See how we map to the Health Canada guidance.

Health Canada expects a cybersecurity strategy for every device class, and specific evidence inside a Class III or IV licence application. Here is each expectation, the section it comes from, and what covers it.

Standards & Regulations

A mapping you can check, clause by clause.

Both halves of the guidance, not just the submission

Health Canada asks for two different things: a cybersecurity strategy every device from Class I to Class IV should have, and specific content inside a Class III or Class IV licence application. All 26 expectations are mapped below, each with the section it comes from.

Four kinds of work, across all twenty-six

Some expectations are answered by process and documentation, some by SBOM and vulnerability management, some by cryptography and update integrity, and some by expert review that genuinely takes a person rather than a tool. The mapping tags each one with what it needs.

Built on the standards the guidance cites

Health Canada points manufacturers at AAMI TIR57, ISO 14971, and IEC 62304 rather than writing its own control set. Those are the standards our model already folds together, alongside a bench that includes former FDA reviewers and HSCC JSPv2 co-authors.

Health Canada pre-market cybersecurity guidance

Twenty-six expectations, and what answers each.

Grouped as the guidance groups them and ordered as it orders them, so you can read this alongside your own copy. Sections 2.1 and 2.2 apply to every device class; Section 2.3 applies to Class III and Class IV licence and amendment applications.

Guidance Document: Pre-market Requirements for Medical Device Cybersecurity. Adopted 17 June 2019, effective 26 June 2019 (PDF)

16

Secure development & documentation

Process, design controls, and the records a submission needs

7

SBOM & vulnerability management

Component inventory and triage across the device lifetime

4

Cryptography & update integrity

Keys, signing, encryption, and secure updates

6

Expert review

Threat modelling and architecture review by people

All 26 categories are mapped. Some are answered by more than one kind of work, so these figures sum to more than 26.

Find your clause

Every category, its section reference, and what answers it. Select one to read the guidance’s own words and our response beside it.

Showing 26 of 26 categories

Section 2

A strategy for the device's cybersecurity risk

Development & docs

Health Canada guidance: Additionally, a manufacturer must have a strategy to address the cybersecurity risk of a medical device (Class I to Class IV) that runs software code.

Medcrypt solution: Medcrypt supplies the strategy as an implemented process rather than a policy document: secure design, risk management, verification and validation, and the monitoring plan, each with the records behind it.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness