IMDRF Principles and Practices for Medical Device Cybersecurity
International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.
Definition
The International Medical Device Regulators Forum (IMDRF) Cybersecurity Working Group has published a series of guidance documents - most notably IMDRF/CYBER WG/N60 (Principles and Practices for Medical Device Cybersecurity, 2020) and N73 (Principles and Practices for the Cybersecurity of Legacy Medical Devices, 2023) - that harmonize regulator expectations across jurisdictions including the FDA, Health Canada, MHRA, TGA, PMDA, and the EU.What this means in practice
MedTech teams pursuing global submissions use IMDRF principles as the common backbone, then layer on jurisdiction-specific requirements (524B for the US, MDCG 2019-16 for the EU). The legacy-device guidance (N73) is particularly valuable because it addresses devices designed before modern cybersecurity expectations existed.- •Treating IMDRF guidance as the ceiling rather than the floor - national regulators add specifics.
- •Ignoring N73's legacy-device guidance for products approaching end-of-support.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsCybersecurity considerations for medical devices that cannot be reasonably protected against current threats.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
International Medical Device Regulators Forum.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
IMDRF/CYBER WG/N60 (2020)VerifiedIMDRFimdrf.org
- 2
IMDRF/CYBER WG/N73 (2023)VerifiedIMDRFimdrf.org
- 3
FDA - Cybersecurity for Medical DevicesVerifiedFDAfda.gov
Inline markers like [1] jump to the matching reference above.