The MDR does not use the term “cybersecurity” literally, but Annex I sets out clear requirements: Section 17.1 requires, for devices incorporating programmable electronic systems, repeatability, reliability and performance in line with their intended purpose; Section 17.2 requires software to be developed in accordance with the state of the art, taking into account the life cycle, risk management – including information security – as well as verification and validation. Under Section 17.4, manufacturers must set out minimum requirements concerning hardware, IT network characteristics and IT security measures, including protection against unauthorised access; Section 18.8 and Section 23.4(ab) add protection against unauthorised access and the obligation to communicate these minimum requirements in the instructions for use. The Cyber Resilience Act (Regulation (EU) 2024/2847) explicitly excludes medical devices from its scope in Art. 2, because the MDR already imposes IT security requirements covering the entire life cycle.
Cybersecurity for Medical Devices
Which cybersecurity requirements the MDR imposes on manufacturers – and how MDCG 2019-16, IEC 81001-5-1 and the AI Act set the framework for the entire product life cycle.
Connected medical devices are both an attack surface and a patient safety risk: an exploited vulnerability can directly impair a device’s clinical function. Regulation (EU) 2017/745 (MDR) therefore anchors information security as a general safety and performance requirement in Annex I – further specified by the MDCG 2019-16 guidance and the life cycle standard IEC 81001-5-1. The horizontal Cyber Resilience Act explicitly does not apply to MDR products; the cybersecurity obligations derive entirely from medical device law. For AI-based medical devices, the AI Act has been in place since 2024 as a second regulatory framework.
MDR cybersecurity milestones
From the guidance to the AI deadline – tap a milestone for details.
MDCG 2019-16 Rev. 1
The Medical Device Coordination Group publishes the revised cybersecurity guidance: secure by design, security capabilities and joint responsibility across the entire life cycle.
AI Act in force
Regulation (EU) 2024/1689 enters into force. Under Art. 6(1), AI-based medical devices requiring a notified body qualify as high-risk AI – under the MDR, regularly from class IIa upwards.
MDR revision proposal
The Commission presents COM(2025) 1023: additional CRA-style reporting of actively exploited vulnerabilities to CSIRTs and ENISA – not yet adopted.
Standards lists without IEC 81001-5-1
Commission Implementing Decision (EU) 2026/1231 updates the lists of standards under the MDR and IVDR; EN IEC 81001-5-1:2022 remains uncited in the Official Journal of the EU – no presumption of conformity.
High-risk obligations for embedded AI
From this date, the high-risk obligations apply to AI systems embedded in regulated products – postponed from 2 August 2027 by the Digital Omnibus; effective upon publication in the Official Journal of the EU.
The Essentials at a Glance
Six topic blocks — tap to expand.
Four regulatory layers, one life cycle
From the regulation via guidance and standard to the AI Act – pick a layer.
- Section 17.1 requires repeatability, reliability and performance; Section 17.2 requires software to be developed in accordance with the state of the art – including information security, verification and validation.
- Under Section 17.4, minimum requirements concerning hardware, IT network characteristics and IT security measures must be set out; Sections 18.8 and 23.4(ab) add access protection and the instructions for use.
- The Cyber Resilience Act (Regulation (EU) 2024/2847) explicitly excludes medical devices in Art. 2 – the cybersecurity obligations derive entirely from medical device law.
- Secure by design, a dedicated security risk management process interlinked with safety risk management, and a catalogue of security capabilities – from authentication to audit logging.
- The principle of joint responsibility also obliges integrators, operators and users alongside the manufacturer.
- A mapping table cross-references MDR and IVDR Annex I; case examples distinguish cybersecurity incidents from reportable serious incidents.
- Defines security risk management with threat modelling, security testing, configuration management, and processes for vulnerability monitoring and problem resolution.
- Extends the life cycle structure of IEC 62304 with security activities and is modelled on IEC 62443-4-1.
- Even after the June 2026 update of the standards lists, the EN version is not cited in the Official Journal – no presumption of conformity; notified bodies nevertheless treat the standard as the state of the art.
- Under Art. 6(1), an AI system qualifies as high-risk AI if its conformity assessment requires a notified body – under the MDR, regularly from class IIa upwards.
- The FAQ MDCG 2025-6 (June 2025) answers 36 practical questions, for example on role mapping and combining the conformity assessments.
- The Digital Omnibus (May 2026) postpones the high-risk obligations for embedded AI systems from 2 August 2027 to 2 August 2028 – effective upon publication in the Official Journal of the EU.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Verordnung (EU) 2017/745 über Medizinprodukte (MDR)
Annex I Sections 17.1, 17.2, 17.4, 18.8 and 23.4 as cybersecurity-relevant general requirements; Art. 83–88 on post-market surveillance and vigilance.
MDCG 2019-16 Rev. 1 – Guidance on Cybersecurity for medical devices
Central guidance on implementing the Annex I requirements: secure by design, security capabilities, joint responsibility, PMS/vigilance including IMDRF codes.
IEC 81001-5-1:2021 – Health software and health IT systems safety, effectiveness and security – Part 5-1: Security – Activities in the product life cycle
Process standard for the secure life cycle of health software (extension of IEC 62304, modelled on IEC 62443-4-1); EN version 2022, not yet harmonised in the Official Journal of the EU.
MDCG 2025-6 – FAQ on Interplay between the Medical Devices Regulation & In vitro Diagnostic Medical Devices Regulation and the Artificial Intelligence Act
36 questions and answers on the interplay between the MDR/IVDR and the AI Act, including high-risk classification, roles and combined conformity assessment.
Verordnung (EU) 2024/1689 (KI-Verordnung)
Art. 6(1) classifies AI-based medical devices requiring notified body involvement as high-risk AI; the application date for embedded high-risk AI was postponed to 2 August 2028 by the 2026 Digital Omnibus.
Team-NB Position Paper „Cyber Security“ V1
Joint position of the notified bodies on the conformity assessment of cybersecurity under the MDR/IVDR; complemented by a Team-NB letter of February 2026 on the harmonisation of standards.
Related Services
Looking to demonstrate MDR cybersecurity in a structured way?
From a gap analysis against MDCG 2019-16 and IEC 81001-5-1 to audit-proof vulnerability handling: talk to us about a no-obligation initial consultation.