The EU Takes a Step Closer to Cybersecurity Requirements for Medical Devices
TL;DR: The EU is moving much closer to making cybersecurity an explicit requirement under MDR & IVDR. Learn what the proposed changes could mean for medical device software, reporting obligations and compliance readiness.
Until now cybersecurity has played a marginal role in the EU’s Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR). In fact, the term cybersecurity doesn't even appear in the regulations. Instead, it’s addressed indirectly under the broader concept of “IT security” in Annex I (§17.2 and §17.4).
As a result, manufacturers have relied mostly on MDCG guidance documents, such as MDCG 2019-16, which set out a common understanding of how cybersecurity risks should be managed.
That is now very likely to change.
In December 2025, the European Commission published a proposal to amend the MDR and IVDR – and for the first time, cybersecurity is given an explicit place in the regulatory text itself as the requirements for cybersecurity become increasingly stringent.
New Cybersecurity Requirements for Medical Devices
The proposal strengthens Annex I, Section 17.4 by requiring manufacturers to specify the minimum hardware requirements, IT network characteristics, IT security measures, and cybersecurity protections — including safeguards against unauthorized access — needed for software to operate as intended.
For the first time, manufacturers must take cybersecurity into account when setting general safety and performance requirements for the devices.
The proposal also adds new reporting obligations. Serious incidents that qualify as actively exploited vulnerabilities or severe incidents per the definitions contained in the EU Cyber Resilience Act (CRA) would need to be reported to national CSIRTs (Computer Security Incident Response Team) and to The European Union Agency for Cybersecurity (ENISA).
[Learn more about the CRA in our guide EU Cyber Resilience Act: Compliance Essentials for Selling Digital Products in Europe.]
This change is intended to close a cybersecurity vigilance gap between MDR/IVDR and CRA. Since medical devices are exempt from the CRA’s scope, currently cybersecurity incidents that don't threaten public health or patient safety can go unreported.
What the Proposal Means in Practice
In practice, MDR and IVDR reach well beyond the EU's borders. Any manufacturer that places medical devices in the EU market must comply with MDR/IVDR regardless of where the company is headquartered.
Most often that's done through an EU Authorized Representative, who takes on legal responsibility for the device's conformity within the EU and acts as the manufacturer's point of contact with EU authorities.
If the proposal passes as drafted, all manufacturers selling into the EU would need to:
- Apply secure-by-design practices throughout their medical device lifecycle
- Fold cybersecurity requirements into technical documentation and general safety and performance requirements (GSPR ) conformity assessments
- Design a reporting pathway to notify CSIRTs and ENISA of actively exploited vulnerabilities or severe incidents. (If the company is based outside of Europe, it will likely be coordinated through an EU Authorized Representative.)
- Align cybersecurity reporting more closely with the CRA (e.g., align definitions and severity thresholds)
What Medical Device Manufacturers Should Do Now
While this remains a European Commission proposal and still requires approval by the European Parliament and the Council before taking effect, the cybersecurity provisions are widely expected to be adopted with few, if any, substantive changes. They closely align with the Cyber Resilience Act and existing MDCG 2019-16 guidance, reinforcing an industry direction that has been taking shape for several years.
For medical device manufacturers, now is the time to review cybersecurity risk management processes and documentation to ensure they are well positioned for the evolving regulatory landscape.
If you have questions about these evolving regulations or need help addressing CRA requirements, reach out to our medtech cybersecurity experts.