The global medical device cybersecurity crosswalk.
The reference RA/QA teams reach for when planning international submissions. Twenty-nine regulators, one device, side by side, without losing a quarter to regulatory whiplash.
Start here
Three questions. We'll route you to the right tool.
Not sure whether to open the matrix, the planner, or a jurisdiction playbook? Answer three quick questions and we'll point you at the shortest path to your answer.
What are you trying to do?
Which markets?
Pick up to 5.
Device risk class?
Per-page social previews and this changelog
Every jurisdiction, pair comparison, and control checklist now renders its own Open Graph preview image, so links shared on LinkedIn and Slack show the actual page title and stats. This changelog and an RSS feed at /rss.xml track updates going forward.
Jurisdictions
38
Cross-cutting frameworks
7
Harmonised baseline
IMDRF N60
EU CRA enforcement
2027
Compare in one click
Pick two. See the deltas.
Choose any two of the 29 jurisdictions to see framework, SBOM, CVD, post-market and penalty rules side by side.
| Dimension |
United States U.S. Food and Drug Administration, Center for Devices and Radiological Health |
European Union European Commission, Medical Device Coordination Group (with national Competent Authorities) |
|---|---|---|
| Legal framework | FD&C Act ยง524B + Feb 3 2026 Final Guidance, aligned to QMSR (21 CFR Part 820 / ISO 13485:2016, effective Feb 2 2026). Supersedes Jun 2025 guidance and replaces 2014 premarket cybersecurity guidance. | MDR Annex I GSPR 17.2 + NIS2 Directive (CRA explicitly excludes products covered by MDR/IVDR) |
| Status | Mandatory | Mandatory |
| Pre-market expectations | Cybersecurity treated as part of device safety under the QMSR (ISO 13485:2016). Secure Product Development Framework (SPDF) presented as one way to satisfy QMSR. Threat model, SBOM in machine-readable format, security risk management (AAMI TIR57), security architecture views (global system, multi-patient harm, updateability), security testing. | Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body. |
| Post-market expectations | Coordinated vulnerability disclosure plan, post-market monitoring, patching commitments and timelines for the supported device lifetime. | PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats). |
| SBOM | Required | Recommended |
| Vulnerability disclosure | Mandatory CVD plan submitted with application. Updates must be free of charge. | Required under NIS2 for essential/important entities; encouraged for all manufacturers. |
| Penalty / enforcement | Refusal to Accept (RTA) of submission, adds months to clearance. | MDR: market removal + national fines. NIS2: up to โฌ10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity). |
| Open full crosswalk | Open full crosswalk |
Not sure which two to pick? Try the Planner for a sequenced roadmap based on your device profile.
Coverage at a glance
The map.
Hover any covered jurisdiction for a one-line read on its cybersecurity maturity. Click to open the full profile.
All jurisdictions
Twenty-nine regulators. One device. Twenty-nine different stories.
FDA / CDRH
United States
Mar 2023
EC / MDCG
European Union
May 2021
MHRA
United Kingdom
Reform program 2024โ26
PMDA / MHLW
Japan
Apr 2024 (cybersecurity notification)
NMPA
China
2022
Health Canada
Canada
Jun 2019
TGA
Australia
Jul 2019 (rev. 2022)
MFDS
South Korea
2019 (rev. 2023); Digital Medical Products Act (DMPA) enforced Jan 24 2025
HSA
Singapore
Apr 2022 (rev.)
ANVISA
Brazil
Mar 2023 (RDC 751)
SFDA
Saudi Arabia
2022
Swissmedic
Switzerland
May 2021 (MedDO)
CDSCO
India
Oct 2023 (full notified-device coverage)
AMAR / MoH
Israel
2019 (cybersecurity circular)
TFDA
Taiwan
Jul 2021
COFEPRIS
Mexico
Dec 2021 (NOM-241)
MOHAP / DHA / DoH
United Arab Emirates
2020 (DoH ADHICS)
SAHPRA
South Africa
2017 (licensing); cyber guidance 2022
MDA
Malaysia
2021 (cybersecurity guidance)
Thai FDA
Thailand
2021 (revised MD Act)
Kemenkes
Indonesia
2017
ANMAT
Argentina
2002 (rev. 2022)
Medsafe
New Zealand
WAND active; reform Bill repealed Dec 2024; replacement Medical Products Bill planned ~2026
TฤฐTCK
Turkey
Jun 2021
DMP / Helsetilsynet
Norway
May 2021
INVIMA
Colombia
2005 (rev. 2023)
ISP / ANID
Chile
2024 (Ley 21.541 in implementation); Exempt Decree No. 25/2026 published Mar 19 2026
DMEC / MoH
Vietnam
Jan 2022
FDA Philippines
Philippines
2018
SES
Ukraine
2013 (Resolution 753), revised 2023
NCEMP
Kazakhstan
2016 (EAEU Decision 46)
EDA
Egypt
2019 (Law 151/2019 - EDA establishment)
MDD
Hong Kong
2004 (voluntary MDACS launched)
KDA
Kuwait
2017 (KDFC medical device circulars)
TFDA
Taiwan
2021 (v1); v2 issued Nov 2023
Thai FDA
Thailand
2008 (Medical Device Act); classification rules 2021
SAHPRA
South Africa
2017 (medical-device licensing under SAHPRA)
Roszdravnadzor
Russia
2012 (Gov. Decree 1416)
Head to head
The pairings everyone asks about.
Six in-depth comparisons of the most-searched regulator pairings - bottom-line, deltas, and answers to the questions that come up in every dual-submission planning call.
FDA 524B vs EU MDR
The FDA's ยง524B regime and the EU MDR cybersecurity expectations (MDCG 2019-16 + GSPR Annex I ยง17) share a common backbone - SPDF-style lifecycle, SBOM, threat โฆ
CompareFDA 524B vs PMDA
PMDA's 2024 cybersecurity guidance is the closest international mirror of FDA ยง524B - same SPDF logic, same SBOM expectation, same lifecycle commitments. The diโฆ
CompareFDA 524B vs MHRA
MHRA recognises CE marking until June 2030 - and following a Feb 2026 targeted consultation, is considering making that recognition indefinite (outcome expectedโฆ
CompareFDA 524B vs Health Canada
Health Canada's 2024 pre-market cybersecurity guidance is the highest-reuse target on the planet for FDA-cleared devices - roughly 95% of the FDA evidence transโฆ
CompareFDA 524B vs NMPA
NMPA is the largest reformat on the crosswalk. FDA evidence stays useful, but China overlays MLPS 2.0 (cybersecurity classification), PIPL (personal informationโฆ
CompareEU MDR vs MHRA
Until 30 June 2030 - or later, if MHRA's Feb 2026 consultation on indefinite CE recognition is enacted - MHRA accepts CE-marked devices on the GB market with noโฆ
CompareEU MDR vs PMDA
PMDA's 2024 cybersecurity guidance is closer to MDCG 2019-16 than most regulators - both anchor on IMDRF N60 and SPDF logic. About 80% of an EU technical file tโฆ
CompareEU MDR vs Health Canada
Health Canada's 2024 pre-market cybersecurity guidance is one of the highest-reuse targets for an EU technical file - roughly 85% lifts cleanly. The additions aโฆ
CompareFDA 524B vs TGA
TGA's 2024 cybersecurity guidance v2 is closely aligned to FDA ยง524B - both reference IMDRF N60, both expect SPDF-style lifecycle evidence, both want an SBOM. Aโฆ
CompareFDA 524B vs MFDS
MFDS's 2024 cybersecurity notification is broadly aligned to FDA ยง524B at the principles level - same lifecycle expectations, same threat-model and SBOM logic. โฆ
Compare