---
title: "Updates - FDA &amp; EU Medical Device Cybersecurity News"
description: "Dated updates on FDA cybersecurity guidance, EU MDR, QMSR, SBOM/VEX practice, and vulnerabilities affecting medical devices."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "WebSite",
          "@id": "https://medtechcybertips.com/#website",
          "url": "https://medtechcybertips.com/",
          "name": "MedTech Cyber Tips",
          "description": "The ultimate organized guide to medical device cybersecurity.",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://medtechcybertips.com/#org"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": "https://medtechcybertips.com/topics?q={search_term_string}",
            "query-input": "required name=search_term_string"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://medtechcybertips.com/#org",
          "name": "MedTech Cyber Tips",
          "url": "https://medtechcybertips.com/",
          "logo": "https://medtechcybertips.com/icon-512.png",
          "sponsor": {
            "@type": "Organization",
            "name": "Blue Goat Cyber",
            "url": "https://bluegoatcyber.com",
            "sameAs": [
              "https://home.bluegoatcyber.com/",
              "https://codebluechart.com/",
              "https://why.bluegoatcyber.com/",
              "https://spdf.bluegoatcyber.com/",
              "https://threatmodel.bluegoatcyber.com/",
              "https://pentesting.bluegoatcyber.com/",
              "https://premarket.bluegoatcyber.com/",
              "https://fdaresponse.bluegoatcyber.com/",
              "https://postmarket.bluegoatcyber.com/",
              "https://goatwatch.bluegoatcyber.com/"
            ]
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Blog",
      "name": "Medical Device Cybersecurity Updates",
      "url": "https://medtechcybertips.com/updates",
      "blogPost": [
        {
          "@type": "BlogPosting",
          "headline": "CISA + FDA joint advisories in 2026: infusion pumps, imaging, and what to do next",
          "datePublished": "2026-08-05",
          "url": "https://medtechcybertips.com/updates/cisa-fda-joint-advisories-mid-2026",
          "description": "Several CISA/FDA joint medical device advisories landed in the first half of 2026, clustered around infusion pumps and imaging modalities. Here's the pattern manufacturers should read from them."
        },
        {
          "@type": "BlogPosting",
          "headline": "PCCP + 524B check-in: pairing your change-control plan with the Feb 2026 guidance",
          "datePublished": "2026-07-22",
          "url": "https://medtechcybertips.com/updates/pccp-524b-july-2026-checkin",
          "description": "A quick July 2026 reminder that Predetermined Change Control Plans and Section 524B cybersecurity obligations are not separate workstreams - each PCCP-covered modification needs a matching cyber impact analysis in your SPDF."
        },
        {
          "@type": "BlogPosting",
          "headline": "Mid-2026 field notes: what's tripping up 524B submissions right now",
          "datePublished": "2026-07-08",
          "url": "https://medtechcybertips.com/updates/mid-2026-deficiency-patterns",
          "description": "Five months into the Feb 3, 2026 guidance, a clear pattern of deficiencies has emerged around SBOM depth, VEX handling, and AI/ML threat modeling. Here's what reviewers are flagging most this quarter."
        },
        {
          "@type": "BlogPosting",
          "headline": "HHS 405(d) HICP 2026 refresh: what changes for MedTech manufacturers",
          "datePublished": "2026-06-28",
          "url": "https://medtechcybertips.com/updates/hhs-405d-hicp-2026-refresh",
          "description": "The Health Industry Cybersecurity Practices (HICP) 2026 refresh from HHS 405(d) tightens the manufacturer-facing sections, especially around SBOM disclosure to HDOs and coordinated vulnerability handling."
        },
        {
          "@type": "BlogPosting",
          "headline": "PCCPs and cybersecurity: what changes when your AI model updates itself",
          "datePublished": "2026-06-10",
          "url": "https://medtechcybertips.com/updates/pccp-cyber-intersection-2026",
          "description": "FDA's Predetermined Change Control Plans let AI/ML devices ship updates without a new submission - but the cyber risk surface moves with every retrain. Here's how to scope a PCCP that doesn't quietly invalidate your 524B package."
        },
        {
          "@type": "BlogPosting",
          "headline": "MDCG 2019-16 Rev.2 lands - Notified Body audits are catching up",
          "datePublished": "2026-04-18",
          "url": "https://medtechcybertips.com/updates/mdcg-2019-16-rev2",
          "description": "The latest revision to MDCG 2019-16 tightens expectations around SBOMs, post-market vulnerability handling, and traceability between security risk controls and design outputs. Here's the FDA-to-CE gap, condensed."
        },
        {
          "@type": "BlogPosting",
          "headline": "FDA issues updated premarket cybersecurity guidance (Feb 3, 2026)",
          "datePublished": "2026-02-03",
          "url": "https://medtechcybertips.com/updates/fda-premarket-cyber-guidance-feb-2026",
          "description": "The FDA's Feb 3, 2026 revision to 'Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions' is now the current final guidance. Here's what changed versus the 2023 edition and what to update in your submission templates."
        },
        {
          "@type": "BlogPosting",
          "headline": "QMSR replaces 21 CFR 820 - what changes for cybersecurity",
          "datePublished": "2026-02-02",
          "url": "https://medtechcybertips.com/updates/qmsr-takes-effect",
          "description": "FDA's Quality Management System Regulation harmonizes Part 820 with ISO 13485. Cyber design controls and CAPA expectations carry over with subtle scoping changes."
        },
        {
          "@type": "BlogPosting",
          "headline": "Two years of Section 524B: what FDA reviewers are pushing back on",
          "datePublished": "2025-10-15",
          "url": "https://medtechcybertips.com/updates/524b-two-year-checkin",
          "description": "Patterns from recent deficiency letters: weak SBOM hygiene, missing VEX statements, and CVD policies that exist on paper but have no real intake."
        },
        {
          "@type": "BlogPosting",
          "headline": "MDCG 2019-16 Rev.2 expectations carry into Notified Body audits",
          "datePublished": "2025-08-20",
          "url": "https://medtechcybertips.com/updates/eu-mdr-cyber-annex-update",
          "description": "European Notified Bodies are now expecting evidence of IEC 81001-5-1 alignment, not just MDCG 2019-16 narrative."
        },
        {
          "@type": "BlogPosting",
          "headline": "MedTechCyberTips.com is live",
          "datePublished": "2025-06-01",
          "url": "https://medtechcybertips.com/updates/site-launch",
          "description": "Nine deeply organized topics, a guided journey, and a glossary covering every acronym in FDA cyber guidance."
        }
      ]
    }
  ]
---

[Skip to main content](#main)

[

MedTech Cyber Tips

The Ultimate Guide



](/)

[Home](/)[Find Your Path](/journey)[All Topics](/topics)Reference[About](/about)

Search ⌘K

Updates

# What's new in MedTech cyber

Short, dated updates on FDA enforcement, EU MDR/MDCG guidance, standards revisions, and notable vulnerabilities.

[Subscribe via RSS](/rss.xml)

All11 FDA6 EU MDR2 Vulnerability1 Standards1 Site1 

1.  [
    
    Vulnerability Updated Aug 5, 2026· 13d ago 
    
    ## CISA + FDA joint advisories in 2026: infusion pumps, imaging, and what to do next
    
    Several CISA/FDA joint medical device advisories landed in the first half of 2026, clustered around infusion pumps and imaging modalities. Here's the pattern manufacturers should read from them.
    
    Read update
    
    ](/updates/cisa-fda-joint-advisories-mid-2026)
2.  [
    
    FDA Updated Jul 22, 2026· 27d ago 
    
    ## PCCP + 524B check-in: pairing your change-control plan with the Feb 2026 guidance
    
    A quick July 2026 reminder that Predetermined Change Control Plans and Section 524B cybersecurity obligations are not separate workstreams - each PCCP-covered modification needs a matching cyber impact analysis in your SPDF.
    
    Read update
    
    ](/updates/pccp-524b-july-2026-checkin)
3.  [
    
    FDA Updated Jul 8, 2026· 1mo ago 
    
    ## Mid-2026 field notes: what's tripping up 524B submissions right now
    
    Five months into the Feb 3, 2026 guidance, a clear pattern of deficiencies has emerged around SBOM depth, VEX handling, and AI/ML threat modeling. Here's what reviewers are flagging most this quarter.
    
    Read update
    
    ](/updates/mid-2026-deficiency-patterns)
4.  [
    
    Standards Updated Jun 28, 2026· 2mo ago 
    
    ## HHS 405(d) HICP 2026 refresh: what changes for MedTech manufacturers
    
    The Health Industry Cybersecurity Practices (HICP) 2026 refresh from HHS 405(d) tightens the manufacturer-facing sections, especially around SBOM disclosure to HDOs and coordinated vulnerability handling.
    
    Read update
    
    ](/updates/hhs-405d-hicp-2026-refresh)
5.  [
    
    FDA Updated Jun 10, 2026· 2mo ago 
    
    ## PCCPs and cybersecurity: what changes when your AI model updates itself
    
    FDA's Predetermined Change Control Plans let AI/ML devices ship updates without a new submission - but the cyber risk surface moves with every retrain. Here's how to scope a PCCP that doesn't quietly invalidate your 524B package.
    
    Read update
    
    ](/updates/pccp-cyber-intersection-2026)
6.  [
    
    EU MDR Updated Apr 18, 2026· 4mo ago 
    
    ## MDCG 2019-16 Rev.2 lands - Notified Body audits are catching up
    
    The latest revision to MDCG 2019-16 tightens expectations around SBOMs, post-market vulnerability handling, and traceability between security risk controls and design outputs. Here's the FDA-to-CE gap, condensed.
    
    Read update
    
    ](/updates/mdcg-2019-16-rev2)
7.  [
    
    FDA Updated Feb 3, 2026· 7mo ago 
    
    ## FDA issues updated premarket cybersecurity guidance (Feb 3, 2026)
    
    The FDA's Feb 3, 2026 revision to 'Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions' is now the current final guidance. Here's what changed versus the 2023 edition and what to update in your submission templates.
    
    Read update
    
    ](/updates/fda-premarket-cyber-guidance-feb-2026)
8.  [
    
    FDA Updated Feb 2, 2026· 7mo ago 
    
    ## QMSR replaces 21 CFR 820 - what changes for cybersecurity
    
    FDA's Quality Management System Regulation harmonizes Part 820 with ISO 13485. Cyber design controls and CAPA expectations carry over with subtle scoping changes.
    
    Read update
    
    ](/updates/qmsr-takes-effect)
9.  [
    
    FDA Updated Oct 15, 2025· 10mo ago 
    
    ## Two years of Section 524B: what FDA reviewers are pushing back on
    
    Patterns from recent deficiency letters: weak SBOM hygiene, missing VEX statements, and CVD policies that exist on paper but have no real intake.
    
    Read update
    
    ](/updates/524b-two-year-checkin)
10.  [
     
     EU MDR Updated Aug 20, 2025· 1y ago 
     
     ## MDCG 2019-16 Rev.2 expectations carry into Notified Body audits
     
     European Notified Bodies are now expecting evidence of IEC 81001-5-1 alignment, not just MDCG 2019-16 narrative.
     
     Read update
     
     ](/updates/eu-mdr-cyber-annex-update)
11.  [
     
     Site Updated Jun 1, 2025· 1y ago 
     
     ## MedTechCyberTips.com is live
     
     Nine deeply organized topics, a guided journey, and a glossary covering every acronym in FDA cyber guidance.
     
     Read update
     
     ](/updates/site-launch)

MedTech Cyber Tips

The organized, end-to-end guide to medical device cybersecurity, from concept through postmarket. Part of the Blue Goat Cyber family.

Topics

-   [Overview](/topics/home)
-   [Why It Matters](/topics/why)
-   [SPDF](/topics/spdf)
-   [Threat Modeling](/topics/threatmodel)
-   [Pentesting](/topics/pentesting)

Reference

-   [Glossary](/glossary)
-   [FDA vs MDR](/compare)
-   [Resources](/resources)
-   [Updates](/updates)
-   [RSS feed](/rss.xml)

© 2026 medtechcybertips.com. An educational resource sponsored by Blue Goat Cyber.

Not legal or regulatory advice.