---
title: "IMDRF N70 - Principles &amp; practices for the cybersecurity of"
description: "International Medical Device Regulators Forum · Guidance for managing devices that are still in active clinical use but no longer fully supported. Defines rol"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "IMDRF N70 - Principles & practices for the cybersecurity of legacy medical devices",
      "description": "Guidance for managing devices that are still in active clinical use but no longer fully supported. Defines roles for manufacturers, healthcare delivery organisations and regulators across the legacy phase of the lifecycle.",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2026-05-28",
      "dateModified": "2026-05-28",
      "about": "International Medical Device Regulators Forum",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/frameworks/imdrf-n70"
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Frameworks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "IMDRF N70"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Frameworks 
3.  IMDRF N70 

International Medical Device Regulators Forum

# IMDRF N70

[Source](https://www.imdrf.org/documents/principles-and-practices-cybersecurity-legacy-medical-devices)

Principles & practices for the cybersecurity of legacy medical devices

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

## What it is

Guidance for managing devices that are still in active clinical use but no longer fully supported. Defines roles for manufacturers, healthcare delivery organisations and regulators across the legacy phase of the lifecycle.

## Why it matters

If your portfolio includes any device older than 5 years that's still on the market, N70 is the reference regulators will measure your end-of-life and patching commitments against.

## Adopted or referenced by

FDA  EU MDR  MFDS  Swissmedic  PMDA (partly)  HSA (partly) 

Verified adoption · self-reported by regulators

## Implementation status across IMDRF members

[IMDRF/MC/N84 FINAL:2025 (Edition 2) · 1 September 2025](https://www.imdrf.org/sites/default/files/2025-09/IMDRF%20Document%20Implementation%20Report%201September2025_0.pdf)

4 of 14 regulators report full implementation. 3 partial. 7 not yet.

Implemented

4 

-   EU
-   South Korea
-   Switzerland
-   USA

Partly implemented

3 

-   China
-   Japan
-   Singapore

Not implemented

7 

-   Australia
-   Brazil
-   Canada
-   Russia
-   UK
-   Argentina
-   Saudi Arabia

Status reported by each regulator to IMDRF as of 1 September 2025. "Implemented" means all relevant elements, concepts and principles of the IMDRF document are followed; "partly" means modified or applied to a narrower product range. Source: [IMDRF/MC/N84 FINAL:2025 (Edition 2)](https://www.imdrf.org/sites/default/files/2025-09/IMDRF%20Document%20Implementation%20Report%201September2025_0.pdf).

## Key clauses

Lifecycle phases

Defines development, support, limited-support and end-of-support phases with clear obligations at each.

Communication

Manufacturers must publish end-of-support dates and security advisories to operators.

Compensating controls

When patching is no longer feasible, alternative mitigations must be documented and shared.

[Previous IMDRF N73 ](/frameworks/imdrf-n73)[Next  IEC 81001-5-1 ](/frameworks/iec-81001-5-1)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.