Question Clearly sourced

Expert knowledge for digital decisions

What cybersecurity requirements apply to connected medical software?

Short answer

The MDR requires cybersecurity as part of safety and performance throughout the entire lifecycle. Annex I number 17.2 mandates software development according to the state of the art, incorporating risk management, information security, as well as verification and validation; number 17.4 requires minimum requirements for IT environment, networks, and protective measures in the manufacturer's information. MDCG 2019-16 Rev. 1 and IEC 81001-5-1:2021 specify the secure product lifecycle.

Cybersecurity is a product characteristic

For connected medical software, an attack can not only affect confidentiality but also influence diagnosis, therapy, or availability. Therefore, cybersecurity is part of the safety and performance assessment of the medical device. MDR Annex I number 17.2 requires a development and manufacturing process according to the state of the art for software-based products, which considers the software lifecycle, risk management including information security, as well as verification and validation.

According to number 17.4, the manufacturer must define minimum requirements for hardware, IT networks, and IT security measures necessary for the intended operation. These requirements must be provided in such a way that operators can safely install, configure, and operate the product. Cybersecurity is thus a shared responsibility, but the manufacturer must not silently shift essential prerequisites onto the operator.

Secure lifecycle

MDCG 2019-16 Rev. 1 and IEC 81001-5-1:2021 lead to a risk-based process that includes:

  • Security requirements and threat model for the product, interfaces, and supply chain,
  • secure architecture with minimal rights, separation of critical functions, and secured default values,
  • controlled third-party components and traceable software composition,
  • code review, static and dynamic analyses, as well as risk-based penetration testing,
  • strong authentication, authorization, encryption, and tamper-proof logging,
  • signed or otherwise authenticated updates with secure rollback,
  • vulnerability acceptance, assessment, coordinated disclosure, and timely remediation,
  • post-market monitoring and feedback into risk files and clinical evaluation.

A component list or SBOM supports the rapid assessment of newly published vulnerabilities but does not replace threat analysis or the examination of actual accessibility and impact. A CVSS score alone does not determine the medical risk; what matters is whether and how a vulnerability in the specific product architecture can affect patient safety or essential performance.

Clearly specify operational requirements

Product information includes supported operating systems, network segmentation, ports and protocols, role model, backup and restart requirements, logging, patch process, and behavior in case of connection or integrity loss. For cloud and remote maintenance access, responsibilities, key management, and response paths must be defined.

IEC 81001-5-1:2021 describes security activities in the lifecycle of health software; ISO 81001-1:2021 classifies safety, effectiveness, and security as key properties to be balanced together. What controls are sufficient must be justified for the intended purpose, exposure, and damage potential of the specific product.

Example from practice

When a vulnerability in a network library becomes known, the manufacturer not only checks its CVSS score. They document affected versions, accessibility, possible clinical consequences, interim measures, patch tests, and secure distribution.

Key facts

MDR requirements
Annex I numbers 17.2 and 17.4
EU guideline
MDCG 2019-16 Rev. 1
Security lifecycle
IEC 81001-5-1:2021
Basic principle
Evaluate security risk and patient safety risk together

Sources

All external claims are backed by traceable sources.
  1. 01
  2. 02
    MDCG 2019-16 Rev. 1 – Guidance on Cybersecurity for medical devices Medical Device Coordination Group / Europäische Kommission
  3. 03
    IEC 81001-5-1:2021 – Security activities in the product life cycle International Electrotechnical Commission (IEC)

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation