RA_QA_Expert
Involved In Discussions
Hello,
For manufacturers placing medical devices on the EU market, MDR (EU) 2017/745 Annex I (e.g. 17.2, 17.4, 18.8) requires "state-of-the-art" cybersecurity — but what does that actually mean in practice?
I’m looking to clarify which technical standards and guidance are considered essential or expected by Notified Bodies. Specifically:
Thanks in advance!
For manufacturers placing medical devices on the EU market, MDR (EU) 2017/745 Annex I (e.g. 17.2, 17.4, 18.8) requires "state-of-the-art" cybersecurity — but what does that actually mean in practice?
I’m looking to clarify which technical standards and guidance are considered essential or expected by Notified Bodies. Specifically:
- For cyber risk management: is ISO 14971 enough, or should we integrate AAMI TIR57, TIR97, or others?
- For secure design: what’s the role of IEC 81001-5-1, IEC 62443-4-1/4-2, NIST CSF, etc.?
- How relevant are MDCG 2019-16 and IMDRF N60 in current EU reviews?
- What cybersecurity documentation is typically expected during conformity assessment?
Thanks in advance!