What EU MDR requires
There's no standalone cybersecurity regulation for devices in the EU. Instead, three clauses in MDR Annex I make it mandatory. IVDR has matching clauses.
17.2:
Software has to be developed using the state of the art, including information security.
17.4:
Manufacturers have to state the minimum IT security measures needed to run the device as intended.
18.8:
Devices have to be protected against unauthorized access that could stop them working as intended.
Notified bodies judge your evidence against MDCG 2019-16 Rev.1, the EU's cybersecurity guidance for devices.
Where FDA-first teams get caught
The cybersecurity work you prepared for FDA can support your EU submission, but it does not show by itself that you meet EU requirements. The differences affect who reviews your evidence, what you tell customers and how you manage security after launch. We help you adapt the work you have rather than start again.
Hover over a heading, or select it to read more.
Proof
"Medcrypt's structured approach to document review was very helpful. We liked their guidance and enjoyed working with their team."
FAQ
Not as a separate law. Cybersecurity sits inside MDR Annex I (17.2, 17.4 and 18.8), with MDCG 2019-16 as guidance.
Largely, yes. Threat models, risk assessments and test reports carry over. The IFU security section, post-market surveillance links and notified body formatting usually need work.
No. Devices covered by MDR and IVDR are excluded from the Cyber Resilience Act.
IEC 81001-5-1 is the most common reference for the secure development lifecycle. Your notified body may ask for others.
