Skip to main content
    MedTech Cyber Tips
    The Ultimate Guide
    Updates
    EU MDR

    MDCG 2019-16 Rev.2 expectations carry into Notified Body audits

    European Notified Bodies are now expecting evidence of IEC 81001-5-1 alignment, not just MDCG 2019-16 narrative.

    Notified Bodies under EU MDR are increasingly aligning their audits with IEC 81001-5-1 and IEC 62304 cybersecurity processes, layered on top of MDCG 2019-16 guidance. If you have an FDA-aligned SPDF, the gap to a clean CE technical file is smaller than it looks — but you'll need explicit traceability between security risk control measures and design outputs, plus evidence of post-market vulnerability handling tied to your PMS plan.