EC / MDCG
European Union - EC / MDCG
MDR 2017/745 + MDCG 2019-16 Cybersecurity Guidance
Authority
European Commission, Medical Device Coordination Group (with national Competent Authorities)
Enforced
May 2021
Legal framework
MDR Annex I GSPR 17.2 + NIS2 Directive (CRA explicitly excludes products covered by MDR/IVDR)
Scope
All medical devices placed on the EU market with electronic programmable systems or software. IVDR mirrors the same expectations.
Pre-market
Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.
Post-market
PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).
SBOM
RecommendedNot yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.
Vulnerability disclosure
Required under NIS2 for essential/important entities; encouraged for all manufacturers.
Penalty
MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).
Unique requirements
- 01Minimum IT requirements stated in the IFU
- 02Notified Body conformity assessment for Class IIa+
- 03EUDAMED registration and UDI
Highlights
- Aligned to IEC 81001-5-1
- Overlaps with NIS2 for in-scope entities (CRA carve-out)
- Heavy Notified Body scrutiny of evidence
Aligns with
Timeline
-
May 2021
MDR fully applicable
-
Jan 2023
NIS2 enters into force
-
Dec 10 2024
CRA enters into force (medical devices excluded under Art. 2)
-
Sep 11 2026
CRA Art.14 reporting obligations begin: 24-h early warning + 72-h notification for actively-exploited vulnerabilities and severe incidents
-
Dec 11 2027
CRA full compliance deadline (36 months from entry into force)
Key documents
MDCG 2019-16 Rev.1 Guidance on Cybersecurity
https://health.ec.europa.eu/system/files/2022-01/md_cybersecurity_en.pdf
Regulation (EU) 2017/745, MDR
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32017R0745
Cyber Resilience Act
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
How to submit in European Union
Playbook reviewed · 2026-07-16
Submission route
Notified Body conformity assessment under MDR Annex IX/X, with cybersecurity evidence per MDCG 2019-16 rev 1 and (from Dec 2027) CRA essential requirements
The EU splits the workload between you and your Notified Body. MDR Annex I §17 sets the security-relevant essential requirements; MDCG 2019-16 rev 1 tells the NB what evidence to demand. From December 2027, connectable devices also fall under the Cyber Resilience Act, which adds machine-readable SBOM and 24-hour incident reporting.
Authority portalStep-by-step
-
Step 01
Confirm class and NB scope
Class IIa and above require a Notified Body. Check the NB's designated codes cover your device type and its software components.
-
Step 02
Build the Technical Documentation (Annex II/III)
Include IEC 62304 lifecycle records, IEC 81001-5-1 security lifecycle, risk management under ISO 14971, and usability under IEC 62366-1.
-
Step 03
Author the cybersecurity documentation per MDCG 2019-16
Security risk management, secure design, security verification and validation, and post-market surveillance / vigilance for security incidents.
-
Step 04
Prepare CRA-ready SBOM (from Dec 2027)
SPDX/CycloneDX with vulnerability handling process. Even before the CRA date of application, most NBs already ask for it.
-
Step 05
NB audit and TD review
Expect on-site QMS audit plus deep-dive on the TD sample. Cybersecurity nonconformities are typically Grade 1 (major) if unaddressed.
-
Step 06
CE mark and EUDAMED registration
Register the device and UDI in EUDAMED; keep the DoC and TD accessible for competent authority requests.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Security risk management file | Required | SPDF threat model + risk assessment | Integrated with ISO 14971 file, not separate. |
| IEC 81001-5-1 lifecycle evidence | Required | — | The de facto expected standard for security development lifecycle in the EU. |
| SBOM | Recommended | 524B(b)(3) | Becomes Required for connectable products under CRA in Dec 2027. |
| Post-market surveillance plan with security metrics | Required | Vulnerability management plan | |
| Vigilance procedure for security incidents | Required | — | Serious incident reporting within 15 days; trend reports quarterly. |
| IFU with cybersecurity information | Required | — |
Common EU MDR rejections
Security risk management not integrated with ISO 14971
CommonFix · Merge into one risk file with a security-specific annex; NBs reject standalone security registers.
No IEC 81001-5-1 gap analysis
CommonFix · Even if you claim compliance via another lifecycle, document a mapping to 81001-5-1 clauses.
Missing CRA readiness plan for connectable devices
OccasionalFix · Add a section describing SBOM format, 24-hour actively exploited vulnerability reporting, and 72-hour incident reporting to ENISA.
Typical timeline
End-to-end window: 12-18 months end-to-end for Class IIa/IIb with a competent NB.
Phase 01
TD authoring
3-6 months
Phase 02
NB queue for review
2-6 months
Highly variable by NB and device class.
Phase 03
TD review + audit cycle
4-9 months
Phase 04
EUDAMED registration + market launch
4-8 weeks
EU MDR head-to-head
Related markets
Frequently asked about European Union
Is SBOM required for medical devices in European Union?
Recommended. Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.
What does EC / MDCG require for pre-market cybersecurity?
Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.
What are the post-market cybersecurity obligations under EC / MDCG?
PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).
What is the penalty for non-compliance with EC / MDCG cybersecurity rules?
MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).
How much of my FDA cybersecurity package is reusable in European Union?
Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).