---
title: "IMDRF N73 - Principles &amp; practices for SBOM in medical devic"
description: "International Medical Device Regulators Forum · The international playbook for software bill of materials in medical devices. Defines content, format, exchang"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "IMDRF N73 - Principles & practices for SBOM in medical device cybersecurity",
      "description": "The international playbook for software bill of materials in medical devices. Defines content, format, exchange and lifecycle expectations for SBOMs.",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2026-05-28",
      "dateModified": "2026-05-28",
      "about": "International Medical Device Regulators Forum",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/frameworks/imdrf-n73"
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Frameworks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "IMDRF N73"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Frameworks 
3.  IMDRF N73 

International Medical Device Regulators Forum

# IMDRF N73

[Source](https://www.imdrf.org/documents/principles-and-practices-software-bill-materials-medical-device-cybersecurity)

Principles & practices for SBOM in medical device cybersecurity

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

## What it is

The international playbook for software bill of materials in medical devices. Defines content, format, exchange and lifecycle expectations for SBOMs.

## Why it matters

Generate one CycloneDX or SPDX SBOM aligned to N73 and you satisfy the FDA, are accepted by Health Canada and South Korea, and have ~80% of what the EU CRA will demand from 2027.

## Adopted or referenced by

FDA  Health Canada  MFDS  EU (partly)  PMDA (partly)  HSA (partly)  TGA (partly) 

Verified adoption · self-reported by regulators

## Implementation status across IMDRF members

[IMDRF/MC/N84 FINAL:2025 (Edition 2) · 1 September 2025](https://www.imdrf.org/sites/default/files/2025-09/IMDRF%20Document%20Implementation%20Report%201September2025_0.pdf)

3 of 14 regulators report full implementation. 6 partial. 5 not yet.

Implemented

3 

-   Canada
-   South Korea
-   USA

Partly implemented

6 

-   Australia
-   China
-   EU
-   Japan
-   Singapore
-   Switzerland

Not implemented

5 

-   Brazil
-   Russia
-   UK
-   Argentina
-   Saudi Arabia

Status reported by each regulator to IMDRF as of 1 September 2025. "Implemented" means all relevant elements, concepts and principles of the IMDRF document are followed; "partly" means modified or applied to a narrower product range. Source: [IMDRF/MC/N84 FINAL:2025 (Edition 2)](https://www.imdrf.org/sites/default/files/2025-09/IMDRF%20Document%20Implementation%20Report%201September2025_0.pdf).

## Key clauses

Machine-readable formats

SPDX or CycloneDX. JSON or XML. Tags for known vulnerabilities and support level.

Lifecycle commitment

SBOM updated at every release; legacy components flagged with end-of-support dates.

Distribution

Provided to procurers and operators on request, not just regulators.

[Previous IMDRF N60 ](/frameworks/imdrf-n60)[Next  IMDRF N70 ](/frameworks/imdrf-n70)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.