EU
MDCG 2019-16 — what a Notified Body actually checks
The cybersecurity questions a Notified Body reviewer asks of a CE technical file, the MDR and IVDR clauses behind them, and the seven findings that draw a non-conformity.
Plain-English writing on the obligations we work with, grounded in the primary sources.
The cybersecurity questions a Notified Body reviewer asks of a CE technical file, the MDR and IVDR clauses behind them, and the seven findings that draw a non-conformity.
India requires cyber incidents to be reported to CERT-In within 6 hours. Who it binds, when the clock actually starts, what counts as reportable, and the localisation myth.
What FDA's cybersecurity law actually requires for a 510(k) or PMA: who it applies to, the four obligations, and what happens if the cybersecurity section is incomplete.