Book an Appointment

Cybersecurity for Medical Devices

Which cybersecurity requirements the MDR imposes on manufacturers – and how MDCG 2019-16, IEC 81001-5-1 and the AI Act set the framework for the entire product life cycle.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

5Cybersecurity-relevant sections in MDR Annex I (17.1–23.4)
36Practical questions on the MDR/AI Act interplay answered by MDCG 2025-6
15Days at the latest to report a serious incident after awareness
2028High-risk obligations for embedded AI apply from 2 August (Digital Omnibus)

Connected medical devices are both an attack surface and a patient safety risk: an exploited vulnerability can directly impair a device’s clinical function. Regulation (EU) 2017/745 (MDR) therefore anchors information security as a general safety and performance requirement in Annex I – further specified by the MDCG 2019-16 guidance and the life cycle standard IEC 81001-5-1. The horizontal Cyber Resilience Act explicitly does not apply to MDR products; the cybersecurity obligations derive entirely from medical device law. For AI-based medical devices, the AI Act has been in place since 2024 as a second regulatory framework.

MDR cybersecurity milestones

From the guidance to the AI deadline – tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Four regulatory layers, one life cycle

From the regulation via guidance and standard to the AI Act – pick a layer.

Regulation (EU) 2017/745
  • Section 17.1 requires repeatability, reliability and performance; Section 17.2 requires software to be developed in accordance with the state of the art – including information security, verification and validation.
  • Under Section 17.4, minimum requirements concerning hardware, IT network characteristics and IT security measures must be set out; Sections 18.8 and 23.4(ab) add access protection and the instructions for use.
  • The Cyber Resilience Act (Regulation (EU) 2024/2847) explicitly excludes medical devices in Art. 2 – the cybersecurity obligations derive entirely from medical device law.
Section 17.1Section 17.2Section 17.4Section 18.8Section 23.4(ab)State of the artCRA exclusion Art. 2

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2017

Verordnung (EU) 2017/745 über Medizinprodukte (MDR)

Annex I Sections 17.1, 17.2, 17.4, 18.8 and 23.4 as cybersecurity-relevant general requirements; Art. 83–88 on post-market surveillance and vigilance.

Medical Device Coordination Group / Europäische Kommission · 2020

MDCG 2019-16 Rev. 1 – Guidance on Cybersecurity for medical devices

Central guidance on implementing the Annex I requirements: secure by design, security capabilities, joint responsibility, PMS/vigilance including IMDRF codes.

IEC · 2021

IEC 81001-5-1:2021 – Health software and health IT systems safety, effectiveness and security – Part 5-1: Security – Activities in the product life cycle

Process standard for the secure life cycle of health software (extension of IEC 62304, modelled on IEC 62443-4-1); EN version 2022, not yet harmonised in the Official Journal of the EU.

Medical Device Coordination Group / Europäische Kommission · 2025

MDCG 2025-6 – FAQ on Interplay between the Medical Devices Regulation & In vitro Diagnostic Medical Devices Regulation and the Artificial Intelligence Act

36 questions and answers on the interplay between the MDR/IVDR and the AI Act, including high-risk classification, roles and combined conformity assessment.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/1689 (KI-Verordnung)

Art. 6(1) classifies AI-based medical devices requiring notified body involvement as high-risk AI; the application date for embedded high-risk AI was postponed to 2 August 2028 by the 2026 Digital Omnibus.

Team-NB (The European Association of Medical Devices Notified Bodies) · 2022

Team-NB Position Paper „Cyber Security“ V1

Joint position of the notified bodies on the conformity assessment of cybersecurity under the MDR/IVDR; complemented by a Team-NB letter of February 2026 on the harmonisation of standards.

Looking to demonstrate MDR cybersecurity in a structured way?

From a gap analysis against MDCG 2019-16 and IEC 81001-5-1 to audit-proof vulnerability handling: talk to us about a no-obligation initial consultation.