The Crosswalk

    The Crosswalk

    The global medical device cybersecurity crosswalk.

    The reference RA/QA teams reach for when planning international submissions. Twenty-nine regulators, one device, side by side, without losing a quarter to regulatory whiplash.

    Sponsored by Blue Goat Cyber
    Last updated ·

    Jurisdictions

    35

    Cross-cutting frameworks

    7

    Harmonised baseline

    IMDRF N60

    EU CRA enforcement

    2027

    Coverage at a glance

    The map.

    Hover any covered jurisdiction for a one-line read on its cybersecurity maturity. Click to open the full profile.

    Leading — statutory, SBOM mandated
    Advanced — mandatory, robust framework
    Developing — guidance, tightening
    Emerging — early-stage requirements
    Watchlist — regulator known, no cyber crosswalk yet
    Sanctions — commercial export restricted
    Out of scope. See methodology →

    How to use this atlas

    Four ways in.

    All jurisdictions

    Twenty-nine regulators. One device. Twenty-nine different stories.

    Status key
    MandatoryStatutory or binding regulation. Non-compliance blocks market access.
    GuidanceNon-statutory guidance. Typically enforced via review and registration.
    EmergingFramework adopted but not yet fully enforced or in active implementation.
    Flag of United StatesMandatory

    FDA / CDRH

    United States

    Mar 2023

    Flag of European UnionMandatory

    EC / MDCG

    European Union

    May 2021

    Flag of United KingdomGuidance

    MHRA

    United Kingdom

    Reform program 2024–26

    Flag of JapanMandatory

    PMDA / MHLW

    Japan

    Apr 2024 (cybersecurity notification)

    Flag of ChinaMandatory

    NMPA

    China

    2022

    Flag of CanadaMandatory

    Health Canada

    Canada

    Jun 2019 (rev. 2024)

    Flag of AustraliaGuidance

    TGA

    Australia

    Jul 2019 (rev. 2022)

    Flag of South KoreaMandatory

    MFDS

    South Korea

    2019 (rev. 2023)

    Flag of SingaporeGuidance

    HSA

    Singapore

    Apr 2022 (rev.)

    Flag of BrazilMandatory

    ANVISA

    Brazil

    Mar 2023 (RDC 751)

    Flag of Saudi ArabiaGuidance

    SFDA

    Saudi Arabia

    2022

    Flag of SwitzerlandMandatory

    Swissmedic

    Switzerland

    May 2021 (MedDO)

    Flag of IndiaGuidance

    CDSCO

    India

    Oct 2023 (full notified-device coverage)

    Flag of IsraelMandatory

    AMAR / MoH

    Israel

    2019 (cybersecurity circular)

    Flag of TaiwanGuidance

    TFDA

    Taiwan

    Jul 2021

    Flag of MexicoGuidance

    COFEPRIS

    Mexico

    Dec 2021 (NOM-241)

    Flag of United Arab EmiratesMandatory

    MOHAP / DHA / DoH

    United Arab Emirates

    2020 (DoH ADHICS)

    Flag of South AfricaGuidance

    SAHPRA

    South Africa

    2017 (licensing); cyber guidance 2022

    Flag of MalaysiaGuidance

    MDA

    Malaysia

    2021 (cybersecurity guidance)

    Flag of ThailandGuidance

    Thai FDA

    Thailand

    2021 (revised MD Act)

    Flag of IndonesiaGuidance

    Kemenkes

    Indonesia

    2017

    Flag of ArgentinaGuidance

    ANMAT

    Argentina

    2002 (rev. 2022)

    Flag of New ZealandGuidance

    Medsafe

    New Zealand

    WAND active; reform Bill in progress

    Flag of TurkeyMandatory

    TİTCK

    Turkey

    Jun 2021

    Flag of NorwayMandatory

    DMP / Helsetilsynet

    Norway

    May 2021

    Flag of ColombiaGuidance

    INVIMA

    Colombia

    2005 (rev. 2023)

    Flag of ChileEmerging

    ISP / ANID

    Chile

    2024 (Ley 21.541 in implementation)

    Flag of VietnamMandatory

    DMEC / MoH

    Vietnam

    Jan 2022

    Flag of PhilippinesGuidance

    FDA Philippines

    Philippines

    2018

    Flag of UkraineMandatory

    SES

    Ukraine

    2013 (Resolution 753), revised 2023

    Flag of KazakhstanMandatory

    NCEMP

    Kazakhstan

    2016 (EAEU Decision 46)

    Flag of EgyptGuidance

    EDA

    Egypt

    2019 (Law 151/2019 — EDA establishment)

    Flag of Hong KongGuidance

    MDD

    Hong Kong

    2004 (voluntary MDACS launched)

    Flag of KuwaitGuidance

    KDA

    Kuwait

    2017 (KDFC medical device circulars)

    Flag of RussiaMandatory

    Roszdravnadzor

    Russia

    2012 (Gov. Decree 1416)

    Head to head

    The pairings everyone asks about.

    Six in-depth comparisons of the most-searched regulator pairings — bottom-line, deltas, and answers to the questions that come up in every dual-submission planning call.

    Flag of United StatesvsFlag of European Union

    FDA 524B vs EU MDR

    The FDA's §524B regime and the EU MDR cybersecurity expectations (MDCG 2019-16 + GSPR Annex I §17) share a common backbone — SPDF-style lifecycle, SBOM, threat …

    Compare
    Flag of United StatesvsFlag of Japan

    FDA 524B vs PMDA

    PMDA's 2024 cybersecurity guidance is the closest international mirror of FDA §524B — same SPDF logic, same SBOM expectation, same lifecycle commitments. The di…

    Compare
    Flag of United StatesvsFlag of United Kingdom

    FDA 524B vs MHRA

    MHRA recognises CE marking until June 2030 and broadly aligns with MDCG 2019-16, so an FDA cybersecurity package travels well — about 80% reusable. The active d…

    Compare
    Flag of United StatesvsFlag of Canada

    FDA 524B vs Health Canada

    Health Canada's 2024 pre-market cybersecurity guidance is the highest-reuse target on the planet for FDA-cleared devices — roughly 95% of the FDA evidence trans…

    Compare
    Flag of United StatesvsFlag of China

    FDA 524B vs NMPA

    NMPA is the largest reformat on the crosswalk. FDA evidence stays useful, but China overlays MLPS 2.0 (cybersecurity classification), PIPL (personal information…

    Compare
    Flag of European UnionvsFlag of United Kingdom

    EU MDR vs MHRA

    Until 30 June 2030 MHRA accepts CE-marked devices on the GB market with no additional submission — so the cybersecurity file you built for MDR works as-is. Afte…

    Compare
    Flag of European UnionvsFlag of Japan

    EU MDR vs PMDA

    PMDA's 2024 cybersecurity guidance is closer to MDCG 2019-16 than most regulators — both anchor on IMDRF N60 and SPDF logic. About 80% of an EU technical file t…

    Compare
    Flag of European UnionvsFlag of Canada

    EU MDR vs Health Canada

    Health Canada's 2024 pre-market cybersecurity guidance is one of the highest-reuse targets for an EU technical file — roughly 85% lifts cleanly. The additions a…

    Compare
    Flag of United StatesvsFlag of Australia

    FDA 524B vs TGA

    TGA's 2024 cybersecurity guidance v2 is closely aligned to FDA §524B — both reference IMDRF N60, both expect SPDF-style lifecycle evidence, both want an SBOM. A…

    Compare
    Flag of United StatesvsFlag of South Korea

    FDA 524B vs MFDS

    MFDS's 2024 cybersecurity notification is broadly aligned to FDA §524B at the principles level — same lifecycle expectations, same threat-model and SBOM logic. …

    Compare