---
title: "FDA 524B vs MHRA: Cybersecurity Compared"
description: "United States vs United Kingdom medical-device cybersecurity: SBOM, threat modeling, post-market and penalties side by side. MHRA recognises CE marking until"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "FDA 524B vs MHRA: Medical Device Cybersecurity Compared",
      "description": "United States vs United Kingdom medical-device cybersecurity: SBOM, threat modeling, post-market and penalties side by side. MHRA recognises CE marking until June 2030 - and following a Feb 2026 targeted c…",
      "about": [
        "U.S. Food and Drug Administration, Center for Devices and Radiological Health",
        "Medicines and Healthcare products Regulatory Agency"
      ],
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/compare/fda-vs-mhra"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Do I need a separate UK submission if I have CE marking?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Until June 30 2030 - and potentially indefinitely if MHRA's Feb 2026 consultation on indefinite CE recognition is enacted - CE-marked devices may be placed on the GB market with no further submission. After that date (if the deadline holds), expect a UKCA / UK SaMD pathway requiring UKRP-held documentation including cybersecurity evidence."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compare",
          "item": "https://mdccrosswalk.lovable.app/compare"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "FDA 524B vs MHRA"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  [Compare](/compare)
3.  FDA 524B vs MHRA 

Head to head

#  ![Flag of United States](/flags/us.svg) FDA 524Bvs ![Flag of United Kingdom](/flags/gb.svg) MHRA 

United States and United Kingdom medical-device cybersecurity, compared.

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

Bottom line

MHRA recognises CE marking until June 2030 - and following a Feb 2026 targeted consultation, is considering making that recognition indefinite (outcome expected later in 2026). MHRA broadly aligns with MDCG 2019-16, so an FDA cybersecurity package travels well - about 80% reusable. The active divergence is the UK's emerging post-market vigilance regime and the future Software-as-a-Medical-Device framework, both of which are tightening faster than the US baseline.

Who this is for · US sponsors evaluating the UKCA / MHRA route post-Brexit.

## Where they differ

Legal basis

![Flag of United States](/flags/us.svg) FDA 524B

FD&C §524B.

![Flag of United Kingdom](/flags/gb.svg) MHRA

UK MDR 2002 (as amended) + recognition of CE / IMDRF.

Takeaway

MHRA is converging with EU MDR for now; SaMD framework is in flux.

SBOM

![Flag of United States](/flags/us.svg) FDA 524B

Mandatory.

![Flag of United Kingdom](/flags/gb.svg) MHRA

Strongly expected; explicit in draft UK SaMD guidance.

Takeaway

Generate once, file everywhere.

Local presence

![Flag of United States](/flags/us.svg) FDA 524B

U.S. agent.

![Flag of United Kingdom](/flags/gb.svg) MHRA

UK Responsible Person (UKRP) required for non-UK manufacturers.

Takeaway

UKRP holds the technical file including your cyber documentation.

[

Full profile

### ![Flag of United States](/flags/us.svg)United States

FDA Premarket Cybersecurity Guidance & FD&C §524B

Open profile ](/standards/fda)[

Full profile

### ![Flag of United Kingdom](/flags/gb.svg)United Kingdom

UK MDR 2002 (as amended) + MHRA Cyber Guidance

Open profile ](/standards/uk)

## Frequently asked

### Do I need a separate UK submission if I have CE marking?

Until June 30 2030 - and potentially indefinitely if MHRA's Feb 2026 consultation on indefinite CE recognition is enacted - CE-marked devices may be placed on the GB market with no further submission. After that date (if the deadline holds), expect a UKCA / UK SaMD pathway requiring UKRP-held documentation including cybersecurity evidence.

## Other head-to-heads

[FDA 524B vs  EU MDR](/compare/fda-vs-eu-mdr)[FDA 524B vs  PMDA](/compare/fda-vs-pmda)[FDA 524B vs  Health Canada](/compare/fda-vs-health-canada)[FDA 524B vs  NMPA](/compare/fda-vs-nmpa)[EU MDR vs  MHRA](/compare/eu-mdr-vs-uk-mhra)[EU MDR vs  PMDA](/compare/eu-mdr-vs-pmda)[EU MDR vs  Health Canada](/compare/eu-mdr-vs-health-canada)[FDA 524B vs  TGA](/compare/fda-vs-tga)[FDA 524B vs  MFDS](/compare/fda-vs-mfds)

Sponsored note · Blue Goat Cyber

Submitting in both United States and United Kingdom? Blue Goat Cyber has prepared cybersecurity evidence for both markets dozens of times. We'll map your existing package against both, in one 30-minute review.  [Talk through your dual submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.