---
title: "European Union EU MDR - Cybersecurity Submission Playbook"
description: "How to submit a medical device to EC / MDCG in European Union: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compare"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "European Union - MDR 2017/745 + MDCG 2019-16 Cybersecurity Guidance",
      "description": "How to submit a medical device to EC / MDCG in European Union: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compare",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "MDCG 2019-16 Rev.1 (2020); CRA reporting obligations begin Sep 11 2026; full CRA compliance Dec 11 2027",
      "about": "European Commission, Medical Device Coordination Group (with national Competent Authorities)",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/eu"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in European Union?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply."
          }
        },
        {
          "@type": "Question",
          "name": "What does EC / MDCG require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under EC / MDCG?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats)."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with EC / MDCG cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity)."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in European Union?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do EU MDR submissions get rejected for \"security risk management not integrated with iso 14971\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Merge into one risk file with a security-specific annex; NBs reject standalone security registers."
          }
        },
        {
          "@type": "Question",
          "name": "Why do EU MDR submissions get rejected for \"no iec 81001-5-1 gap analysis\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Even if you claim compliance via another lifecycle, document a mapping to 81001-5-1 clauses."
          }
        },
        {
          "@type": "Question",
          "name": "Why do EU MDR submissions get rejected for \"missing cra readiness plan for connectable devices\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add a section describing SBOM format, 24-hour actively exploited vulnerability reporting, and 72-hour incident reporting to ENISA."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to EC / MDCG",
      "description": "The EU splits the workload between you and your Notified Body. MDR Annex I §17 sets the security-relevant essential requirements; MDCG 2019-16 rev 1 tells the NB what evidence to demand. From December 2027, connectable devices also fall under the Cyber Resilience Act, which adds machine-readable SBOM and 24-hour incident reporting.",
      "totalTime": "12-18 months end-to-end for Class IIa/IIb with a competent NB.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Confirm class and NB scope",
          "text": "Class IIa and above require a Notified Body. Check the NB's designated codes cover your device type and its software components."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Build the Technical Documentation (Annex II/III)",
          "text": "Include IEC 62304 lifecycle records, IEC 81001-5-1 security lifecycle, risk management under ISO 14971, and usability under IEC 62366-1."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Author the cybersecurity documentation per MDCG 2019-16",
          "text": "Security risk management, secure design, security verification and validation, and post-market surveillance / vigilance for security incidents."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Prepare CRA-ready SBOM (from Dec 2027)",
          "text": "SPDX/CycloneDX with vulnerability handling process. Even before the CRA date of application, most NBs already ask for it."
        },
        {
          "@type": "HowToStep",
          "position": 5,
          "name": "NB audit and TD review",
          "text": "Expect on-site QMS audit plus deep-dive on the TD sample. Cybersecurity nonconformities are typically Grade 1 (major) if unaddressed."
        },
        {
          "@type": "HowToStep",
          "position": 6,
          "name": "CE mark and EUDAMED registration",
          "text": "Register the device and UDI in EUDAMED; keep the DoC and TD accessible for competent authority requests."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "European Union"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  European Union 

EC / MDCG

# ![Flag of European Union](/flags/eu.svg)European Union - EC / MDCG 

Mandatory Last updated · MDCG 2019-16 Rev.1 (2020); CRA reporting obligations begin Sep 11 2026; full CRA compliance Dec 11 2027 Verified · 2026-07-16 

MDR 2017/745 + MDCG 2019-16 Cybersecurity Guidance

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against MDR Annex I, MDCG 2019-16, and CRA scope (medical devices excluded from CRA).

Authority

European Commission, Medical Device Coordination Group (with national Competent Authorities)

Enforced

May 2021

Legal framework

MDR Annex I GSPR 17.2 + NIS2 Directive (CRA explicitly excludes products covered by MDR/IVDR)

FDA package reuse

~60%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices placed on the EU market with electronic programmable systems or software. IVDR mirrors the same expectations.

Pre-market

Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.

Post-market

PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).

SBOM

Recommended 

Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.

Vulnerability disclosure

Required under NIS2 for essential/important entities; encouraged for all manufacturers.

Penalty

MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).

## Unique requirements

-   01 Minimum IT requirements stated in the IFU 
-   02 Notified Body conformity assessment for Class IIa+ 
-   03 EUDAMED registration and UDI 

## Highlights

-   Aligned to IEC 81001-5-1 
-   Overlaps with NIS2 for in-scope entities (CRA carve-out) 
-   Heavy Notified Body scrutiny of evidence 

## Aligns with

IMDRF N60  IEC 81001-5-1  IEC 62443-4-1  ISO 14971 

## Timeline

1.  May 2021
    
    MDR fully applicable
    
2.  Jan 2023
    
    NIS2 enters into force
    
3.  Dec 10 2024
    
    CRA enters into force (medical devices excluded under Art. 2)
    
4.  Sep 11 2026
    
    CRA Art.14 reporting obligations begin: 24-h early warning + 72-h notification for actively-exploited vulnerabilities and severe incidents
    
5.  Dec 11 2027
    
    CRA full compliance deadline (36 months from entry into force)
    

## Key documents

[

MDCG 2019-16 Rev.1 Guidance on Cybersecurity

https://health.ec.europa.eu/system/files/2022-01/md\_cybersecurity\_en.pdf



](https://health.ec.europa.eu/system/files/2022-01/md_cybersecurity_en.pdf)[

Regulation (EU) 2017/745, MDR

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32017R0745



](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32017R0745)[

Cyber Resilience Act

https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act



](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)

## How to submit in European Union

Playbook reviewed · 2026-07-16

Submission route

Notified Body conformity assessment under MDR Annex IX/X, with cybersecurity evidence per MDCG 2019-16 rev 1 and (from Dec 2027) CRA essential requirements

The EU splits the workload between you and your Notified Body. MDR Annex I §17 sets the security-relevant essential requirements; MDCG 2019-16 rev 1 tells the NB what evidence to demand. From December 2027, connectable devices also fall under the Cyber Resilience Act, which adds machine-readable SBOM and 24-hour incident reporting.

[Authority portal](https://health.ec.europa.eu/medical-devices-sector_en)

### Step-by-step

1.  Step 01
    
    Confirm class and NB scope
    
    Class IIa and above require a Notified Body. Check the NB's designated codes cover your device type and its software components.
    
2.  Step 02
    
    Build the Technical Documentation (Annex II/III)
    
    Include IEC 62304 lifecycle records, IEC 81001-5-1 security lifecycle, risk management under ISO 14971, and usability under IEC 62366-1.
    
3.  Step 03
    
    Author the cybersecurity documentation per MDCG 2019-16
    
    Security risk management, secure design, security verification and validation, and post-market surveillance / vigilance for security incidents.
    
4.  Step 04
    
    Prepare CRA-ready SBOM (from Dec 2027)
    
    SPDX/CycloneDX with vulnerability handling process. Even before the CRA date of application, most NBs already ask for it.
    
5.  Step 05
    
    NB audit and TD review
    
    Expect on-site QMS audit plus deep-dive on the TD sample. Cybersecurity nonconformities are typically Grade 1 (major) if unaddressed.
    
6.  Step 06
    
    CE mark and EUDAMED registration
    
    Register the device and UDI in EUDAMED; keep the DoC and TD accessible for competent authority requests.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Security risk management file

Required 

SPDF threat model + risk assessment

Integrated with ISO 14971 file, not separate.

IEC 81001-5-1 lifecycle evidence

Required 

—

The de facto expected standard for security development lifecycle in the EU.

SBOM

Recommended 

524B(b)(3)

Becomes Required for connectable products under CRA in Dec 2027.

Post-market surveillance plan with security metrics

Required 

Vulnerability management plan

Vigilance procedure for security incidents

Required 

—

Serious incident reporting within 15 days; trend reports quarterly.

IFU with cybersecurity information

Required 

—

### Common EU MDR rejections

Security risk management not integrated with ISO 14971

Common 

Fix ·  Merge into one risk file with a security-specific annex; NBs reject standalone security registers.

No IEC 81001-5-1 gap analysis

Common 

Fix ·  Even if you claim compliance via another lifecycle, document a mapping to 81001-5-1 clauses.

Missing CRA readiness plan for connectable devices

Occasional 

Fix ·  Add a section describing SBOM format, 24-hour actively exploited vulnerability reporting, and 72-hour incident reporting to ENISA.

### Typical timeline

End-to-end window: 12-18 months end-to-end for Class IIa/IIb with a competent NB. 

Phase 01

TD authoring

3-6 months

Phase 02

NB queue for review

2-6 months

Highly variable by NB and device class.

Phase 03

TD review + audit cycle

4-9 months

Phase 04

EUDAMED registration + market launch

4-8 weeks

[Previous ![Flag of United States](/flags/us.svg)United States ](/standards/fda)[Next  ![Flag of United Kingdom](/flags/gb.svg)United Kingdom ](/standards/uk)

## EU MDR head-to-head

[

Compare

![Flag of European Union](/flags/eu.svg)EU MDRvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-eu-mdr)[

Compare

![Flag of European Union](/flags/eu.svg)EU MDRvs ![Flag of United Kingdom](/flags/gb.svg)MHRA

Open comparison ](/compare/eu-mdr-vs-uk-mhra)[

Compare

![Flag of European Union](/flags/eu.svg)EU MDRvs ![Flag of Japan](/flags/jp.svg)PMDA

Open comparison ](/compare/eu-mdr-vs-pmda)[

Compare

![Flag of European Union](/flags/eu.svg)EU MDRvs ![Flag of Canada](/flags/ca.svg)Health Canada

Open comparison ](/compare/eu-mdr-vs-health-canada)

## Related markets

[![Flag of Brazil](/flags/br.svg)

Brazil

~60% FDA reuse

](/standards/br)[![Flag of Norway](/flags/no.svg)

Norway

~60% FDA reuse

](/standards/no)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)

## Frequently asked about European Union

### Is SBOM required for medical devices in European Union?

Recommended. Not yet mandated by MDR but expected by many Notified Bodies. Note: medical devices are excluded from the Cyber Resilience Act under Art. 2 - CRA SBOM rules do not apply.

### What does EC / MDCG require for pre-market cybersecurity?

Risk management per ISO 14971, IT security in technical documentation, IEC 81001-5-1, minimum IT requirements in IFU, verification & validation evidence reviewed by Notified Body.

### What are the post-market cybersecurity obligations under EC / MDCG?

PMS plan, PSUR, vigilance reporting within 15 days for serious incidents (2 days for serious public health threats).

### What is the penalty for non-compliance with EC / MDCG cybersecurity rules?

MDR: market removal + national fines. NIS2: up to €10M or 2% global turnover (where the manufacturer is in scope as an essential/important entity).

### How much of my FDA cybersecurity package is reusable in European Union?

Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to EC / MDCG? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for European Union alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your EU MDR submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.