
jfmda_20260122_d15ec1e0
Final Study Report for Review of SaMD Utilizing AI (English Version)
PUBLISHED AI / Machine Learning
English translation of the report "Study on the Review of AI-Enabled Software as a Medical Device: Report of Research Results," originally posted in August 2025. Published as "Final Study Report for Review of SaMD utilizing AI_English" by the working group on review of AI-enabled SaMD under the Regulatory System Committee of the Japan Federation of Medical Devices Associations (JFMDA).
Published: 2026-01-22
JFMDA
Notice
jfmda_20260109_fuguai
Utilization of the Medical Device Malfunction Terminology
PUBLISHED Post-Market Surveillance
JFMDA has revised its Medical Device Malfunction Terminology. Following the revision of the IMDRF adverse event terminology, the mapping of similar terms between the individual terminologies and the IMDRF terminology was checked, and the individual terminologies were also revised in response to requests and questions. The common terminology was likewise revised in line with the IMDRF revision. The MHLW Pharmaceutical Safety Division and PMDA issued administrative notices on this matter dated January 9, 2026. The Version 8 reporting data required for malfunction reports under the Director-General's notification, and the Excel file of the terminology (8th edition) previously provided by JFMDA, are now available from the PMDA website. A briefing session on the new terminology will be held.
Published: 2026-01-09
AAMI
TIR
AAMI CR515:2025
AAMI CR515:2025 - Cybersecurity Considerations Specific to Machine Learning-enabled Medical Devices
PUBLISHED Cybersecurity
AAMI CR515:2025 establishes cybersecurity considerations specific to machine learning-enabled medical devices. Recognized by the FDA as a consensus standard (Recognition Number: 13-153) on December 22, 2025, the document serves as a normative reference in the Software/Informatics domain. The standard specifies security risk management requirements essential for the development and operational deployment of medical devices incorporating artificial intelligence and machine learning technologies. Manufacturers should implement the specified cybersecurity controls and risk management procedures to address vulnerabilities introduced by machine learning algorithms, including model drift, adversarial attacks, and data integrity threats. The document provides manufacturers with practical guidance for integrating cybersecurity considerations throughout the device lifecycle, from initial algorithm development through post-market surveillance and model updates.
Published: 2025-12-22
NIST
SP
SP 800-218 Rev. 1
Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities
DRAFT NEW Software Life Cycle
Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) — a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities.
Published: 2025-12-17
NIST
CSWP
CSWP 34
Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration
PUBLISHED Risk Management
In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions are a form of telehealth that provide an in-patient care experience in patients’ homes, offering the potential for improved outcomes. While these are desirable benefits, HaH involves privacy and cybersecurity risks by introducing hospital-grade medical or biometric devices and information systems outside the hospital’s direct control (i.e., the patient’s home). Patient homes increasingly feature Internet of Things (IoT) devices, such as voice assistants (e.g., smart speakers), as part of a broader “smart home” ecosystem. These devices may not have capabilities that support privacy and security practices and may be used as pivot points for attackers to gain access to a hospital’s information system. This paper introduces a notional high-level smart home integration reference architecture to better un
Published: 2025-12-17
IEC
IEC TS 81001-2-2:2025
Health software and health IT systems safety, effectiveness and security — Part 2-2: Coordination — Guidance for the implementation, disclosure and communication of security needs, risks and controls
PUBLISHED Cybersecurity
Withdraws and replaces IEC TR 80001-2-2. Provides guidance for communication of security needs, risks and controls for health software connected to IT networks.
Published: 2025-10-01
‹ 1 2 3 4 5 … 13 ›