The Crosswalk

    NewPer-page social previews and this changelog
    The Crosswalk

    The global medical device cybersecurity crosswalk.

    The reference RA/QA teams reach for when planning international submissions. Twenty-nine regulators, one device, side by side, without losing a quarter to regulatory whiplash.

    Sponsored by Blue Goat Cyber
    Last updated ยท

    Start here

    Three questions. We'll route you to the right tool.

    Not sure whether to open the matrix, the planner, or a jurisdiction playbook? Answer three quick questions and we'll point you at the shortest path to your answer.

    1

    What are you trying to do?

    2

    Which markets?

    Pick up to 5.

    3

    Device risk class?

    Take me there Answer question 1 to continue.
    What's newJul 25, 2026
    Feature

    Per-page social previews and this changelog

    Every jurisdiction, pair comparison, and control checklist now renders its own Open Graph preview image, so links shared on LinkedIn and Slack show the actual page title and stats. This changelog and an RSS feed at /rss.xml track updates going forward.

    See all updates

    Jurisdictions

    38

    Cross-cutting frameworks

    7

    Harmonised baseline

    IMDRF N60

    EU CRA enforcement

    2027

    Compare in one click

    Pick two. See the deltas.

    Choose any two of the 29 jurisdictions to see framework, SBOM, CVD, post-market and penalty rules side by side.

    Full matrix
    Control-by-control checklist
    Dimension
    Flag of United States

    United States

    U.S. Food and Drug Administration, Center for Devices and Radiological Health

    Leading tier
    Flag of European Union

    European Union

    European Commission, Medical Device Coordination Group (with national Competent Authorities)

    Leading tier
    Legal framework FD&C Act ยง524B + Feb 3 2026 Final Guidance, aligned to QMSR (21 CFR Part 820 / ISO 13485:2016, effective Feb 2 2026). Supersedes Jun 2025 guidance and replaces 2014 premarket cybersecurity guidance. MDR Annex I GSPR 17.2 + NIS2 Directive (CRA explicitly excludes products covered by MDR/IVDR)
    Status Mandatory Mandatory
    Pre-market expectations Cybersecurity treated as part of device safety under the QMSR (ISO 13485:2016). Secure Product Development Framework (SPDF) presented as one way to satisfy QMSR. Threat model, SBOM in machine-readable format, security risk management (AAMI TIR57), security architecture views (global system, multi-patient harm, updateability), security testing. Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.
    Post-market expectations Coordinated vulnerability disclosure plan, post-market monitoring, patching commitments and timelines for the supported device lifetime. PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).
    SBOM Required Recommended
    Vulnerability disclosure Mandatory CVD plan submitted with application. Updates must be free of charge. Required under NIS2 for essential/important entities; encouraged for all manufacturers.
    Penalty / enforcement Refusal to Accept (RTA) of submission, adds months to clearance. MDR: market removal + national fines. NIS2: up to โ‚ฌ10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).
    Open full crosswalk Open full crosswalk

    Not sure which two to pick? Try the Planner for a sequenced roadmap based on your device profile.

    Coverage at a glance

    The map.

    Hover any covered jurisdiction for a one-line read on its cybersecurity maturity. Click to open the full profile.

    Leading - statutory, SBOM mandated
    Advanced - mandatory, robust framework
    Developing - guidance, tightening
    Emerging - early-stage requirements
    Watchlist - regulator known, no cyber crosswalk yet
    Sanctions - commercial export restricted

    All jurisdictions

    Twenty-nine regulators. One device. Twenty-nine different stories.

    Status key
    MandatoryStatutory or binding regulation. Non-compliance blocks market access.
    GuidanceNon-statutory guidance. Typically enforced via review and registration.
    EmergingFramework adopted but not yet fully enforced or in active implementation.
    Flag of United StatesMandatory

    FDA / CDRH

    United States

    Mar 2023

    Flag of European UnionMandatory

    EC / MDCG

    European Union

    May 2021

    Flag of United KingdomGuidance

    MHRA

    United Kingdom

    Reform program 2024โ€“26

    Flag of JapanMandatory

    PMDA / MHLW

    Japan

    Apr 2024 (cybersecurity notification)

    Flag of ChinaMandatory

    NMPA

    China

    2022

    Flag of CanadaMandatory

    Health Canada

    Canada

    Jun 2019

    Flag of AustraliaGuidance

    TGA

    Australia

    Jul 2019 (rev. 2022)

    Flag of South KoreaMandatory

    MFDS

    South Korea

    2019 (rev. 2023); Digital Medical Products Act (DMPA) enforced Jan 24 2025

    Flag of SingaporeGuidance

    HSA

    Singapore

    Apr 2022 (rev.)

    Flag of BrazilMandatory

    ANVISA

    Brazil

    Mar 2023 (RDC 751)

    Flag of Saudi ArabiaGuidance

    SFDA

    Saudi Arabia

    2022

    Flag of SwitzerlandMandatory

    Swissmedic

    Switzerland

    May 2021 (MedDO)

    Flag of IndiaGuidance

    CDSCO

    India

    Oct 2023 (full notified-device coverage)

    Flag of IsraelMandatory

    AMAR / MoH

    Israel

    2019 (cybersecurity circular)

    Flag of TaiwanGuidance

    TFDA

    Taiwan

    Jul 2021

    Flag of MexicoGuidance

    COFEPRIS

    Mexico

    Dec 2021 (NOM-241)

    Flag of United Arab EmiratesMandatory

    MOHAP / DHA / DoH

    United Arab Emirates

    2020 (DoH ADHICS)

    Flag of South AfricaGuidance

    SAHPRA

    South Africa

    2017 (licensing); cyber guidance 2022

    Flag of MalaysiaGuidance

    MDA

    Malaysia

    2021 (cybersecurity guidance)

    Flag of ThailandGuidance

    Thai FDA

    Thailand

    2021 (revised MD Act)

    Flag of IndonesiaGuidance

    Kemenkes

    Indonesia

    2017

    Flag of ArgentinaGuidance

    ANMAT

    Argentina

    2002 (rev. 2022)

    Flag of New ZealandGuidance

    Medsafe

    New Zealand

    WAND active; reform Bill repealed Dec 2024; replacement Medical Products Bill planned ~2026

    Flag of TurkeyMandatory

    TฤฐTCK

    Turkey

    Jun 2021

    Flag of NorwayMandatory

    DMP / Helsetilsynet

    Norway

    May 2021

    Flag of ColombiaGuidance

    INVIMA

    Colombia

    2005 (rev. 2023)

    Flag of ChileEmerging

    ISP / ANID

    Chile

    2024 (Ley 21.541 in implementation); Exempt Decree No. 25/2026 published Mar 19 2026

    Flag of VietnamMandatory

    DMEC / MoH

    Vietnam

    Jan 2022

    Flag of PhilippinesGuidance

    FDA Philippines

    Philippines

    2018

    Flag of UkraineMandatory

    SES

    Ukraine

    2013 (Resolution 753), revised 2023

    Flag of KazakhstanMandatory

    NCEMP

    Kazakhstan

    2016 (EAEU Decision 46)

    Flag of EgyptGuidance

    EDA

    Egypt

    2019 (Law 151/2019 - EDA establishment)

    Flag of Hong KongGuidance

    MDD

    Hong Kong

    2004 (voluntary MDACS launched)

    Flag of KuwaitGuidance

    KDA

    Kuwait

    2017 (KDFC medical device circulars)

    Flag of TaiwanGuidance

    TFDA

    Taiwan

    2021 (v1); v2 issued Nov 2023

    Flag of ThailandGuidance

    Thai FDA

    Thailand

    2008 (Medical Device Act); classification rules 2021

    Flag of South AfricaGuidance

    SAHPRA

    South Africa

    2017 (medical-device licensing under SAHPRA)

    Flag of RussiaMandatory

    Roszdravnadzor

    Russia

    2012 (Gov. Decree 1416)

    Head to head

    The pairings everyone asks about.

    Six in-depth comparisons of the most-searched regulator pairings - bottom-line, deltas, and answers to the questions that come up in every dual-submission planning call.

    Flag of United StatesvsFlag of European Union

    FDA 524B vs EU MDR

    The FDA's ยง524B regime and the EU MDR cybersecurity expectations (MDCG 2019-16 + GSPR Annex I ยง17) share a common backbone - SPDF-style lifecycle, SBOM, threat โ€ฆ

    Compare
    Flag of United StatesvsFlag of Japan

    FDA 524B vs PMDA

    PMDA's 2024 cybersecurity guidance is the closest international mirror of FDA ยง524B - same SPDF logic, same SBOM expectation, same lifecycle commitments. The diโ€ฆ

    Compare
    Flag of United StatesvsFlag of United Kingdom

    FDA 524B vs MHRA

    MHRA recognises CE marking until June 2030 - and following a Feb 2026 targeted consultation, is considering making that recognition indefinite (outcome expectedโ€ฆ

    Compare
    Flag of United StatesvsFlag of Canada

    FDA 524B vs Health Canada

    Health Canada's 2024 pre-market cybersecurity guidance is the highest-reuse target on the planet for FDA-cleared devices - roughly 95% of the FDA evidence transโ€ฆ

    Compare
    Flag of United StatesvsFlag of China

    FDA 524B vs NMPA

    NMPA is the largest reformat on the crosswalk. FDA evidence stays useful, but China overlays MLPS 2.0 (cybersecurity classification), PIPL (personal informationโ€ฆ

    Compare
    Flag of European UnionvsFlag of United Kingdom

    EU MDR vs MHRA

    Until 30 June 2030 - or later, if MHRA's Feb 2026 consultation on indefinite CE recognition is enacted - MHRA accepts CE-marked devices on the GB market with noโ€ฆ

    Compare
    Flag of European UnionvsFlag of Japan

    EU MDR vs PMDA

    PMDA's 2024 cybersecurity guidance is closer to MDCG 2019-16 than most regulators - both anchor on IMDRF N60 and SPDF logic. About 80% of an EU technical file tโ€ฆ

    Compare
    Flag of European UnionvsFlag of Canada

    EU MDR vs Health Canada

    Health Canada's 2024 pre-market cybersecurity guidance is one of the highest-reuse targets for an EU technical file - roughly 85% lifts cleanly. The additions aโ€ฆ

    Compare
    Flag of United StatesvsFlag of Australia

    FDA 524B vs TGA

    TGA's 2024 cybersecurity guidance v2 is closely aligned to FDA ยง524B - both reference IMDRF N60, both expect SPDF-style lifecycle evidence, both want an SBOM. Aโ€ฆ

    Compare
    Flag of United StatesvsFlag of South Korea

    FDA 524B vs MFDS

    MFDS's 2024 cybersecurity notification is broadly aligned to FDA ยง524B at the principles level - same lifecycle expectations, same threat-model and SBOM logic. โ€ฆ

    Compare