LIVE — Last crawled: 2026-09-29 17:35 JST
Vol.1 — September 30, 2026
MSC Portal ›Regulatory Watch› All Entries (129)
Standards, Guidance & Notices
Showing 61–70 of 129
NIST
SP
SP 800-82 Rev. 3
Guide to Operational Technology (OT) Security
PUBLISHED NEW SBOM / Vulnerability
This document provides guidance on how to secure operational technology (OT) while addressing their unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. The document provides an overview of OT and typical system topologies, identifies common threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks.
Published: 2023-09-28
FDA
CDRH
FDA-OTS-Software-2023
Off-The-Shelf (OTS) Software Use in Medical Devices
FINAL Software Life Cycle
FDA guidance setting out the recommended documentation in premarket submissions for off-the-shelf (OTS) software incorporated into medical devices, such as operating systems, database management systems, and libraries. A practical basis for managing SOUP (Software of Unknown Provenance). It presents requirements for evaluating and documenting vendor information, known anomalies, and the support life cycle. Referenced in relation to the SOUP management requirements of IEC 62304.
Published: 2023-09-28
MHLW
Notice
Admin-Notice-2023-07-20
Q&A on Application of Essential Principles Article 12(3) for Medical Devices
PUBLISHED Cybersecurity
Q&A addressing application and conformance assessment of Essential Principles Article 12(3). Covers transition period marketing approval application handling, submission documentation methods, third-party agency utilization for JIS T 81001-5-1 conformance, and reliability document review scope. References related MHLW regulatory notices issued in March and May 2023.
Published: 2023-07-20
FDA
CDRH
FDA-Device-Software-Functions-2023
Content of Premarket Submissions for Device Software Functions
FINAL Software Life Cycle
FDA final guidance (2023) on the content of software documentation required in premarket submissions (510(k), PMA, De Novo) for SaMD and SiMD. It organizes documentation requirements by documentation level (Basic or Enhanced) and specifies what to include for software design specifications, architecture, verification and validation, and unresolved anomalies. It replaces the 2005 Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices.
Published: 2023-06-14
MHLW
Notice
Admin-Notice-2023-05-29
Publication of Guidance on Appropriate and Expedited Approval and Development of Software as Medical Devices (SaMD)
PUBLISHED SaMD Classification & Approval
Practical guidance on expedited regulatory approval for SaMD including two-stage approval processes. Clarifies early marketing approval application handling across different development stages while maintaining consistent pre- and post-market safety/effectiveness assurance. Developed through public-private-academic collaboration as part of DASH for SaMD strategy, applicable to AI/ML-enabled SaMD.
Published: 2023-05-29
MHLW
Notice
MHLW-PSEHB-MDED-0523-No.1
Conformance Assessment Procedures for Essential Principles Article 12(3) of Medical Devices
PUBLISHED Cybersecurity
Notice specifying concrete compliance assessment considerations for Essential Principles Article 12(3). Details additional verification items against JIS T 81001-5-1 provisions (general requirements, maintenance processes, configuration management). Requires demonstration of intended use environment through system/network architecture diagrams and integration of vulnerability notification activities into quality management systems.
Published: 2023-05-23
IMDRF
IMDRF/CYBER WG/N73 FINAL:2023
Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity
PUBLISHED SBOM / Vulnerability
Final document of the IMDRF Medical Device Cybersecurity Working Group on the Software Bill of Materials (SBOM), complementing the medical device cybersecurity principles set out in IMDRF N60. It provides recommendations for medical device manufacturers on creating, maintaining, and distributing SBOMs, and for healthcare providers on receiving and managing them. It also describes how both manufacturers and healthcare providers can use SBOMs in risk management, vulnerability management, and incident response across the total product life cycle.
Published: 2023-04-13
IMDRF
IMDRF/CYBER WG/N70 FINAL:2023
Principles and Practices for the Cybersecurity of Legacy Medical Devices
PUBLISHED Cybersecurity
Final document of the IMDRF Medical Device Cybersecurity Working Group on the cybersecurity of legacy medical devices, complementing IMDRF N60. It divides the total product life cycle for cybersecurity into four stages (Development, Support, Limited Support, and End of Support (EOS)) and sets out the responsibilities and expectations of medical device manufacturers and healthcare providers at each stage in three areas: communication, risk management, and transfer of responsibility. Responsibility shifts from the manufacturer to the healthcare provider as the life cycle progresses, and cybersecurity responsibility for devices used beyond the EOS communicated by the manufacturer rests entirely with the healthcare provider. The document also notes that the end of life or end of support of a software or firmware component can prematurely move the device itself into a later stage, which manufacturers should address in advance.
Published: 2023-04-11
MHLW
Notice
MHLW-PSEHB-MDED-0331-No.1
Partial Amendment of Guideline on Software as a Medical Device Classification
PUBLISHED SaMD Classification & Approval
Revision of 2021 SaMD classification guideline (2023 version). Clarifies and refines classification criteria based on accumulated consultation cases. Adds judgment criteria for AI/ML-enabled software, cloud-based programs, and wellness applications. Maintains alignment with IMDRF N10 and N12. Updates judgment flow based on intended use and risk.
Published: 2023-03-31
MHLW
Notice
医政参発0331-No.1
Guideline for Ensuring Cybersecurity of Medical Devices in Healthcare Facilities
PUBLISHED Cybersecurity
MHLW notification of Cybersecurity Guideline for healthcare facility administrators and staff. Presents practical procedures for information collection from manufacturers, risk assessment, pre-implementation verification, vulnerability response during operation, and EOL management. Positioned as the healthcare facility counterpart to the related manufacturer-directed guideline, structured to promote coordination between both parties.
Published: 2023-03-31
‹ 1 … 5 6 7 8 9 … 13 ›