---
title: "Compare Medical Device Cybersecurity Rules Side by Side"
description: "Stack any 5 of 29 jurisdictions head-to-head: legal framework, SBOM, vulnerability disclosure, post-market &amp; penalties. FDA, EU MDR, PMDA &amp; more."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compare",
          "item": "https://mdccrosswalk.lovable.app/compare"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Compare 

Side by side

# Pick your markets. See the deltas.

Select up to five jurisdictions to put their cybersecurity expectations head to head. Click any column header to drill into the full profile.

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

Status key 

Mandatory Statutory or binding regulation. Non-compliance blocks market access. 

Guidance Non-statutory guidance. Typically enforced via review and registration. 

Emerging Framework adopted but not yet fully enforced or in active implementation. 

Filters

All statusMandatoryGuidanceEmerging

SBOM Required only38 / 38 jurisdictions match current filters  Export PDF

Diligence rankingQuick compare (2)FDA translationDeep compare (up to 5)

Cybersecurity diligence ranking

### Which regulators demand the most rigorous cybersecurity evidence?

Composite score (0-100) computed from 29 weighted requirements in the FDA translation matrix. Weightings prioritize dimensions that actually change security posture - threat modeling, SBOM/vuln mapping, testing, CVD, patching, incident reporting - over paperwork-only obligations.

#

Jurisdiction

Diligence score

Tier

Required / Expected

Top gaps vs FDA

1

[![Flag of United States](/flags/us.svg)

FDA 524B

FDA / CDRH



](/standards/fda)

154 

Tier 1 - Rigorous 

24 req · 5 exp

Matches FDA rigor 

2

[![Flag of China](/flags/cn.svg)

NMPA

NMPA



](/standards/cn)

146 

Tier 1 - Rigorous 

20 req · 8 exp

-   Security architecture views (global / multi-patient / updateability) 

3

[![Flag of South Korea](/flags/kr.svg)

MFDS

MFDS



](/standards/kr)

128 

Tier 1 - Rigorous 

6 req · 21 exp

-   Security architecture views (global / multi-patient / updateability) 

4

[![Flag of European Union](/flags/eu.svg)

EU MDR

EC / MDCG



](/standards/eu)

127 

Tier 1 - Rigorous 

7 req · 20 exp

-   Security architecture views (global / multi-patient / updateability) 

5

[![Flag of United Kingdom](/flags/gb.svg)

MHRA

MHRA



](/standards/uk)

122 

Tier 1 - Rigorous 

3 req · 24 exp

-   Security architecture views (global / multi-patient / updateability) 

6

[![Flag of Canada](/flags/ca.svg)

Health Canada

Health Canada



](/standards/ca)

121 

Tier 1 - Rigorous 

3 req · 23 exp

-   Security architecture views (global / multi-patient / updateability) 

7

[![Flag of Switzerland](/flags/ch.svg)

Swissmedic

Swissmedic



](/standards/ch)

121 

Tier 1 - Rigorous 

3 req · 23 exp

-   Security architecture views (global / multi-patient / updateability) 

8

[![Flag of Taiwan](/flags/tw.svg)

TFDA Cyber

TFDA



](/standards/tw)

120 

Tier 1 - Rigorous 

3 req · 22 exp

-   Security architecture views (global / multi-patient / updateability) 

9

[![Flag of Singapore](/flags/sg.svg)

HSA

HSA



](/standards/sg)

117 

Tier 1 - Rigorous 

3 req · 21 exp

-   SBOM tied to known vulnerabilities + support status 
-   Security architecture views (global / multi-patient / updateability) 

10

[![Flag of Japan](/flags/jp.svg)

PMDA

PMDA / MHLW



](/standards/jp)

114 

Tier 1 - Rigorous 

3 req · 19 exp

-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 
-   Security architecture views (global / multi-patient / updateability) 

11

[![Flag of Australia](/flags/au.svg)

TGA

TGA



](/standards/au)

95 

Tier 1 - Rigorous 

3 req · 3 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

12

[![Flag of India](/flags/in.svg)

CDSCO

CDSCO



](/standards/in)

91 

Tier 1 - Rigorous 

2 req · 4 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

13

[![Flag of Israel](/flags/il.svg)

AMAR

AMAR / MoH



](/standards/il)

91 

Tier 1 - Rigorous 

2 req · 2 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

14

[![Flag of Saudi Arabia](/flags/sa.svg)

SFDA

SFDA



](/standards/sa)

86 

Tier 1 - Rigorous 

1 req · 4 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

15

[![Flag of Brazil](/flags/br.svg)

ANVISA

ANVISA



](/standards/br)

84 

Tier 2 - Substantive 

1 req · 3 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

16

[![Flag of United Arab Emirates](/flags/ae.svg)

MOHAP

MOHAP / DHA / DoH



](/standards/ae)

81 

Tier 2 - Substantive 

0 req · 3 exp

-   Threat model with device-specific attack surface 
-   Machine-readable SBOM (SPDX or CycloneDX) 
-   SBOM tied to known vulnerabilities + support status 

Not sure how to use this? Try the [journey planner](/planner) to turn these scores into a sequenced submission roadmap.

Sponsored note · Blue Goat Cyber

Building one cybersecurity package for multiple markets? That's the entire premise of how Blue Goat Cyber works, design once against the strictest common denominator, then map evidence to each regulator. We've done it 250+ times. Zero rejections.  [See how we'd structure yours](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.