Standards, Guidance & Notices
Showing 31–40 of 129
NIST
IR
IR
IR 8259 Rev. 1 (2pd)
Foundational Cybersecurity Activities for IoT Product Manufacturers
Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT products are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of compromises.
Published: 2025-09-30
JFMDA
Notice
Notice
jfmda_20250929_33bce5c8
Alert Regarding the Expiration of Windows Secure Boot Certificates
For medical devices running Windows under an embedded license agreement, from Windows Embedded 8 Standard onward, that use the Secure Boot function, the expiration of the Secure Boot certificates in June 2026 may have serious impacts, such as the devices no longer being able to receive subsequent security updates or becoming unstable all at once. JFMDA asks readers to read the attached alert and take action. Issued by the Medical Device Cybersecurity WG of the JFMDA Liaison and Coordination Meeting.
Published: 2025-09-29
JFMDA
Notice
Notice
jfmda_20250827_AI
Final Study Report for Review of SaMD Utilizing AI
In October 2022, the JFMDA Regulatory System Committee set up a working group on review of AI-enabled SaMD under its review-related subcommittee. Its purpose was to discuss the requirements for the review of AI-enabled SaMD (including medical devices that contain software), such as what to describe in the application and which documents are needed, with PMDA review and standards staff, based on the outputs of AMED research on regulation of software medical devices using AI and other advanced technologies and on current review practice, and to improve the transparency of review by publishing the results. This report summarizes the activities of the working group.
Published: 2025-08-27
ISO
ISO/IEC 42006:2025
Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems
Specifies requirements for bodies providing audit and certification of AI management systems conforming to ISO/IEC 42001. Forms the foundation for AI conformity assessment schemes. Referenced in the context of EU AI Act harmonized standards development.
Published: 2025-07-07
EU
MDCG
MDCG
MDCG 2025-6
FAQ on Interplay between the Medical Devices Regulation (MDR) & In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)
FAQ-style guidance jointly issued by the Medical Device Coordination Group (MDCG) and the AI Board (MDCG 2025-6 / AIB 2025-1, published 19 June 2025) on the interplay between the Medical Devices Regulation (MDR), the In Vitro Diagnostic Medical Devices Regulation (IVDR), and the EU Artificial Intelligence Act (AIA). Addressed to manufacturers, competent authorities, and notified bodies, it explains how AI-specific requirements, such as data governance, algorithmic transparency, performance monitoring, bias mitigation, and human oversight, can be integrated into existing MDR/IVDR technical documentation and a single conformity assessment rather than requiring separate processes. It also touches on post-market surveillance obligations and the use of predetermined change control plans (PCCPs), relevant ahead of the AI Act obligations that are expected to start applying from August 2027.
Published: 2025-06-01
EU
MDCG
MDCG
MDCG 2025-4
Guidance on the safe making available of medical device software (MDSW) apps on online platforms
Guidance (MDCG 2025-4, published 16 June 2025) clarifying the responsibilities of online platforms that make medical device software (MDSW) apps available, and how the MDR, the IVDR, and the Digital Services Act (DSA) interact. Where a platform merely connects a manufacturer with users, it is treated as an online marketplace under the DSA rather than a distributor or importer under the MDR/IVDR, but it still carries DSA obligations such as a mechanism for reporting illegal content, ensuring manufacturers provide transparent safety and compliance information, and, for very large platforms, risk assessment and mitigation. Where a platform itself supplies the app directly to users, it is instead treated as a distributor or importer under the MDR/IVDR, the DSA no longer applies, and the platform must verify compliance and cooperate with authorities. The guidance also recommends that platforms create a dedicated category for MDSW apps, separate from general health and wellness apps, and lists the information manufacturers should provide, including the device name, manufacturer details (including the Single Registration Number, SRN), the MD or IVD symbol, intended purpose, warnings, a link to the electronic instructions for use (eIFU), and the UDI-DI.
Published: 2025-06-01
EU
MDCG
MDCG
MDCG 2019-11 rev.1
Qualification and classification of software - Regulation (EU) 2017/745 and Regulation (EU) 2017/746
Revision 1 of MDCG 2019-11 (published 17 June 2025), the core guidance on qualifying software as a medical device (MDSW) and classifying it under the MDR (Regulation (EU) 2017/745) and the IVDR (Regulation (EU) 2017/746). The revision clarifies the scope of the guidance, adds considerations on establishing a clear intended purpose and on modular MDSW (defining intended purpose at the level of individual functional modules), and clarifies the interpretation of Classification Rule 11 sub-rule (a) concerning devices intended to prevent the risk of illness, with additional reference material and examples. It also adds a new Class I example to Annex IV and updates Annex I to reflect the interplay with the European Health Data Space Regulation.
Published: 2025-06-01
ISO
ISO/IEC 42005:2025
Information technology — Artificial intelligence — AI system impact assessment
Specifies processes and requirements for assessing the impacts of AI systems on society, individuals and the environment. Intended for use in conjunction with ISO/IEC 42001. Serves as a framework for impact assessment in medical AI development.
Published: 2025-05-28
IMDRF
IMDRF/SaMD WG/N81 FINAL:2025
Characterization Considerations for Medical Device Software and Software-Specific Risk
Final document of the IMDRF SaMD Working Group that supplements the N12 SaMD risk categorization framework and broadens its scope to all medical device software, including software that is part of a hardware medical device. It identifies key elements of an intended use/intended purpose statement and organizes characterization features and attributes into four groupings: medical problem and/or objective, context of use, function and/or use (e.g., output type, input source, degree of autonomy, explainability), and change management. For risk characterization, it focuses on information-related (performance-related) hazards, considers both direct and indirect harms including reduction of effectiveness, and notes that it can be helpful to set the probability of software failure to 1 when estimating software-specific risk. Appendices provide guiding questions and worked examples. The document is not regulation or guidance, does not provide guidance on device classification, and does not replace N12 or risk management standards such as ISO 14971.
Published: 2025-01-29
IMDRF
IMDRF/AIML WG/N88 FINAL:2025
Good machine learning practice for medical device development: Guiding principles
Final document of the IMDRF AI/ML-enabled Working Group setting out 10 guiding principles for Good Machine Learning Practice (GMLP), intended to promote the development of safe, effective, and high-quality AI-enabled medical devices across the total product life cycle. The principles cover: understanding the intended use and leveraging multidisciplinary expertise; good software engineering, medical device design, and security practices; clinical evaluation using datasets representative of the intended patient population; independence of training and test datasets; fit-for-purpose reference standards; model choice and design tailored to the available data and intended use; assessment focused on human-AI interactions and the performance of the human-AI team rather than the device in isolation; testing under clinically relevant conditions; clear, essential information for users; and monitoring of deployed models and management of re-training risks. The document presents the principles as a call to action for standards organizations, regulators, and other bodies to further advance GMLP, and notes that generative AI may heighten their importance.
Published: 2025-01-29
