Skip to main content
    MedTech Cyber Tips
    The Ultimate Guide
    Updates

    What's new in MedTech cyber

    Short, dated updates on FDA enforcement, EU MDR/MDCG guidance, standards revisions, and notable vulnerabilities.

    Subscribe via RSS
    1. StandardsUpdated · 21d ago

      IEC 81001-5-1 Amendment 1 reaches FDIS - what MedTech teams should track

      Amendment 1 to IEC 81001-5-1 (health software security lifecycle) is in Final Draft International Standard ballot. It sharpens SBOM, CVD, and postmarket vulnerability expectations - and it's the standard EU Notified Bodies are quietly aligning MDCG 2019-16 audits against.

      Read update
    2. StandardsUpdated · 1mo ago

      EU CRA delegated acts under Article 27 - the technical baseline is taking shape

      The European Commission's Article 27 delegated acts translating the Cyber Resilience Act's essential requirements into technical standards are moving through consultation. For medical device makers, three of the draft harmonized standards will do most of the audit work.

      Read update
    3. VulnerabilityUpdated · 2mo ago

      CISA + FDA joint advisories in 2026: infusion pumps, imaging, and what to do next

      Several CISA/FDA joint medical device advisories landed in the first half of 2026, clustered around infusion pumps and imaging modalities. Here's the pattern manufacturers should read from them.

      Read update
    4. FDAUpdated · 3mo ago

      PCCP + 524B check-in: pairing your change-control plan with the Feb 2026 guidance

      A quick July 2026 reminder that Predetermined Change Control Plans and Section 524B cybersecurity obligations are not separate workstreams - each PCCP-covered modification needs a matching cyber impact analysis in your SPDF.

      Read update
    5. FDAUpdated · 3mo ago

      Mid-2026 field notes: what's tripping up 524B submissions right now

      Five months into the Feb 3, 2026 guidance, a clear pattern of deficiencies has emerged around SBOM depth, VEX handling, and AI/ML threat modeling. Here's what reviewers are flagging most this quarter.

      Read update
    6. StandardsUpdated · 3mo ago

      HHS 405(d) HICP 2026 refresh: what changes for MedTech manufacturers

      The Health Industry Cybersecurity Practices (HICP) 2026 refresh from HHS 405(d) tightens the manufacturer-facing sections, especially around SBOM disclosure to HDOs and coordinated vulnerability handling.

      Read update
    7. FDAUpdated · 4mo ago

      PCCPs and cybersecurity: what changes when your AI model updates itself

      FDA's Predetermined Change Control Plans let AI/ML devices ship updates without a new submission - but the cyber risk surface moves with every retrain. Here's how to scope a PCCP that doesn't quietly invalidate your 524B package.

      Read update
    8. EU MDRUpdated · 6mo ago

      MDCG 2019-16 Rev.2 lands - Notified Body audits are catching up

      The latest revision to MDCG 2019-16 tightens expectations around SBOMs, post-market vulnerability handling, and traceability between security risk controls and design outputs. Here's the FDA-to-CE gap, condensed.

      Read update
    9. FDAUpdated · 8mo ago

      FDA issues updated premarket cybersecurity guidance (Feb 3, 2026)

      The FDA's Feb 3, 2026 revision to 'Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions' is now the current final guidance. Here's what changed versus the 2023 edition and what to update in your submission templates.

      Read update
    10. FDAUpdated · 8mo ago

      QMSR replaces 21 CFR 820 - what changes for cybersecurity

      FDA's Quality Management System Regulation harmonizes Part 820 with ISO 13485. Cyber design controls and CAPA expectations carry over with subtle scoping changes.

      Read update
    11. FDAUpdated · 1y ago

      Two years of Section 524B: what FDA reviewers are pushing back on

      Patterns from recent deficiency letters: weak SBOM hygiene, missing VEX statements, and CVD policies that exist on paper but have no real intake.

      Read update
    12. EU MDRUpdated · 1y ago

      MDCG 2019-16 Rev.2 expectations carry into Notified Body audits

      European Notified Bodies are now expecting evidence of IEC 81001-5-1 alignment, not just MDCG 2019-16 narrative.

      Read update
    13. SiteUpdated · 1y ago

      MedTechCyberTips.com is live

      Nine deeply organized topics, a guided journey, and a glossary covering every acronym in FDA cyber guidance.

      Read update