Standards, Guidance & Notices
Showing 71–80 of 146
MHLW
Notice
Notice
Admin-Notice-2023-12-22-IDATEN-QA
Q&A on Change Control Plan Confirmation Applications for Medical Devices, AI-Enabled Medical Devices, and Software as a Medical Device (Consolidated Revision)
Consolidated revision of Q&A guidance on the IDATEN change control plan confirmation system, integrating three previously separate documents. Adds provisions specific to AI/ML-enabled medical devices and SaMD, requiring submission of procedures for developing and implementing the change control plan and materials for appropriate AI technology management. Reflects startup company needs and accumulated regulatory experience since the system's 2020 launch.
Published: 2023-12-22
EU
MDCG
MDCG
MDCG 2023-5
Guidance on qualification and classification of Annex XVI products - A guide for manufacturers and notified bodies
MDCG 2023-5 — Guidance on qualification and classification of Annex XVI products - A guide for manufacturers and notified bodies — (December 2023)
Published: 2023-12-01
JFMDA
Notice
Notice
jfmda_20231116_emc
Release of MHLW 'Representative Examples of Radio Waves from Mobile Phones and Similar Devices'
November 2023 notice from JFMDA's Technical Committee EMC Subcommittee regarding MHLW publication of representative radio wave examples from mobile communication devices, supporting medical device electromagnetic compatibility assessments.
Published: 2023-11-16
EU
MDCG
MDCG
MDCG 2023-4
Medical Device Software (MDSW) – Hardware combinations Guidance on MDSW intended to work in combination with hardware or hardware components
MDCG 2023-4 — Medical Device Software (MDSW) – Hardware combinations Guidance on MDSW intended to work in combination with hardware or hardware components — (October 2023)
Published: 2023-10-01
NIST
SP
SP
SP 800-82 Rev. 3
Guide to Operational Technology (OT) Security
This document provides guidance on how to secure operational technology (OT) while addressing their unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. The document provides an overview of OT and typical system topologies, identifies common threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks.
Published: 2023-09-28
FDA
CDRH
CDRH
FDA-OTS-Software-2023
Off-The-Shelf (OTS) Software Use in Medical Devices
This FDA guidance addresses off-the-shelf (OTS) software including operating systems, database management systems, programming language compilers, libraries, and middleware incorporated into medical devices. The document provides practical recommendations for documenting OTS software in premarket submissions, recognizing the regulatory challenges associated with software of unknown or partially known provenance (SOUP). Manufacturers should evaluate and document vendor information, known defects and vulnerabilities, product lifecycle and support duration, configuration management practices, and compatibility with device safety and effectiveness requirements. The guidance establishes documentation expectations proportionate to OTS software risk contribution to overall device safety. Manufacturers must demonstrate that OTS software selection and management processes follow systematic risk-based approaches. This document serves as the practical foundation for implementing IEC 62304 Section 7.1 (SOUP management) requirements, bridging international standards and FDA regulatory expectations. Manufacturers should maintain current understanding of OTS software vulnerabilities and security patches, coordinating with vendors to receive timely security updates and assessing impact on marketed devices through post-market surveillance protocols.
Published: 2023-09-28
FDA
CDRH
CDRH
FDA-Cybersecurity-Premarket-2023
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions
⚠ NEWER VERSION
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (2026-02-03) →
This FDA final guidance (September 2023) establishes current cybersecurity requirements for medical device manufacturers, implementing legal mandates from the Consolidated Appropriations Act 2023 (Section 524B). The guidance specifies mandatory inclusion of software bill of materials (SBOM), vulnerability disclosure policies, and cybersecurity management plans in premarket submissions for devices with network connectivity or remote functionality. Manufacturers must establish processes for identifying, evaluating, and disclosing known and potential cybersecurity vulnerabilities to the FDA and relevant stakeholders. The cybersecurity management plan should address threat modeling, risk assessment, security design controls, and post-market monitoring strategies. The guidance demonstrates alignment with international standards including IEC 81001-5-1 (application of risk management to network security) and AAMI TIR57 (medical device security guidance), facilitating harmonized global regulatory compliance. Manufacturers should integrate cybersecurity considerations throughout the device lifecycle from design through post-market surveillance. The guidance represents current regulatory expectations and serves as the primary reference for FDA premarket submissions incorporating cybersecurity requirements. Compliance demonstrates manufacturer commitment to protecting patient safety and data integrity.
Published: 2023-09-27
NIST
SP
SP
SP 800-188
De-Identifying Government Datasets: Techniques and Governance
De-identification is a general term for any process of removing the association between a set of identifying data and the data subject. This document describes the use of deidentification with the goal of preventing or limiting disclosure risks to individuals and establishments while still allowing for the production of meaningful statistical analysis. Government agencies can use de-identification to reduce the privacy risk associated with collecting, processing, archiving, distributing, or publishing government data. Previously, NIST IR 8053, ""De-Identification of Personal Information,"" provided a detailed survey of deidentification and re-identification techniques. This document provides specific guidance to government agencies that wish to use de-identification. Before using de-identification, agencies should evaluate their goals for using de-identification and the potential risks that releasing de-identified data might create. Agencies should decide upon a data-sharing model, suc
Published: 2023-09-14
MHLW
Notice
Notice
Admin-Notice-2023-07-20
Q&A on Application of Essential Principles Article 12(3) for Medical Devices
Q&A addressing application and conformance assessment of Essential Principles Article 12(3). Covers transition period marketing approval application handling, submission documentation methods, third-party agency utilization for JIS T 81001-5-1 conformance, and reliability document review scope. References related MHLW regulatory notices issued in March and May 2023.
Published: 2023-07-20
FDA
CDRH
CDRH
FDA-Device-Software-Functions-2023
Content of Premarket Submissions for Device Software Functions
This FDA final guidance (2023) specifies required documentation content for software in premarket submissions including 510(k), PMA, and De Novo pathways. The guidance provides structured requirements based on software risk level (minor, moderate, major) classification, recognizing that documentation scope should be proportionate to patient risk. For each software risk category, the document delineates specific submission requirements for design specifications, system architecture, verification and validation (V&V) documentation, cybersecurity considerations, and unmet need summaries. Manufacturers must provide detailed design specifications describing intended functionality and performance parameters, system architecture documentation explaining software structure and interfaces, comprehensive V&V documentation demonstrating safety and effectiveness testing, and cybersecurity management plans addressing relevant threats. The guidance replaces the previous "Content of Premarket Submissions for Software" document, incorporating contemporary regulatory expectations including artificial intelligence considerations, interoperability requirements, and cybersecurity standards. Compliance with these content requirements streamlines FDA review and supports timely device approval decisions.
Published: 2023-06-14
