---
title: "EU MDR vs PMDA: Cybersecurity Compared"
description: "European Union vs Japan medical-device cybersecurity: SBOM, threat modeling, post-market and penalties side by side. PMDA's 2024 cybersecurity guidance is clo"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "EU MDR vs PMDA: Medical Device Cybersecurity Compared",
      "description": "European Union vs Japan medical-device cybersecurity: SBOM, threat modeling, post-market and penalties side by side. PMDA's 2024 cybersecurity guidance is closer to MDCG 2019-16 than most regulator…",
      "about": [
        "European Commission, Medical Device Coordination Group (with national Competent Authorities)",
        "Pharmaceuticals and Medical Devices Agency / Ministry of Health, Labour and Welfare"
      ],
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/compare/eu-mdr-vs-pmda"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is my EU technical file accepted in Japan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not as-is. Japan accepts the content but requires the dossier in PMDA's STED-aligned format, a Japanese MAH, and Japanese-language labelling and IFU. Cybersecurity evidence (threat model, SBOM, pen-test, risk assessment) transfers without rework."
          }
        },
        {
          "@type": "Question",
          "name": "Does PMDA recognise CE marking?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No formal recognition. CE evidence is accepted as supporting documentation in a PMDA dossier, but the regulator runs its own review."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compare",
          "item": "https://mdccrosswalk.lovable.app/compare"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "EU MDR vs PMDA"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  [Compare](/compare)
3.  EU MDR vs PMDA 

Head to head

#  ![Flag of European Union](/flags/eu.svg) EU MDRvs ![Flag of Japan](/flags/jp.svg) PMDA 

European Union and Japan medical-device cybersecurity, compared.

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

Bottom line

PMDA's 2024 cybersecurity guidance is closer to MDCG 2019-16 than most regulators - both anchor on IMDRF N60 and SPDF logic. About 80% of an EU technical file transfers cleanly; the work is translation, a Japanese Marketing Authorisation Holder (MAH), and re-mapping to JIS T 81001-5-1.

Who this is for · EU-CE-marked sponsors planning a Japan Shonin or third-party certification.

## Where they differ

Legal anchor

![Flag of European Union](/flags/eu.svg) EU MDR

MDR Annex I §17 + MDCG 2019-16; CRA from Dec 2027.

![Flag of Japan](/flags/jp.svg) PMDA

PMD Act + Ordinance 169 + MHLW 2023 cyber notification.

Takeaway

Both reference IMDRF N60; PMDA leans on JIS T 81001-5-1 as its primary harmonised standard.

SBOM

![Flag of European Union](/flags/eu.svg) EU MDR

Strongly expected today; mandatory under CRA from 2027.

![Flag of Japan](/flags/jp.svg) PMDA

Recommended; PMDA reviews for connected devices.

Takeaway

One CycloneDX file satisfies both - no rework needed.

Local presence

![Flag of European Union](/flags/eu.svg) EU MDR

EU Authorised Representative.

![Flag of Japan](/flags/jp.svg) PMDA

Japanese Marketing Authorisation Holder (MAH) is mandatory.

Takeaway

MAH liability is broader than an EU AR; choose carefully.

Incident timeline

![Flag of European Union](/flags/eu.svg) EU MDR

15 days (serious); 24 hours for active exploit under CRA (2027+).

![Flag of Japan](/flags/jp.svg) PMDA

15 days for serious incidents; immediate if public-health threat.

Takeaway

Same baseline; CRA will pull EU ahead post-2027.

[

Full profile

### ![Flag of European Union](/flags/eu.svg)European Union

MDR 2017/745 + MDCG 2019-16 Cybersecurity Guidance

Open profile ](/standards/eu)[

Full profile

### ![Flag of Japan](/flags/jp.svg)Japan

PMSD Act + MHLW Cybersecurity Notifications (2023–24)

Open profile ](/standards/jp)

## Frequently asked

### Is my EU technical file accepted in Japan?

Not as-is. Japan accepts the content but requires the dossier in PMDA's STED-aligned format, a Japanese MAH, and Japanese-language labelling and IFU. Cybersecurity evidence (threat model, SBOM, pen-test, risk assessment) transfers without rework.

### Does PMDA recognise CE marking?

No formal recognition. CE evidence is accepted as supporting documentation in a PMDA dossier, but the regulator runs its own review.

## Other head-to-heads

[FDA 524B vs  EU MDR](/compare/fda-vs-eu-mdr)[FDA 524B vs  PMDA](/compare/fda-vs-pmda)[FDA 524B vs  MHRA](/compare/fda-vs-mhra)[FDA 524B vs  Health Canada](/compare/fda-vs-health-canada)[FDA 524B vs  NMPA](/compare/fda-vs-nmpa)[EU MDR vs  MHRA](/compare/eu-mdr-vs-uk-mhra)[EU MDR vs  Health Canada](/compare/eu-mdr-vs-health-canada)[FDA 524B vs  TGA](/compare/fda-vs-tga)[FDA 524B vs  MFDS](/compare/fda-vs-mfds)

Sponsored note · Blue Goat Cyber

Submitting in both European Union and Japan? Blue Goat Cyber has prepared cybersecurity evidence for both markets dozens of times. We'll map your existing package against both, in one 30-minute review.  [Talk through your dual submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.