Deep Clause Coverage · Source-Linked
Every clause. Every major medtech cybersecurity regime. Every source, one click away.
CyberCompass maps premarket, SBOM/vulnerability, and postmarket cybersecurity obligations across the eleven jurisdictions with the deepest medtech regulatory footprint worldwide. Each clause links directly to its primary official document — nothing here asks to be taken on faith.
11Jurisdictions
4Clause categories
0AI / telemetry calls
1:1Clause : source link
Decision-support only — provided "as is". Content is paraphrased for navigation purposes and may contain errors or omissions. Every clause below links to its primary official source — verify there before relying on it for a submission. This tool does not replace agency, Notified Body, or legal review.
01 Device Profile
Filters every clause to what applies to your deviceNO PROFILE SET — SHOWING ALL CLAUSES UNFILTERED
02 Country / Regime Modules
All 11 jurisdictions fully populated & source-linked
All 11 jurisdictions populated — full clause detail, source-linked
01 · Legal basis
- FD&C Act §524B ("Ensuring Cybersecurity of Devices"), added by the FY2023 Omnibus (Consolidated Appropriations Act, 2023) — effective for submissions on or after Mar 29, 2023. 21 U.S.C. §360n-2
- FDA Premarket Cybersecurity Guidance, final Sep 2023 — device-level threat modeling, SBOM, and lifecycle expectations. FDA guidance doc
- Applies to "cyber devices": contains software, has connectivity capability, and could be vulnerable to cybersecurity threats — standalone non-connected software is largely out of scope for §524B. FDA cyber hub
02 · Premarket requirements
- Plan to monitor, identify, and address postmarket vulnerabilities and exploits, including coordinated disclosure. FDA guidance §V
- Processes to provide reasonable assurance the device and related systems are cybersecure, with evidence of testing. FDA guidance §V
- Cybersecurity risk management documentation integrated with ISO 14971 safety risk analysis, not a parallel silo. ISO 14971
- Architecture views, threat model, and interoperability/third-party software risk assessment. FDA guidance §VI
- SaMD-specific: algorithm change control and, where used, a Predetermined Change Control Plan (PCCP) scoped to cyber-relevant modifications. FDA PCCP guidance
- Life-sustaining/high-risk devices: independent penetration testing and formal fuzz/abuse-case testing expected as part of premarket evidence. FDA guidance §VI.B
- Implantable devices: wireless telemetry link (if present) must be assessed for replay, jamming, and unauthorized reprogramming risk. FDA cyber hub
03 · SBOM / vulnerability handling
- SBOM required at a machine-readable level, aligned to NTIA/CISA minimum elements (supplier, component, version, dependency relationships). CISA SBOM
- Known Unresolved Vulnerabilities (KUVs) and Known Exploited Vulnerabilities (KEVs) must be disclosed with justification/mitigation if unresolved at submission. CISA KEV catalog
- Coordinated vulnerability disclosure process expected, referencing ISO/IEC 29147 and 30111 practices. ISO/IEC 29147
- PHI/PII-handling devices: SBOM and vulnerability review should explicitly flag components with data-handling exposure for prioritized patching. HHS HIPAA Security Rule
04 · Postmarket obligations
- Continuous monitoring and timely patching commitment; unpatched critical vulnerabilities can trigger recall-level review. FDA cyber hub
- Software Bill of Materials must be kept current across the product lifecycle, not just at clearance. CISA SBOM
- Coordinated disclosure and incident response processes must remain active post-clearance. ISO/IEC 30111
- PCCP, if used, must define the boundaries within which cyber-relevant changes can be made without new submission. FDA PCCP guidance
- Life-sustaining/high-risk devices: expedited patch-timeline expectations and closer FDA engagement on unmitigated critical vulnerabilities. FDA cyber hub
- Class III implantables: postmarket surveillance should include telemetry-link-specific incident monitoring, not just software-layer monitoring. FDA cyber hub
Primary sources — United States
FD&C Act §524B21 U.S.C. §360n-2
GovInfo ↗Premarket Cybersecurity GuidanceFDA, final Sep 2023
FDA.gov ↗FDA Digital Health — Cybersecurityprogram hub
FDA.gov ↗CISA SBOM programNTIA minimum elements
CISA.gov ↗PCCP guidance for ML-enabled devicesFDA
FDA.gov ↗ISO 14971:2019Risk management for medical devices
ISO.org ↗01 · Legal basis
- MDR Annex I, General Safety and Performance Requirements (GSPR) 17.2 and 17.4 — IT security and protection against unauthorised access. EUR-Lex 2017/745
- MDCG 2019-16 rev.1 — Guidance on Cybersecurity for Medical Devices (state of the art expectations). MDCG guidance index
- Cyber Resilience Act (EU) 2024/2847 layers additional obligations for products with digital elements as its phased application dates arrive; devices already regulated under MDR/IVDR have a defined interface to avoid duplicate assessment. EUR-Lex 2024/2847
02 · Premarket requirements
- Secure design and manufacture (state of the art) reducing cybersecurity risk; IT security measures for the intended environment of use documented. MDR Annex I §17.2
- Risk management under ISO 14971 must explicitly incorporate cybersecurity threats as a risk source, not a separate track. ISO 14971
- Technical documentation must describe minimum IT requirements (network specs, hardware, security patches) needed to run the device as intended. MDR Annex II
- Usability/human factors interplay: authentication and access control must not undermine safe use by intended users. IEC 62366-1
- AI Act overlay: if the device is high-risk AI under Art. 6(1), Art. 15 accuracy/robustness/cybersecurity obligations apply in addition to GSPR 17.2/17.4. EUR-Lex 2024/1689
- Class IIb/III life-sustaining devices: Notified Body scrutiny of cybersecurity evidence is materially deeper — expect dedicated cyber expert review. MDCG 2019-16
- Active implantable devices: wireless telemetry channels must be assessed under GSPR 17.2 for unauthorised reprogramming and signal interference risk. MDR Annex I §17.2
03 · SBOM / vulnerability handling
- MDCG 2019-16 expects an inventory of software components (SBOM-equivalent) sufficient to assess third-party/legacy component risk. MDCG 2019-16
- Integrity and authenticity of software and data must be verifiable (e.g., signing, checksums) across the update chain. MDR Annex I §17.4
- Vulnerability handling expected to reference ISO/IEC 29147 (disclosure) and ISO/IEC 30111 (processing) practices. ISO/IEC 29147
- Devices processing health data: SBOM review should cross-reference GDPR Art. 32 security-of-processing obligations for the same components. GDPR Art. 32
04 · Postmarket obligations
- Post-Market Surveillance (PMS) plan must explicitly capture cybersecurity signals (vulnerability reports, incidents) alongside clinical complaints. MDR Art. 83–86
- Serious incidents with a cybersecurity root cause are reportable under MDR vigilance obligations (Art. 87) via the competent authority / EUDAMED. MDR Art. 87
- Field Safety Corrective Actions (FSCAs) may be triggered by unmitigated critical vulnerabilities. MDR Art. 89
- Notified Body reassessment expected where cyber posture materially changes (e.g., new connectivity, major architecture change). MDCG guidance index
- Class III implantables: PMS should include telemetry-specific incident monitoring in addition to standard software vigilance. MDCG 2019-16
Primary sources — European Union
01 · Legal basis
- UK Medical Devices Regulations 2002 (SI 2002/618, as amended) remain in force post-Brexit; MHRA is the competent authority (no EU MDR direct effect in Great Britain). legislation.gov.uk
- MHRA guidance on medical device cybersecurity sets premarket and lifecycle expectations aligned to, but distinct from, EU MDCG 2019-16. Unverified — pending review
- NHS-deployed software additionally falls under the DCB0129 (manufacturer) / DCB0160 (deploying organisation) clinical safety standards. NHS Digital standards
02 · Premarket requirements
- Secure by design expectations mirror EU GSPR 17.2/17.4 in substance; manufacturer must document IT environment assumptions and security controls. Unverified — pending review
- Risk management integrated with ISO 14971; DCB0129 requires a Clinical Safety Case Report and Hazard Log for health IT manufacturers. DCB0129
- Software/AI-as-a-medical-device guidance (MHRA Software and AI as a Medical Device Change Programme) applies additional expectations for adaptive algorithms. gov.uk SaMD/AI programme
03 · SBOM / vulnerability handling
- MHRA guidance expects a software component inventory equivalent to SBOM, consistent with the UK's broader NCSC secure-software supply-chain expectations. NCSC supply chain
- Coordinated vulnerability disclosure practice expected, referencing the same ISO/IEC 29147 / 30111 baseline used across most Tier-comparable regimes. ISO/IEC 29147
04 · Postmarket obligations
- Field Safety Corrective Actions and Yellow Card-linked vigilance reporting apply where cyber vulnerabilities create a safety risk. MHRA vigilance reporting
- NHS-deployed systems: DCB0160 places ongoing clinical risk management obligations on the deploying organisation, separate from the manufacturer's DCB0129 duties. DCB0160
Primary sources — United Kingdom
UK Medical Devices Regulations 2002SI 2002/618, as amended
legislation.gov.uk ↗MHRA medical device cybersecurity guidancegov.uk
Unverified — pending reviewDCB0129 / DCB0160NHS Digital clinical safety standards
NHS Digital ↗Software and AI as a Medical Device ProgrammeMHRA
gov.uk ↗NCSC supply chain security guidanceNational Cyber Security Centre
ncsc.gov.uk ↗01 · Legal basis
- Medical Devices Regulations (SOR/98-282) under the Food and Drugs Act — Health Canada is the licensing authority. justice.gc.ca
- Guidance Document: Pre-market Requirements for Medical Device Cybersecurity — sets premarket expectations for connected/software devices. canada.ca guidance
02 · Premarket requirements
- Cybersecurity risk assessment integrated with ISO 14971; architecture diagrams, threat/risk analysis, and security control summary expected in the licence application. canada.ca guidance
- Cybersecurity test summary (e.g., penetration testing, vulnerability scanning results) submitted as supporting evidence for higher-risk device classes. canada.ca guidance
- SaMD-specific expectations align with Health Canada's pre-market guidance on machine learning-enabled devices. canada.ca device guidance index
03 · SBOM / vulnerability handling
- SBOM (or equivalent software inventory) expected for devices with third-party/off-the-shelf software components, per the pre-market cybersecurity guidance. canada.ca guidance
- Coordinated vulnerability disclosure processes referencing ISO/IEC 29147 / 30111 expected as part of manufacturer cybersecurity posture. ISO/IEC 29147
04 · Postmarket obligations
- Mandatory problem reporting under the Medical Devices Regulations applies where a cybersecurity issue results in (or could result in) a serious health impact. SOR/98-282
- Health Canada expects ongoing postmarket vulnerability monitoring and timely notification for licence holders of connected devices. canada.ca guidance
Primary sources — Canada
Medical Devices RegulationsSOR/98-282
justice.gc.ca ↗Pre-market Requirements for Medical Device CybersecurityHealth Canada guidance
canada.ca ↗Medical device guidance document indexHealth Canada
canada.ca ↗01 · Legal basis
- Act on Securing Quality, Efficacy and Safety of Products including Pharmaceuticals and Medical Devices (PMD Act) — MHLW sets policy, PMDA conducts review. PMDA reviews (EN)
- MHLW/PMDA cybersecurity notifications (based on the PSEHB/MDED administrative notice series) set premarket and postmarket cybersecurity expectations, explicitly IMDRF-aligned. PMDA English portal
02 · Premarket requirements
- Cybersecurity risk assessment expected as part of the application dossier, integrated with the device's overall risk management file (ISO 14971 aligned). ISO 14971
- PMDA reviewers expect manufacturers to reference IMDRF N60 principles when describing premarket cybersecurity controls. IMDRF N60 (PDF)
- Programme Medical Device (SaMD) pathway carries additional expectations for update/change management of AI-enabled software. PMDA reviews (EN)
03 · SBOM / vulnerability handling
- Software component inventory expected for third-party/OSS components as part of the technical dossier, consistent with IMDRF SBOM principles. IMDRF N73 (PDF)
- JPCERT/CC coordinates vulnerability disclosure for medical devices in Japan in cooperation with MHLW/PMDA. JPCERT/CC
04 · Postmarket obligations
- Manufacturers must report cybersecurity incidents that affect safety/performance under the PMD Act's adverse-event reporting framework. PMDA English portal
- Ongoing postmarket vulnerability monitoring and coordinated patching expected for network-connected devices, per MHLW/PMDA notifications. PMDA reviews (EN)
Primary sources — Japan
PMD ActMHLW / PMDA
PMDA ↗PMDA device review servicesEnglish portal
PMDA ↗IMDRF cybersecurity principlesN60 / N70
IMDRF N60 ↗JPCERT/CCNational CERT, medical device coordination
jpcert.or.jp ↗01 · Legal basis
- Regulations on the Supervision and Administration of Medical Devices, administered by the National Medical Products Administration (NMPA). NMPA English portal
- NMPA Guiding Principles for Cybersecurity Registration Review of Medical Devices (医疗器械网络安全注册审查指导原则) — one of the most prescriptive cybersecurity review guidelines among major regimes, covering both premarket and update-registration expectations. NMPA English portal
02 · Premarket requirements
- Detailed cybersecurity technical documentation required at registration: network architecture, data transmission security, and access control design. NMPA English portal
- Cybersecurity risk analysis expected to be integrated with the device's ISO 14971 risk-management process. ISO 14971
- AI-enabled/SaMD devices face additional registration review under NMPA's dedicated AI medical software review pathway. NMPA English portal
- Devices handling personal health data must also satisfy the Personal Information Protection Law (PIPL) and data cross-border transfer rules. Cyberspace Administration of China
03 · SBOM / vulnerability handling
- Software component/module inventory expected as part of the cybersecurity registration dossier. NMPA English portal
- Vulnerability handling expected to align with China's national vulnerability database (CNVD) coordination process for connected medical devices. CNVD
04 · Postmarket obligations
- Adverse event/incident reporting obligations extend to cybersecurity-related safety events under NMPA's postmarket surveillance framework. NMPA English portal
- Material changes to network/connectivity architecture generally require a registration change filing rather than a silent update. NMPA English portal
Primary sources — China
NMPA — medical device regulationEnglish portal
english.nmpa.gov.cn ↗Cyberspace Administration of ChinaPIPL / data transfer
cac.gov.cn ↗CNVDNational vulnerability database
cnvd.org.cn ↗ISO 14971:2019Risk management
ISO.org ↗01 · Legal basis
- Therapeutic Goods (Medical Devices) Regulations 2002, administered by the Therapeutic Goods Administration (TGA). legislation.gov.au
- TGA Medical device cyber security guidance for industry sets premarket and lifecycle expectations, referencing the Essential Principles. tga.gov.au guidance
02 · Premarket requirements
- Essential Principle 12.1 (software and IT network security) requires manufacturers to design devices to protect against unauthorised access. TGA cyber guidance
- Risk management under ISO 14971 must incorporate cybersecurity threats; TGA expects a cybersecurity risk management summary in the technical file. ISO 14971
- Software-based devices (including AI/ML) fall under TGA's SaMD regulatory framework with additional classification and evidence expectations. TGA SaMD framework
03 · SBOM / vulnerability handling
- TGA cyber guidance expects a software bill of materials or equivalent inventory for devices with third-party/OTS components. TGA cyber guidance
- Coordinated vulnerability disclosure expected, referencing ISO/IEC 29147 / 30111 and alignment with Australian Cyber Security Centre (ACSC) practices. ACSC
04 · Postmarket obligations
- Mandatory adverse event reporting to TGA applies where a cybersecurity vulnerability causes or could cause patient harm. TGA problem reporting
- Ongoing postmarket monitoring and timely patch deployment expected for network-connected devices, consistent with TGA cyber guidance. TGA cyber guidance
Primary sources — Australia
Therapeutic Goods (Medical Devices) Regulations 2002legislation.gov.au
legislation.gov.au ↗TGA medical device cyber security guidanceIndustry guidance
tga.gov.au ↗TGA software-based medical devicesSaMD framework
tga.gov.au ↗Australian Cyber Security CentreACSC
cyber.gov.au ↗01 · Legal basis
- Medical Devices Act, administered by the Ministry of Food and Drug Safety (MFDS). MFDS English portal
- MFDS cybersecurity review guidance for medical devices sets premarket documentation expectations, IMDRF-aligned. MFDS English portal
02 · Premarket requirements
- Cybersecurity risk assessment and security architecture documentation required for network-connected device approvals. MFDS English portal
- Risk management integrated with ISO 14971; MFDS reviewers reference IMDRF cybersecurity principles for evaluation consistency. IMDRF N60
- AI/SaMD devices reviewed under MFDS's dedicated digital medical device approval pathway. MFDS English portal
03 · SBOM / vulnerability handling
- Software component inventory expected for devices incorporating third-party or open-source components. MFDS English portal
- Vulnerability coordination expected through KISA (Korea Internet & Security Agency) channels for connected medical devices. KISA
04 · Postmarket obligations
- Adverse event reporting obligations extend to cybersecurity-caused safety events under MFDS postmarket surveillance rules. MFDS English portal
- Ongoing monitoring and patch management expected for connected devices, consistent with MFDS cybersecurity review guidance. MFDS English portal
Primary sources — South Korea
Ministry of Food and Drug SafetyMFDS — Medical Devices Act
mfds.go.kr ↗Korea Internet & Security AgencyKISA — vulnerability coordination
kisa.or.kr ↗IMDRF cybersecurity principlesN60 / N70
imdrf.org ↗01 · Legal basis
- Health Products Act and Health Products (Medical Devices) Regulations, administered by the Health Sciences Authority (HSA). HSA medical devices
- HSA guidance documents for medical device software (including cybersecurity considerations) set premarket expectations, IMDRF-aligned. HSA guidance documents
02 · Premarket requirements
- Cybersecurity risk documentation expected for connected/networked devices as part of the product registration dossier. HSA guidance documents
- Risk management integrated with ISO 14971; HSA reviewers reference IMDRF cybersecurity principles. IMDRF N60
- Standalone software/AI medical devices reviewed under HSA's dedicated SaMD regulatory guidance. HSA guidance documents
03 · SBOM / vulnerability handling
- Software component inventory expected for devices with third-party or open-source components, consistent with regional IMDRF-aligned practice. HSA guidance documents
- Vulnerability disclosure coordination available through Singapore's national CERT (SingCERT) for connected medical devices. SingCERT
04 · Postmarket obligations
- Adverse event reporting to HSA applies where a cybersecurity vulnerability results in, or could result in, patient harm. HSA adverse events
- Ongoing postmarket vulnerability monitoring expected for connected devices, consistent with HSA guidance. HSA guidance documents
Primary sources — Singapore
Health Sciences AuthorityHSA — medical devices
hsa.gov.sg ↗HSA guidance documentsPremarket & software guidance
hsa.gov.sg ↗SingCERTCyber Security Agency of Singapore
csa.gov.sg ↗01 · Legal basis
- RDC (Resolução da Diretoria Colegiada) framework for medical devices, administered by ANVISA (Agência Nacional de Vigilância Sanitária). gov.br/anvisa
- ANVISA software/SaMD-specific regulation (RDC 657/2022 and related instructions) covers cybersecurity-relevant documentation for software-based devices. ANVISA legislation index
02 · Premarket requirements
- Technical documentation for connected/networked devices expected to describe data security and access control design. ANVISA legislation index
- Risk management integrated with ISO 14971 as the internationally-harmonized baseline referenced in ANVISA technical requirements. ISO 14971
- Devices handling personal health data must also satisfy Brazil's LGPD (Lei Geral de Proteção de Dados) requirements. ANPD (LGPD authority)
03 · SBOM / vulnerability handling
- Software component documentation expected for devices with third-party or open-source components as part of the technical dossier. ANVISA legislation index
- Vulnerability coordination available through Brazil's national CERT (CERT.br) for connected medical devices. CERT.br
04 · Postmarket obligations
- Adverse event / technical complaint reporting (Notivisa) obligations extend to cybersecurity-related safety events. Notivisa
- Ongoing postmarket monitoring expected for connected devices, consistent with ANVISA's general vigilance framework. ANVISA legislation index
Primary sources — Brazil
ANVISAMedical device regulation (RDC framework)
gov.br/anvisa ↗ANVISA legislation indexSoftware / SaMD instructions
gov.br/anvisa ↗NotivisaAdverse event reporting system
gov.br/anvisa ↗ANPDLGPD data protection authority
gov.br/anpd ↗01 · Legal basis
- Medical Devices Rules, 2017 (under the Drugs and Cosmetics Act), administered by the Central Drugs Standard Control Organisation (CDSCO). CDSCO medical devices
- Cybersecurity-specific regulatory expectations are lighter and still emerging relative to other jurisdictions in this navigator; CDSCO increasingly references IMDRF principles for software/connected devices. IMDRF N60
02 · Premarket requirements
- Risk management documentation (ISO 14971-aligned) expected as part of the device master file for software-containing devices. ISO 14971
- Software as a Medical Device (SaMD) classification follows CDSCO's risk-based classification rules under the Medical Devices Rules, 2017. CDSCO medical devices
- Connected/networked devices are expected to document data security and access control measures, though a dedicated cybersecurity guidance document (comparable to FDA/MDCG) is still developing. CDSCO medical devices
03 · SBOM / vulnerability handling
- No dedicated SBOM mandate yet; manufacturers commonly rely on the same software inventory prepared for FDA/EU submissions to satisfy CDSCO documentation review. CDSCO medical devices
- Vulnerability coordination available through India's national CERT (CERT-In) for connected medical devices. CERT-In
04 · Postmarket obligations
- Adverse event reporting under the Materiovigilance Programme of India (MvPI), coordinated by the Indian Pharmacopoeia Commission (IPC) as National Coordination Centre, extends to safety events with a cybersecurity root cause. MvPI (IPC)
- Devices handling personal health data must also account for India's Digital Personal Data Protection Act, 2023. MeitY — DPDP Act 2023
Primary sources — India
Medical Devices Rules, 2017CDSCO
cdsco.gov.in ↗Materiovigilance Programme of IndiaMvPI — IPC (National Coordination Centre)
ipc.gov.in ↗CERT-InNational CERT
cert-in.org.in ↗Digital Personal Data Protection Act, 2023MeitY
meity.gov.in ↗03 Cross-Cutting Standards Layer
Shared scaffolding referenced by every country moduleIEC 81001-5-1
Health software cybersecurity lifecycle
Security engineering across the software lifecycle for health software products — referenced by FDA, EU MDR, and most major regimes as the technical baseline.
ISO.org
IEC 62443 series
Industrial / network security
Component and system-level security requirements, often invoked for connected device architecture and network segmentation.
ISA.org
ISO/IEC 27001 · 27005
ISMS and risk management
Manufacturer-side information security management and risk assessment methodology — governance layer above device-level controls.
ISO.org
NIST CSF 2.0
Cybersecurity Framework
Govern / Identify / Protect / Detect / Respond / Recover structure — many submissions map their controls to this framework for reviewer familiarity.
NIST.gov
NTIA / CISA SBOM
SBOM minimum elements
Baseline data fields (supplier, component, version, dependency relationships) referenced by FDA and increasingly across Asia-Pacific regimes.
CISA.gov
ISO/IEC 29147 · 30111
Vulnerability disclosure & handling
Coordinated vulnerability disclosure and internal handling process standards, referenced across nearly every postmarket obligation worldwide.
ISO.org
IMDRF N60 / N70
International harmonization guides
IMDRF principles and practices for medical device cybersecurity that most national regimes explicitly align to or cite.
IMDRF.org
ISO 14971
Risk management integration
Every regime in this navigator expects cybersecurity risk folded into the same risk management process as safety risk, not run in parallel.
ISO.org