Understanding EU MDR and IVDR Cybersecurity Requirements for Medical Devices
As medical devices become increasingly connected, they are also more exposed to cybersecurity threats. At the same time, compliance with European regulations has become a critical factor, not just for market approval, but above all for ensuring patient safety. The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) and the In Vitro Diagnostic Regulation (IVDR, Regulation (EU) 2017/746) set clear and high expectations for the cybersecurity of medical and IVD devices. These requirements, supported by guidance from MDCG 2019-16, cover both the development phase and the post-market period.
Our “EU MDR/IVDR Cybersecurity Compliance Training” is designed to support medical device manufacturers in meeting the EU’s cybersecurity obligations. The focus is on practical implementation, covering cybersecurity risk management, security testing, and the integration of cybersecurity into quality management systems.
This training is particularly relevant for professionals working in R&D, Regulatory Affairs, Quality Management, and executive leadership. It provides a clear and structured understanding of how to incorporate cybersecurity throughout the entire product lifecycle—from design and development to post-market surveillance.
- Content
- Introduction to Product Security: Importance of cybersecurity in medical devices, overview of the regulatory landscape. Definition of key vocabulary and concepts in cybersecurity, such as “threat,” “vulnerability,” “risk,” “attack vector,” “mitigation,” “authentication,” “authorization,” “encryption,” and the CIA triad
- Regulatory Requirements and Standards: Overview of EU MDR cybersecurity requirement, and MDCG 2019-16 guidance, covering pre-market and post-market aspects. Discussion of relevant standards, such as ISO 14971 for risk management, IEC 81001-5-1, IEC 60601-4-5, and other Horizontal regulations in the EU
- Security Risk Management and ISO 14971 Application: Detailed explanation of security risk management processes, including hazard identification (e.g., unauthorized access, data breaches), risk estimation and evaluation, risk control (e.g., encryption, access controls), and monitoring effectiveness, with examples specific to cybersecurity.
- Threat Modeling and Risk Analysis: Introduction to threat modeling, including Data Flow Diagrams (DFDs), STRIDE methodology (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), attack trees, and other methods (e.g., PASTA, OCTAVE).
- Post-Market Activities for Cybersecurity: Overview of post-market cybersecurity activities, including: Post-market surveillance plan, incorporating cybersecurity monitoring, Vulnerability monitoring, using sources like vulnerability databases and manufacturer notifications
- Your Benefits
- Understand MDR/IVDR cybersecurity requirements and the MDCG 2019-16 guidance.
- Learn how ISO 14971 ties to cybersecurity, including hazard identification, threat modelling, and risk control.
- Gain hands-on experience through case studies and interactive sessions
- Ensure compliance, avoiding delays in market approval
- Enhance device security, protecting patient safety.
- Prepare teams for inspections and audits with confidence.
- Stay updated with evolving cybersecurity threats and regulations.
- Methods
Presentation, workshops, real-life examples, discussion, storytelling
- Target Audience
- Professionals in Research and Development (R&D) of medical and IVD devices
- Experts working in Regulatory Affairs with a focus on MDR/IVDR compliance
- Quality Managers integrating cybersecurity into quality management systems
- Technical Leads and Product Owners responsible for security risk management
- Cybersecurity Officers dealing with medical device IT security
- Auditors and team members preparing for notified body inspections and audits
- Executives and decision-makers with strategic responsibility for product compliance and patient safety

