LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 14, 2026
MSC Portal Regulatory Watch All Entries (146)
Standards, Guidance & Notices
Showing 31–40 of 146
JFMDA
Notice
jfmda_20260122_d15ec1e0
Review of Regulatory Considerations for AI-Based Software as a Medical Device - Research Results Report - English Version
PUBLISHED AI / Machine Learning
English translation of the August 2025 research report on regulatory review considerations for AI-based SaMD. This publication provides comprehensive guidance on assessment methodologies and regulatory pathways for software medical devices incorporating artificial intelligence technologies.
Published: 2026-01-22
JFMDA
Notice
jfmda_20260109_fuguai
Utilization of Medical Device Defect Terminology Glossary
PUBLISHED Post-Market Surveillance
JFMDA has revised the medical device defect terminology glossary. Updates include harmonization of individual terminology with IMDRF adverse event terminology standards to ensure consistency and clarity in defect reporting and classification across regulatory frameworks.
Published: 2026-01-09
AAMI
TIR
AAMI CR515:2025
AAMI CR515:2025 - Cybersecurity Considerations Specific to Machine Learning-enabled Medical Devices
PUBLISHED Cybersecurity
AAMI CR515:2025 establishes cybersecurity considerations specific to machine learning-enabled medical devices. Recognized by the FDA as a consensus standard (Recognition Number: 13-153) on December 22, 2025, the document serves as a normative reference in the Software/Informatics domain. The standard specifies security risk management requirements essential for the development and operational deployment of medical devices incorporating artificial intelligence and machine learning technologies. Manufacturers should implement the specified cybersecurity controls and risk management procedures to address vulnerabilities introduced by machine learning algorithms, including model drift, adversarial attacks, and data integrity threats. The document provides manufacturers with practical guidance for integrating cybersecurity considerations throughout the device lifecycle, from initial algorithm development through post-market surveillance and model updates.
Published: 2025-12-22
NIST
SP
SP 800-218 Rev. 1
Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities
DRAFT NEW Software Life Cycle
Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) — a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities.
Published: 2025-12-17
NIST
CSWP
CSWP 34
Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration
PUBLISHED Risk Management
In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions are a form of telehealth that provide an in-patient care experience in patients’ homes, offering the potential for improved outcomes. While these are desirable benefits, HaH involves privacy and cybersecurity risks by introducing hospital-grade medical or biometric devices and information systems outside the hospital’s direct control (i.e., the patient’s home). Patient homes increasingly feature Internet of Things (IoT) devices, such as voice assistants (e.g., smart speakers), as part of a broader “smart home” ecosystem. These devices may not have capabilities that support privacy and security practices and may be used as pivot points for attackers to gain access to a hospital’s information system. This paper introduces a notional high-level smart home integration reference architecture to better un
Published: 2025-12-17
IEC
IEC TS 81001-2-2:2025
Health software and health IT systems safety, effectiveness and security — Part 2-2: Coordination — Guidance for the implementation, disclosure and communication of security needs, risks and controls
PUBLISHED NEW Cybersecurity
Withdraws and replaces IEC TR 80001-2-2. Provides guidance for communication of security needs, risks and controls for health software connected to IT networks.
Published: 2025-10-01
JFMDA
Notice
jfmda_20250929_33bce5c8
Alert Regarding Validity Period of Windows Secure Boot Certificate
PUBLISHED Cybersecurity
Alert for medical devices running embedded Windows (Standard Edition 8 or later) with Secure Boot functionality enabled. Device manufacturers should verify secure boot certificate validity and plan for potential renewal to prevent operational disruptions in 2025.
Published: 2025-09-29
JFMDA
Notice
jfmda_20250827_AI
Review of Regulatory Considerations for AI-Based Software as a Medical Device - Research Results Report
PUBLISHED AI / Machine Learning
JFMDA Law and Regulations Committee report on regulatory considerations for AI-based SaMD from October 2022. This working group study addresses assessment frameworks, regulatory pathways, and compliance requirements specific to medical devices incorporating artificial intelligence technologies.
Published: 2025-08-27
NIST
SP
SP 800-63-4
Digital Identity Guidelines
PUBLISHED NEW Cybersecurity
These guidelines cover the identity proofing, authentication, and federation of users (e.g., employees, contractors, or private individuals) who interact with government information systems over networks. They define technical requirements in each of the areas of identity proofing, enrollment, authenticators, management processes, authentication protocols, federation, and related assertions. They also offer technical recommendations and other informative text as helpful suggestions. The guidelines are not intended to constrain the development or use of standards outside of this purpose. This publication supersedes NIST Special Publication (SP) 800-63-3.
Published: 2025-07-31
NIST
SP
SP 800-63A-4
Digital Identity Guidelines: Identity Proofing and Enrollment
PUBLISHED NEW Cybersecurity
This guideline focuses on identity proofing and enrollment for use in digital authentication. During the process of identity proofing, an applicant provides evidence to a credential service provider (CSP) reliably identifying themselves, thereby allowing the CSP to assert that identification at a useful identity assurance level. This document defines technical requirements for each of three identity assurance levels. The guidelines are not intended to constrain the development or use of standards outside of this purpose. This publication supersedes NIST Special Publication (SP) 800-63A.
Published: 2025-07-31
1 2 3 4 5 6 15