---
title: "FDA 524B vs EU MDR vs EU CRA - 2026 Cybersecurity Crosswalk"
description: "2026 crosswalk of FDA Section 524B, EU MDR (MDCG 2019-16 Rev.2), and the EU Cyber Resilience Act (CRA) cybersecurity requirements for medical devices, plus…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "WebSite",
          "@id": "https://medtechcybertips.com/#website",
          "url": "https://medtechcybertips.com/",
          "name": "MedTech Cyber Tips",
          "description": "The ultimate organized guide to medical device cybersecurity.",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://medtechcybertips.com/#org"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": "https://medtechcybertips.com/topics?q={search_term_string}",
            "query-input": "required name=search_term_string"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://medtechcybertips.com/#org",
          "name": "MedTech Cyber Tips",
          "url": "https://medtechcybertips.com/",
          "logo": "https://medtechcybertips.com/icon-512.png",
          "sponsor": {
            "@type": "Organization",
            "name": "Blue Goat Cyber",
            "url": "https://bluegoatcyber.com",
            "sameAs": [
              "https://home.bluegoatcyber.com/",
              "https://codebluechart.com/",
              "https://why.bluegoatcyber.com/",
              "https://spdf.bluegoatcyber.com/",
              "https://threatmodel.bluegoatcyber.com/",
              "https://pentesting.bluegoatcyber.com/",
              "https://premarket.bluegoatcyber.com/",
              "https://fdaresponse.bluegoatcyber.com/",
              "https://postmarket.bluegoatcyber.com/",
              "https://goatwatch.bluegoatcyber.com/"
            ]
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "FDA Section 524B vs EU MDR vs EU Cyber Resilience Act (CRA) - 2026 cybersecurity crosswalk",
      "description": "2026 side-by-side comparison of FDA Section 524B, EU MDR, and EU Cyber Resilience Act (CRA) cybersecurity obligations for medical devices, plus SPDX vs CycloneDX SBOM formats.",
      "url": "https://medtechcybertips.com/compare",
      "datePublished": "2026-02-03",
      "dateModified": "2026-07-10",
      "author": {
        "@type": "Organization",
        "name": "MedTech Cyber Tips"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How do FDA cybersecurity rules compare to EU MDR?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "FDA (Section 524B + 2026 guidance) is prescriptive about premarket artifacts: threat model, SBOM, penetration test, CVD policy, labeling. EU MDR (via MDCG 2019-16 Rev.2) frames cybersecurity as an essential requirement under Annex I with more principles-based expectations and heavier reliance on state-of-the-art standards like IEC 81001-5-1."
          }
        },
        {
          "@type": "Question",
          "name": "Does the EU Cyber Resilience Act (CRA) apply to medical devices?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The CRA carves out devices that are already regulated under MDR/IVDR at equivalent or higher rigor, but the carve-out is narrower than many manufacturers assume. Accessories, standalone software, and non-medical connected components in a MedTech portfolio may fall directly under the CRA. Use a scoping walkthrough to check per product."
          }
        },
        {
          "@type": "Question",
          "name": "Which framework should we align to first if we sell in both markets?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Align to IEC 81001-5-1 as your process baseline. It maps cleanly to both FDA SPDF expectations and MDR Annex I cybersecurity essential requirements, and it is the standard the CRA is expected to lean on. Then layer the FDA-specific artifacts (SBOM format, CVD policy) on top."
          }
        },
        {
          "@type": "Question",
          "name": "How do postmarket obligations compare?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "FDA expects continuous monitoring, coordinated disclosure, and remediation on a risk-based cadence with public advisories via CISA/ICS-MEDICAL. EU MDR requires postmarket surveillance and vigilance reporting; the CRA (once fully in force) adds a 24-hour early-warning and 72-hour incident-reporting duty for exploited vulnerabilities."
          }
        },
        {
          "@type": "Question",
          "name": "Do we need a separate CVD policy for the EU?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "One CVD policy is fine if it explicitly commits to both FDA-aligned coordination (CISA) and EU-aligned notification obligations. What matters is that reporters know how to reach you, and that internal timelines meet the tightest applicable statutory deadline."
          }
        }
      ]
    }
  ]
---

[Skip to main content](#main)

[

MedTech Cyber Tips

The Ultimate Guide



](/)

[Home](/)[Find Your Path](/journey)[All Topics](/topics)Reference[About](/about)

Search ⌘K

Reference · 2026 edition

# FDA 524B vs EU MDR vs EU CRA - 2026 crosswalk

Cross-jurisdiction and cross-format reference tables covering the Feb 3, 2026 FDA guidance, MDCG 2019-16 Rev.2, and the EU Cyber Resilience Act (Regulation (EU) 2024/2847). Useful for technical-file mapping and tool selection.

Last updated Jul 10, 2026· 1mo ago 

FDA Section 524B vs EU MDR cybersecurity

### What overlaps, what doesn't

FDA only

-   •  Statutory SBOM (524B)
-   •  PCCP
-   •  eSTAR submission
-   •  Refuse-to-Accept policy

Both

-   •  Threat model
-   •  CVD policy
-   •  Pentest evidence
-   •  Postmarket monitoring
-   •  Risk mgmt (ISO 14971)

EU MDR only

-   •  Notified Body review
-   •  IEC 81001-5-1 hard tie
-   •  Annex I §17.2
-   •  PMS plan integration

## FDA (Section 524B) vs EU MDR cybersecurity

Both regimes require evidence of secure development and postmarket vigilance, but the statutory authority, format, and review style differ. Use this as a mapping for a single global technical file.

Requirement

FDA (US)

EU MDR

Statutory cybersecurity authority

Section 524B FD&C Act (2023) + Feb 2026 guidance 

Annex I §17.2 + MDCG 2019-16 Rev.2 

SBOM required in submission

Required 

Expected, not statutory 

Coordinated Vulnerability Disclosure (CVD) policy

Yes 

Yes 

Threat model in technical file

Yes 

Yes 

Penetration testing evidence

Independent recommended 

Expected by NB 

Postmarket vulnerability monitoring plan

Yes 

Tied to PMS plan 

VEX pairing with SBOM

Strongly encouraged 

Partial 

Predetermined Change Control Plan (PCCP)

Yes 

No equivalent 

Reference standards

AAMI TIR57, AAMI SW96, IEC 81001-5-1 

IEC 81001-5-1, IEC 62304, ISO 14971 

Guided walkthrough

## Is my product in EU Cyber Resilience Act scope?

Four short questions route you to the right rows in the crosswalk and the deep-dive topics that matter for your profile. Educational - not legal advice.

1.  1 
    
    Which best describes the product?
    
    Pick the closest fit - you can restart at any time.
    
    Medical device regulated under EU MDR/IVDR
    
    CE-marked or in conformity assessment
    
    Accessory or companion app to a medical device
    
    Not itself a regulated device
    
    Standalone software / SaMD outside MDR scope
    
    e.g. wellness, general-purpose clinical tool
    
    Component, library, or connected sub-system
    
    Sold to device makers
    
2.  2 
    
    Is the product placed on the EU market?
    
    Yes - sold or distributed in the EU today
    
    Planned within 24 months
    
    No EU market plans
    
3.  3 
    
    Does the product have 'digital elements' with data connections?
    
    CRA scope hinges on remote data connections (network, Bluetooth, cloud, updates).
    
    Yes - network, cloud, or wireless connectivity
    
    Local software only, no remote connection
    
    Not sure
    
4.  4 
    
    Where are you today on SBOM + coordinated vulnerability disclosure?
    
    SBOM + CVD + PSIRT already in place
    
    Some pieces exist, not fully documented
    
    Not started
    

## EU Cyber Resilience Act (CRA) crosswalk: FDA 524B vs EU MDR vs EU CRA

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) adds a third regime for connected products. Devices already regulated as medical devices under the MDR/IVDR are generally excluded from the CRA where equivalent requirements are met - but accessories, standalone software, and companion apps can fall into scope. Vulnerability and incident reporting obligations begin **Sept 11 2026**; core obligations apply from **Dec 11 2027**.

Dimension

FDA (US)

EU MDR

EU CRA

Instrument

Section 524B FD&C Act 

Regulation (EU) 2017/745 (MDR) 

Regulation (EU) 2024/2847 (CRA) 

Core obligations effective

Mar 29 2023 

May 26 2021 

Dec 11 2027 

Scope of medical devices

Cyber devices 

All MDR-regulated devices 

MDR/IVDR-regulated devices largely carved out; accessories & standalone apps may apply 

SBOM expectation

SPDX or CycloneDX 

Partial 

Annex I §2(1) - machine-readable 

Vulnerability handling process

CVD + PSIRT 

Tied to PMS 

Annex I §2 - documented, coordinated 

Mandatory incident reporting

Uncontrolled-risk criteria 

Vigilance 

24h early warning to ENISA + CSIRT 

Actively-exploited vuln reporting

Partial 

Partial 

24h → 72h → 14d cadence 

Security updates during support period

Postmarket plan 

Yes 

Min 5-yr support default 

CE marking / conformity assessment

510(k)/PMA 

MDR CE 

CRA CE, may combine with MDR 

Enforcement penalty ceiling

FD&C Act enforcement 

Member-state fines 

€15M or 2.5% global turnover 

Sources: [EUR-Lex - Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj), [European Commission - CRA](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act), [MDCG guidance index](https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en). Not legal advice - confirm scope with a notified body or regulatory counsel.

## SBOM formats: SPDX vs CycloneDX

Both are accepted by FDA. The choice usually comes down to whether your priority is license compliance and standardization (SPDX) or security tooling and VEX/CBOM extensibility (CycloneDX).

Dimension

SPDX

CycloneDX

Steward

Linux Foundation 

OWASP 

ISO standardized

ISO/IEC 5962:2021 

No 

License focus

Strong 

Partial 

Vulnerability / VEX integration

Partial 

Native VEX & VDR 

Cryptographic BOM (CBOM)

No 

Yes 

Hardware / SaaS BOM

Partial 

Yes 

Common formats

tag-value, JSON, YAML, RDF 

JSON, XML, Protobuf 

FDA accepts in submission

Yes 

Yes 

Looking for the underlying terms? See the [glossary](/glossary) for SBOM, VEX, CBOM, MDCG, PCCP and more.

FAQ

## FDA, MDR, and CRA - common questions

## Frequently asked questions

Quick answers to the questions teams most often ask about this topic.

### How do FDA cybersecurity rules compare to EU MDR? 

FDA (Section 524B + 2026 guidance) is prescriptive about premarket artifacts: threat model, SBOM, penetration test, CVD policy, labeling. EU MDR (via MDCG 2019-16 Rev.2) frames cybersecurity as an essential requirement under Annex I with more principles-based expectations and heavier reliance on state-of-the-art standards like IEC 81001-5-1.

### Does the EU Cyber Resilience Act (CRA) apply to medical devices? 

The CRA carves out devices that are already regulated under MDR/IVDR at equivalent or higher rigor, but the carve-out is narrower than many manufacturers assume. Accessories, standalone software, and non-medical connected components in a MedTech portfolio may fall directly under the CRA. Use a scoping walkthrough to check per product.

### Which framework should we align to first if we sell in both markets? 

Align to IEC 81001-5-1 as your process baseline. It maps cleanly to both FDA SPDF expectations and MDR Annex I cybersecurity essential requirements, and it is the standard the CRA is expected to lean on. Then layer the FDA-specific artifacts (SBOM format, CVD policy) on top.

### How do postmarket obligations compare? 

FDA expects continuous monitoring, coordinated disclosure, and remediation on a risk-based cadence with public advisories via CISA/ICS-MEDICAL. EU MDR requires postmarket surveillance and vigilance reporting; the CRA (once fully in force) adds a 24-hour early-warning and 72-hour incident-reporting duty for exploited vulnerabilities.

### Do we need a separate CVD policy for the EU? 

One CVD policy is fine if it explicitly commits to both FDA-aligned coordination (CISA) and EU-aligned notification obligations. What matters is that reporters know how to reach you, and that internal timelines meet the tightest applicable statutory deadline.

MedTech Cyber Tips

The organized, end-to-end guide to medical device cybersecurity, from concept through postmarket. Part of the Blue Goat Cyber family.

Topics

-   [Overview](/topics/home)
-   [Why It Matters](/topics/why)
-   [SPDF](/topics/spdf)
-   [Threat Modeling](/topics/threatmodel)
-   [Pentesting](/topics/pentesting)

Reference

-   [Glossary](/glossary)
-   [FDA vs MDR](/compare)
-   [Resources](/resources)
-   [Updates](/updates)
-   [RSS feed](/rss.xml)

© 2026 medtechcybertips.com. An educational resource sponsored by Blue Goat Cyber.

Not legal or regulatory advice.