Standards, Guidance & Notices
Showing 71–80 of 129
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.11
Revision of Cybersecurity Implementation Guideline for Medical Devices
MHLW notification of revised Cybersecurity Guideline for Medical Device Manufacturers (2nd Edition). Updated to align with Essential Principles Article 12(3) implementation. Provides practical procedures for security requirements identification, architecture design, SBOM, PSIRT establishment, and vulnerability disclosure. Functions as specific guidance for JIS T 81001-5-1 application.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.8
Notice on Application of Essential Principles Article 12(3) for Medical Devices
Interpretation notice accompanying April 1, 2023 enforcement of Essential Principles Article 12(3) cybersecurity requirements. Mandates three elements for network-connected medical devices: lifecycle cybersecurity planning, risk reduction design, and minimum operational environment specifications. Recognizes JIS T 81001-5-1 conformance as equivalent to Article 12(3) compliance. Provides transition period until March 31, 2024.
Published: 2023-03-31
AAMI
TIR
TIR
AAMI TIR45:2023
Guidance on the use of AGILE practices in the development of medical device software
Technical information report providing recommendations for complying with IEC 62304, FDA 21 CFR 820, and ISO 13485 when using agile practices to develop medical device software. Covers integration of cybersecurity, risk management, design validation, and human factors within an agile framework. Second edition revising TIR45:2012, approved March 2023.
Published: 2023-03-15
JIS
Std
Std
JIS T 81001-5-1:2023
JIS T 81001-5-1:2023 Health software and health IT system safety, efficacy and security - Part 5-1: Security - Activities in the product lifecycle (equivalent to IEC 81001-5-1:2021)
This JIS standard specifies cybersecurity activities that medical device manufacturers must implement in addition to the software lifecycle processes defined in JIS T 2304, corresponding to IEC 81001-5-1:2021. The document establishes requirements for managing security risks throughout the product lifecycle, addressing threats related to unauthorized access, data integrity, and system availability. Enacted on February 25, 2023, and effective from April 1, 2024, this standard was developed by JEITA (Japan Electronics and Information Technology Industries Association) as a draft originator. The standard is positioned as a conformance specification for Article 12, Paragraph 3 of Japan's Medical Device Basic Requirements Standards (Yakuhin Kikai Kihon Youken Kijun). Manufacturers should integrate the cybersecurity activities outlined herein with their existing software development processes to ensure comprehensive protection against evolving security threats throughout the device lifecycle.
Published: 2023-02-25
NIST
FIPS
FIPS
FIPS 186-5
Digital Signature Standard (DSS)
This standard specifies a suite of algorithms that can be used to generate a digital signature. Digital signatures are used to detect unauthorized modifications to data and to authenticate the identity of the signatory. In addition, the recipient of signed data can use a digital signature as evidence in demonstrating to a third party that the signature was, in fact, generated by the claimed signatory. This is known as non-repudiation since the signatory cannot easily repudiate the signature at a later time.
Published: 2023-02-03
AAMI
TIR
TIR
AAMI TIR97:2019/(R)2023
Principles for medical device security — Postmarket risk management for device manufacturers
Technical information report providing guidance on postmarket security risk management for medical devices within the ISO 14971 safety risk management process. Designed for use with AAMI TIR57:2016. Covers PSIRT establishment, vulnerability disclosure policy, and coordinated vulnerability disclosure (CVD) frameworks. Closely aligned with FDA postmarket cybersecurity guidance. Published 2019, reaffirmed 2023.
Published: 2023-01-31
AAMI
TIR
TIR
AAMI TIR57:2016/(R)2023
Principles for medical device security — Risk management
Technical information report providing guidance on information security risk management for medical devices within the ISO 14971 safety risk management process. Incorporates expanded risk management concepts from IEC 62443, presenting practical methods for threat modeling and security risk assessment. Directly referenced by FDA's 2023 final cybersecurity guidance. Complementary to IEC 81001-5-1. Originally published 2016, reaffirmed 2023.
Published: 2023-01-13
JFMDA
Notice
Notice
jfmda_20221020_b84d0618
Handling of Software as a Medical Device (SaMD) Class I Products_October 20, 2022
Overview of handling procedures for SaMD Class I products. This document summarizes materials presented during the 2022 SaMD regulatory compliance seminar as an activity report by the SaMD Regulation Response Sub-Working Group.
Published: 2022-10-20
JFMDA
Notice
Notice
jfmda_20221020_fcd85f82
Explanatory Document for Software Medical Device Applicability Guideline - JFMDA Edition Version 1.0 October 20, 2022
JFMDA explanatory document providing detailed guidance on software medical device applicability determination and classification. Clarifies regulatory interpretation for software qualification and classification to support industry compliance and regulatory submissions.
Published: 2022-10-20
CEN/
CENELEC
CENELEC
EN ISO 14971:2019/A11:2021
Medical devices - Application of risk management to medical devices (ISO 14971:2019)
Regulation: MDR (EU) 2017/745 | Legislation: 2017/745 - Medical Devices | ESO: CEN | Amendments/Corrigenda: EN ISO 14971:2019/A11:2021 | Publication Decision: 2022/757 | Publication OJ: OJ L 138 | Start of legal effect: 17.05.2022
Published: 2022-05-17
