See how we map to the EU MDR cybersecurity guidance.

The MDR states its cybersecurity requirements in Annex I and leaves the method to MDCG 2019-16. Here is each obligation, the chapter it comes from, and what covers it.

Standards & Regulations

A mapping you can check, clause by clause.

The guidance the Regulation leaves out

The MDR states its cybersecurity requirements in a handful of Annex I clauses and says nothing about how to meet them. MDCG 2019-16 is where the method lives. All 29 of its obligations are mapped below, each with the chapter it comes from and the Annex I or Article reference behind it.

Four kinds of work, across all twenty-nine

Some obligations are answered by process and documentation, some by SBOM and vulnerability management, some by cryptography and update integrity, and some by expert review that genuinely takes a person rather than a tool. The mapping tags each one with what it needs.

State of the art, which the guidance never defines

MDCG 2019-16 requires the state of the art and then points at standards and Official Journal listings rather than enumerating controls. Our model folds twelve global standards together to answer that, alongside a bench that includes a former FDA reviewer and three HSCC JSPv2 co-authors.

MDCG 2019-16 cybersecurity guidance

Twenty-nine obligations, and what answers each.

Grouped as the guidance groups them and ordered as it orders them, so you can read this alongside your own copy. Chapter references point to MDCG 2019-16; the Annex I and Article references beside them point into Regulation (EU) 2017/745 itself. The same obligations apply under the IVDR at the section numbers the guidance gives in its Table 1.

MDCG 2019-16 Rev. 1, Guidance on Cybersecurity for medical devices. Endorsed by the Medical Device Coordination Group, December 2019, revised July 2020 (PDF)

17

Secure development & documentation

Process, design controls, and the records a submission needs

8

SBOM & vulnerability management

Component inventory and triage across the device lifetime

6

Cryptography & update integrity

Keys, signing, encryption, and secure updates

6

Expert review

Threat modelling and architecture review by people

All 29 categories are mapped. Some are answered by more than one kind of work, so these figures sum to more than 29.

Find your clause

Every category, its section reference, and what answers it. Select one to read the guidance’s own words and our response beside it.

Showing 29 of 29 categories

Chapter 1.3, MDR Annex I

Cybersecurity requirements in Annex I

Development & docs

MDCG 2019-16 guidance: Cybersecurity requirements listed in Annex I of the Medical Devices Regulations, deal with both pre-market and post-market aspects. These requirements, and their interconnection, are illustrated in Figure 1 and are elaborated in Chapter 2 with the aim to provide a basis for the development of recommendations and guidance for medical device manufacturers (Chapters 3-6 of this document).

Medcrypt solution: Medcrypt works the pre-market and post-market halves as one record, so the Annex I conformity argument and the post-market evidence that has to keep supporting it do not drift apart after CE marking.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness