LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 14, 2026
MSC Portal Regulatory Watch All Entries (146)
Standards, Guidance & Notices
Showing 61–70 of 146
NIST
SP
SP 800-171 Rev. 3
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
PUBLISHED NEW Cybersecurity
The protection of Controlled Unclassified Information (CUI) is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations. The requirements apply to components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components. The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations. This publication can be used in conjunction with its companion publication, NIST Special Publication 800-171A, which provides a comprehensive set of procedures to assess the security requirements.
Published: 2024-05-14
IMDRF
IMDRF/GRRP WG/N47 FINAL:2024 (Edition 2)
Essential Principles of Safety and Performance of Medical Devices and IVD Medical Devices
PUBLISHED Risk Management
Defines the internationally agreed essential principles of safety and performance that medical devices and IVD medical devices are expected to meet. Covers baseline requirements across the product life cycle, including design, manufacture, verification and risk management, with the aim of protecting patient safety and public health.
Published: 2024-04-26
NIST
CSWP
CSWP 33
Product Development Cybersecurity Handbook: Concepts and Considerations for IoT Product Manufacturers
DRAFT Cybersecurity
As interest in Internet of Things (IoT) technologies has grown, so have concerns and attention to cybersecurity of the newly network-connected products and services offered in many sectors, including energy services, water/waste-water services, automobiles, consumer electronics, and government. This Product Development Cybersecurity Handbook will describe concepts important to developing and deploying secure IoT products for any sector or use case, including discussion of IoT Product architecture, deployment, roles and cybersecurity perspectives. This publication extends and elaborates on NIST’s prior work related to development of IoT products. In addition to discussing the concepts, this publication also demonstrates their application and discusses how satisfaction of cybersecurity in IoT products can be approached.
Published: 2024-04-03
MHLW
Notice
MHLW-PFSB-MDED-0328-No.1
Guidance on Vulnerability Management to Ensure Cybersecurity of Medical Devices
PUBLISHED SBOM / Vulnerability
Notice on post-market vulnerability management framework. Requires manufacturers/distributors to integrate vulnerability monitoring, evaluation, response, and disclosure processes (including SBOM utilization) into quality management systems. Mandates establishment of PSIRT structure, clear vulnerability notification policies to customers, and practical end-of-life support management procedures.
Published: 2024-03-28
NIST
CSWP
CSWP 29
The NIST Cybersecurity Framework (CSF) 2.0
PUBLISHED Cybersecurity
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.
Published: 2024-02-26
FDA
CDRH
21 CFR Part 820
Quality Management System Regulation (QMSR) — 21 CFR Part 820
PUBLISHED Quality Management
The FDA's Quality Management System Regulation establishes comprehensive good manufacturing practice (CGMP) requirements for medical device manufacturing. Through the final rule effective February 2, 2026, the QMSR incorporates by reference ISO 13485:2016, aligning FDA requirements with international quality management standards. The regulation covers design and development controls (equivalent to 21 CFR 820.30), manufacturing operations, documentation, and management oversight across the entire device lifecycle. Key requirements include design input and output specifications, design review and verification, design validation, design transfer, and identification and implementation of design changes. The QMSR serves as a foundational regulatory framework for simultaneous FDA and Japanese approval pathways, establishing baseline quality system compliance expectations for manufacturers seeking marketing authorization in multiple regions. Compliance with these requirements demonstrates commitment to systematic quality assurance throughout device development and commercialization.
Published: 2024-02-02
MHLW
Notice
Admin-Notice-2024-01-31
Q&A on Cybersecurity of Medical Devices (2024 Version)
PUBLISHED Cybersecurity
Expanded Q&A set on application and conformance assessment of Essential Principles Article 12(3). Provides guidance on system architecture diagram formats, post-transition application handling, third-party testing utilization, SBOM documentation scope, and legacy product compliance strategies based on practical implementation experience.
Published: 2024-01-31
JFMDA
Notice
jfmda_20240129_f5a055dd
English Translation of Cybersecurity and Usability Notification
PUBLISHED Cybersecurity
English version of JFMDA Law and Regulations Committee's notification on cybersecurity and usability requirements for medical devices, published January 29, 2024. Provides guidance on regulatory expectations for device security and user interface safety.
Published: 2024-01-29
MHLW
Notice
MHLW-PSEHB-PSD-0115-No.2
Fundamental Approach to Adverse Event Reporting Related to Medical Device Cybersecurity
PUBLISHED Cybersecurity
Notice clarifying handling of cybersecurity events in adverse event/serious adverse event reporting systems. Addresses reporting applicability for patient harm from cyber attacks or vulnerability exploitation, decision-making flowcharts, and manufacturer response procedures. Serves as foundational regulatory documentation for post-market cybersecurity management.
Published: 2024-01-15
MHLW
Notice
Admin-Notice-2023-12-22-IDATEN-KISAIJIREI
Examples of Application Forms and Supporting Documents for Change Control Plan Confirmation Applications for Software as a Medical Device
PUBLISHED NEW SaMD Classification
Practical worked examples of application forms and supporting documentation for IDATEN change control plan confirmation applications specific to SaMD. Illustrates how to describe proposed changes, set acceptance criteria, and prepare draft revised approval documents. Issued concurrently with the consolidated Q&A revision.
Published: 2023-12-22
1 5 6 7 8 9 15