Skip to main content
EUEU MDR 2017/745 · IVDR 2017/746 · MDCG 2019-16 · EN IEC 81001-5-1

Medical device & IVD cybersecurity for CE marking.
We get the evidence ready.

Since MDCG 2019-16, CE marking under the EU MDR and IVDR requires you to show that cybersecurity was designed in, tested, and documented in your technical file. That is a specialist discipline, distinct from the regulatory and quality-system work your CE partner leads. We cover it — end to end — so cybersecurity is not what holds up your submission.

How it works

01

Kaitara Security delivers the cybersecurity evidence

Threat model, gap assessment, security risk file, SBOM, testing strategy and VAPT, post-market plan, and the technical-file cybersecurity section — every cybersecurity input a Notified Body reviewer will ask for.

02

Your team implements fixes with our guidance

We specify what needs to change — secure update, credentials, logging, data protection — and review the fixes, then retest to confirm the critical and high findings are closed.

03

Notified Body issues the CE mark

CE marking is a Notified Body conformity assessment. We prepare the cybersecurity evidence and work alongside your CE / ISO 13485 partner; the mark itself is issued by the Notified Body.

Collaborative and hands-on — delivered remotely, working directly with your engineering team.

GSPR 17.2

Software to the state of the art, with information-security risk management

MDCG 2019-16

The cybersecurity documentation a Notified Body expects

IEC 81001-5-1

The recognised secure product-lifecycle standard

Phase 1

Gap assessment

Start here. It stands on its own.

A short, scoped first step: we confirm what actually applies to your device — and what does not, with the reason — review what you already hold, and give you a gap report per assessment area with a prioritised action plan. If you go no further, you keep a defensible assessment you can share with your regulatory partner and your Notified Body.

Fixed-fee, scoped to you — no hourly billing.

Full programme

Phases 2–4

Evidence, testing, readiness

Quoted firm once the assessment is done.

Threat model and security risk file linked to your ISO 14971 process, SBOM, security testing with a clean retest, disclosure and post-market plans, the technical-file cybersecurity section, and the CE Cybersecurity Readiness Assessment. Sized to your device class, connectivity and timeline — and run alongside your CE partner so both workstreams finish together.

Fixed-fee, scoped to you — no hourly billing.

What we deliver

Security architecture review — data flows, interfaces, and trust boundaries
Threat model (STRIDE) with security risks scored and prioritised
Cybersecurity gap assessment against MDCG 2019-16 and IEC 81001-5-1
Security risk management file (AAMI TIR57) linked to your ISO 14971 process
Minimum IT / network / security requirements and IFU security section (GSPR 17.4 / 23.4)
Software Bill of Materials (SBOM) and vulnerability management plan
Security testing strategy — SAST, software composition analysis, DAST, and penetration testing
VAPT findings report with severity ratings, then a clean retest after remediation
Device-specific checks — credentials, secure update, wireless, logging, session, data protection
Cybersecurity management plan aligned to the IEC 81001-5-1 lifecycle
Coordinated vulnerability disclosure policy (ISO/IEC 29147 / 30111)
Post-market cybersecurity surveillance plan (MDCG 2019-16 / AAMI TIR97)
Traceability matrix mapping security requirements and design controls to EN IEC 81001-5-1 clauses
Cybersecurity section of the technical documentation, assembled for the Notified Body
CE cybersecurity readiness assessment — the final sign-off before submission

What the MDR requires

17.1–17.4

MDR Annex I — software & IT security GSPRs

Programmable systems designed for reliability; software developed to the state of the art with information-security risk management (17.2); minimum hardware / IT-network / IT-security requirements against unauthorised access (17.4).

16.1–16.4

IVDR Annex I — the same GSPRs for IVDs

IVDR 2017/746 carries the identical obligations under different numbering: 16.2 mirrors MDR 17.2 (state of the art, including information security) and 16.4 mirrors MDR 17.4 (minimum hardware, IT-network and IT-security requirements).

14.2(d) / 23.4

Operating environment & IFU

Risks from interaction with the operating environment reduced; the Instructions for Use state the minimum IT and IT-security measures needed to run the device safely — MDR 23.4(ab), IVDR 20.4.1(ah).

MDCG 2019-16

Cybersecurity guidance for medical devices

The interpreting guidance: secure by design, defence in depth, security capabilities, the manufacturer/operator responsibility split, and pre- and post-market cybersecurity documentation.

IEC 81001-5-1

Secure product lifecycle

The recognised state-of-the-art secure development lifecycle for health software — the evidence that satisfies GSPR 17.2. Aligns with IEC 62443-4-1.

ISO 14971 + TIR57

Security risk, connected to safety risk

Security risk management per AAMI TIR57, with risks that can cause patient harm integrated into the ISO 14971 safety risk file.

How an engagement runs

Scoping

Understand the device

Class, connectivity, software, cloud/app, update mechanism, target markets, and where you are in the CE timeline.

Assess

Architecture, threat model & gap assessment

Security architecture and threat model; posture measured against MDCG 2019-16 and IEC 81001-5-1.

Build

Risk file, SBOM & testing

Security risk management file linked to ISO 14971; SBOM and vulnerability management; security testing strategy and VAPT.

Remediate

Fix and retest

Your team closes critical and high findings with our guidance; we retest to a clean result.

Ready

Technical file & readiness sign-off

Cybersecurity section assembled; CE cybersecurity readiness assessment issued for the Notified Body submission.

Common questions

Do you issue the CE mark?

No. CE marking is issued through a Notified Body conformity assessment. We prepare and validate the cybersecurity portion of your technical file — the threat model, gap assessment, security risk file, SBOM, testing evidence, and readiness assessment — so that cybersecurity is not what holds up your submission. We work alongside your CE / ISO 13485 partner, who leads the regulatory and quality-system side.

Is cybersecurity really required for CE marking?

Yes. The EU MDR General Safety and Performance Requirements (Annex I, especially 17.2 and 17.4) require software to be developed to the state of the art with information-security risk management, and require minimum IT-security measures against unauthorised access. MDCG 2019-16 sets out how a Notified Body expects that to be demonstrated. For a device with software or connectivity, it is part of the technical documentation — not optional.

Does this apply to IVDs as well?

Yes. MDCG 2019-16 is the joint guidance for both the MDR and the IVDR, and EN IEC 81001-5-1:2022 is the recognised state of the art for both. The IVDR carries the same obligations under different numbering — Annex I 16.2 mirrors MDR 17.2, 16.4 mirrors 17.4, and 20.4.1(ah) mirrors 23.4(ab) for the Instructions for Use. The evidence set is identical. What differs is the harm pathway: for an IVD a compromise shows up as a wrong, delayed or unavailable result rather than physical injury, so severity is assessed against clinical decision impact — and the connectivity surface is usually LIS/LIMS and middleware over HL7 or ASTM rather than DICOM and PACS.

What standards do you work to?

EU MDR 2017/745 (the GSPRs on software and IT security), MDCG 2019-16 (the cybersecurity guidance), IEC 81001-5-1 (secure product lifecycle), IEC 62304 (software lifecycle), ISO 14971 with AAMI TIR57 (security risk management), and SBOM practice. These are the recognised state of the art a reviewer looks for.

Our device isn't heavily connected — do we still need this?

If it contains software, yes — but the scope is smaller. You still need a secure development lifecycle, a security risk assessment, an SBOM for third-party components, and the minimum IT-security documentation. Connectivity, wireless, cloud or companion apps, and remote update each add scope. We size the engagement to what your device actually is.

We also want to sell in the US — does that change anything?

Yes. The FDA premarket cybersecurity expectations under Section 524B of the FD&C Act require a vulnerability-management plan, reasonable assurance of security, an update/patch process, and a mandatory SBOM for 'cyber devices'. We can extend the engagement to cover FDA premarket cybersecurity alongside the EU MDR work — available on request.

How does this fit with our CE / regulatory consultant?

Cleanly. Your CE consultant leads CE marking, ISO 13485, the technical file, and the Notified Body relationship. We cover the cybersecurity slice that sits inside that technical file — a specialist discipline most regulatory firms do not do in-house. The two run in parallel so the cybersecurity evidence is ready when your submission is.

Getting a device CE-marked?

30-minute scoping call. We look at your device, connectivity, and timeline, and give you a right-sized, fixed-fee proposal to get the cybersecurity evidence ready for your Notified Body.

Book a free scoping call →

Further reading: MDCG 2019-16 — what a Notified Body actually checks