The Crosswalk

    NewPer-page social previews and this changelog

    EC / MDCG

    Flag of European UnionEuropean Union - EC / MDCG

    MandatoryLast updated · MDCG 2019-16 Rev.1 (2020); CRA reporting obligations begin Sep 11 2026; full CRA compliance Dec 11 2027Verified · 2026-07-16

    MDR 2017/745 + MDCG 2019-16 Cybersecurity Guidance

    Share

    Authority

    European Commission, Medical Device Coordination Group (with national Competent Authorities)

    Enforced

    May 2021

    Legal framework

    MDR Annex I GSPR 17.2 + NIS2 Directive (CRA explicitly excludes products covered by MDR/IVDR)

    FDA package reuse

    ~60%

    Scope

    All medical devices placed on the EU market with electronic programmable systems or software. IVDR mirrors the same expectations.

    Pre-market

    Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.

    Post-market

    PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).

    SBOM

    Recommended

    Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.

    Vulnerability disclosure

    Required under NIS2 for essential/important entities; encouraged for all manufacturers.

    Penalty

    MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).

    Unique requirements

    • 01Minimum IT requirements stated in the IFU
    • 02Notified Body conformity assessment for Class IIa+
    • 03EUDAMED registration and UDI

    Highlights

    • Aligned to IEC 81001-5-1
    • Overlaps with NIS2 for in-scope entities (CRA carve-out)
    • Heavy Notified Body scrutiny of evidence

    Aligns with

    IMDRF N60 IEC 81001-5-1 IEC 62443-4-1 ISO 14971

    Timeline

    1. May 2021

      MDR fully applicable

    2. Jan 2023

      NIS2 enters into force

    3. Dec 10 2024

      CRA enters into force (medical devices excluded under Art. 2)

    4. Sep 11 2026

      CRA Art.14 reporting obligations begin: 24-h early warning + 72-h notification for actively-exploited vulnerabilities and severe incidents

    5. Dec 11 2027

      CRA full compliance deadline (36 months from entry into force)

    Key documents

    How to submit in European Union

    Playbook reviewed · 2026-07-16

    Submission route

    Notified Body conformity assessment under MDR Annex IX/X, with cybersecurity evidence per MDCG 2019-16 rev 1 and (from Dec 2027) CRA essential requirements

    The EU splits the workload between you and your Notified Body. MDR Annex I §17 sets the security-relevant essential requirements; MDCG 2019-16 rev 1 tells the NB what evidence to demand. From December 2027, connectable devices also fall under the Cyber Resilience Act, which adds machine-readable SBOM and 24-hour incident reporting.

    Authority portal

    Step-by-step

    1. Step 01

      Confirm class and NB scope

      Class IIa and above require a Notified Body. Check the NB's designated codes cover your device type and its software components.

    2. Step 02

      Build the Technical Documentation (Annex II/III)

      Include IEC 62304 lifecycle records, IEC 81001-5-1 security lifecycle, risk management under ISO 14971, and usability under IEC 62366-1.

    3. Step 03

      Author the cybersecurity documentation per MDCG 2019-16

      Security risk management, secure design, security verification and validation, and post-market surveillance / vigilance for security incidents.

    4. Step 04

      Prepare CRA-ready SBOM (from Dec 2027)

      SPDX/CycloneDX with vulnerability handling process. Even before the CRA date of application, most NBs already ask for it.

    5. Step 05

      NB audit and TD review

      Expect on-site QMS audit plus deep-dive on the TD sample. Cybersecurity nonconformities are typically Grade 1 (major) if unaddressed.

    6. Step 06

      CE mark and EUDAMED registration

      Register the device and UDI in EUDAMED; keep the DoC and TD accessible for competent authority requests.

    Evidence checklist

    Item Level FDA equivalent Notes
    Security risk management file Required SPDF threat model + risk assessment Integrated with ISO 14971 file, not separate.
    IEC 81001-5-1 lifecycle evidence Required — The de facto expected standard for security development lifecycle in the EU.
    SBOM Recommended 524B(b)(3) Becomes Required for connectable products under CRA in Dec 2027.
    Post-market surveillance plan with security metrics Required Vulnerability management plan
    Vigilance procedure for security incidents Required — Serious incident reporting within 15 days; trend reports quarterly.
    IFU with cybersecurity information Required —

    Common EU MDR rejections

    Security risk management not integrated with ISO 14971

    Common

    Fix · Merge into one risk file with a security-specific annex; NBs reject standalone security registers.

    No IEC 81001-5-1 gap analysis

    Common

    Fix · Even if you claim compliance via another lifecycle, document a mapping to 81001-5-1 clauses.

    Missing CRA readiness plan for connectable devices

    Occasional

    Fix · Add a section describing SBOM format, 24-hour actively exploited vulnerability reporting, and 72-hour incident reporting to ENISA.

    Typical timeline

    End-to-end window: 12-18 months end-to-end for Class IIa/IIb with a competent NB.

    Phase 01

    TD authoring

    3-6 months

    Phase 02

    NB queue for review

    2-6 months

    Highly variable by NB and device class.

    Phase 03

    TD review + audit cycle

    4-9 months

    Phase 04

    EUDAMED registration + market launch

    4-8 weeks

    EU MDR head-to-head

    Related markets

    Frequently asked about European Union

    Is SBOM required for medical devices in European Union?

    Recommended. Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.

    What does EC / MDCG require for pre-market cybersecurity?

    Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.

    What are the post-market cybersecurity obligations under EC / MDCG?

    PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).

    What is the penalty for non-compliance with EC / MDCG cybersecurity rules?

    MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).

    How much of my FDA cybersecurity package is reusable in European Union?

    Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).