LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (129)
Standards, Guidance & Notices
Showing 51–60 of 129
NIST
CSWP
CSWP 33
Product Development Cybersecurity Handbook: Concepts and Considerations for IoT Product Manufacturers
DRAFT Cybersecurity
As interest in Internet of Things (IoT) technologies has grown, so have concerns and attention to cybersecurity of the newly network-connected products and services offered in many sectors, including energy services, water/waste-water services, automobiles, consumer electronics, and government. This Product Development Cybersecurity Handbook will describe concepts important to developing and deploying secure IoT products for any sector or use case, including discussion of IoT Product architecture, deployment, roles and cybersecurity perspectives. This publication extends and elaborates on NIST’s prior work related to development of IoT products. In addition to discussing the concepts, this publication also demonstrates their application and discusses how satisfaction of cybersecurity in IoT products can be approached.
Published: 2024-04-03
MHLW
Notice
MHLW-PFSB-MDED-0328-No.1
Guidance on Vulnerability Management to Ensure Cybersecurity of Medical Devices
PUBLISHED SBOM / Vulnerability
Notice on post-market vulnerability management framework. Requires manufacturers/distributors to integrate vulnerability monitoring, evaluation, response, and disclosure processes (including SBOM utilization) into quality management systems. Mandates establishment of PSIRT structure, clear vulnerability notification policies to customers, and practical end-of-life support management procedures.
Published: 2024-03-28
NIST
CSWP
CSWP 29
The NIST Cybersecurity Framework (CSF) 2.0
PUBLISHED Cybersecurity
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.
Published: 2024-02-26
FDA
CDRH
21 CFR Part 820
Quality Management System Regulation (QMSR) — 21 CFR Part 820
PUBLISHED Quality Management
The FDA quality system regulation for medical device manufacturing. Under the February 2024 final rule, it incorporates ISO 13485:2016 by reference and was renamed the Quality Management System Regulation (QMSR), effective February 2, 2026. It specifies CGMP requirements across manufacturing, including design and development controls (equivalent to former 820.30). The foundational regulation for quality system compliance in simultaneous Japan-US submissions.
Published: 2024-02-02
MHLW
Notice
Admin-Notice-2024-01-31
Q&A on Cybersecurity of Medical Devices (2024 Version)
PUBLISHED Cybersecurity
Expanded Q&A set on application and conformance assessment of Essential Principles Article 12(3). Provides guidance on system architecture diagram formats, post-transition application handling, third-party testing utilization, SBOM documentation scope, and legacy product compliance strategies based on practical implementation experience.
Published: 2024-01-31
JFMDA
Notice
jfmda_20240129_f5a055dd
English Translation of Cybersecurity and Usability Notification
PUBLISHED Cybersecurity
Notice (29 January 2024) from the JFMDA Legislative Affairs Committee, Review-Related Subcommittee, announcing unofficial English translations, prepared by the PMDA Office of Medical Devices, of three MHLW notifications concerning medical device cybersecurity and usability: (1) Application of Article 12-3 of the Essential Principles for Medical Devices (PSEHB MDED Notification No. 0331-8, 31 March 2023); (2) Confirmation of compliance with Article 12-3 of the Essential Principles for Medical Devices (PSEHB MDED Notification No. 0523-1, 23 May 2023); and (3) Handling of the revised Japanese Industrial Standard (JIS) on usability engineering requirements for medical devices (PSEHB MDED and CND Notification No. 0930-1, 30 September 2022). The page notes that the translations are provided for reference only and that only the original Japanese texts have legal effect.
Published: 2024-01-29
MHLW
Notice
MHLW-PSEHB-PSD-0115-No.2
Fundamental Approach to Adverse Event Reporting Related to Medical Device Cybersecurity
PUBLISHED Cybersecurity
Notice clarifying handling of cybersecurity events in adverse event/serious adverse event reporting systems. Addresses reporting applicability for patient harm from cyber attacks or vulnerability exploitation, decision-making flowcharts, and manufacturer response procedures. Serves as foundational regulatory documentation for post-market cybersecurity management.
Published: 2024-01-15
MHLW
Notice
Admin-Notice-2023-12-22-IDATEN-KISAIJIREI
Examples of Application Forms and Supporting Documents for Change Control Plan Confirmation Applications for Software as a Medical Device
PUBLISHED SaMD Classification & Approval
Practical worked examples of application forms and supporting documentation for IDATEN change control plan confirmation applications specific to SaMD. Illustrates how to describe proposed changes, set acceptance criteria, and prepare draft revised approval documents. Issued concurrently with the consolidated Q&A revision.
Published: 2023-12-22
MHLW
Notice
Admin-Notice-2023-12-22-IDATEN-QA
Q&A on Change Control Plan Confirmation Applications for Medical Devices, AI-Enabled Medical Devices, and Software as a Medical Device (Consolidated Revision)
PUBLISHED SaMD Classification & Approval
Consolidated revision of Q&A guidance on the IDATEN change control plan confirmation system, integrating three previously separate documents. Adds provisions specific to AI/ML-enabled medical devices and SaMD, requiring submission of procedures for developing and implementing the change control plan and materials for appropriate AI technology management. Reflects startup company needs and accumulated regulatory experience since the system's 2020 launch.
Published: 2023-12-22
EU
MDCG
MDCG 2023-4
Medical Device Software (MDSW) – Hardware combinations Guidance on MDSW intended to work in combination with hardware or hardware components
PUBLISHED SaMD Classification & Approval
MDCG 2023-4 addresses MDSW that cannot achieve its intended medical purpose without hardware or a hardware component, setting out three regulatory scenarios (desktop PCs and cloud platforms are out of scope): (1) the hardware qualifies as an accessory to the MDSW under MDR Annex VIII classification rules; (2) the hardware is placed on the market as a standalone medical device -- as part of a system (Art. 22), a combination (Art. 2(1)), or an integral component -- in which case the manufacturer may rely on the hardware's MDR conformity for general safety and performance requirements, though clinical evaluation must still cover the combined intended purpose; (3) the hardware is part of a general consumer or wearable product with no medical device/accessory status, in which case the MDSW manufacturer bears sole responsibility for the safety, performance and reproducibility of the combination across all supported configurations, with correspondingly broader post-market surveillance. Illustrative examples include dermal sensor patches and smartwatches (temperature, SpO2, heart rate) paired with a companion app.
Published: 2023-10-01
‹ 1 … 4 5 6 7 8 … 13 ›