Medical device & IVD cybersecurity for CE marking.
We get the evidence ready.
Since MDCG 2019-16, CE marking under the EU MDR and IVDR requires you to show that cybersecurity was designed in, tested, and documented in your technical file. That is a specialist discipline, distinct from the regulatory and quality-system work your CE partner leads. We cover it — end to end — so cybersecurity is not what holds up your submission.
How it works
Kaitara Security delivers the cybersecurity evidence
Threat model, gap assessment, security risk file, SBOM, testing strategy and VAPT, post-market plan, and the technical-file cybersecurity section — every cybersecurity input a Notified Body reviewer will ask for.
Your team implements fixes with our guidance
We specify what needs to change — secure update, credentials, logging, data protection — and review the fixes, then retest to confirm the critical and high findings are closed.
Notified Body issues the CE mark
CE marking is a Notified Body conformity assessment. We prepare the cybersecurity evidence and work alongside your CE / ISO 13485 partner; the mark itself is issued by the Notified Body.
Collaborative and hands-on — delivered remotely, working directly with your engineering team.
GSPR 17.2
Software to the state of the art, with information-security risk management
MDCG 2019-16
The cybersecurity documentation a Notified Body expects
IEC 81001-5-1
The recognised secure product-lifecycle standard
Phase 1
Gap assessment
Start here. It stands on its own.
A short, scoped first step: we confirm what actually applies to your device — and what does not, with the reason — review what you already hold, and give you a gap report per assessment area with a prioritised action plan. If you go no further, you keep a defensible assessment you can share with your regulatory partner and your Notified Body.
Fixed-fee, scoped to you — no hourly billing.
Phases 2–4
Evidence, testing, readiness
Quoted firm once the assessment is done.
Threat model and security risk file linked to your ISO 14971 process, SBOM, security testing with a clean retest, disclosure and post-market plans, the technical-file cybersecurity section, and the CE Cybersecurity Readiness Assessment. Sized to your device class, connectivity and timeline — and run alongside your CE partner so both workstreams finish together.
Fixed-fee, scoped to you — no hourly billing.
What we deliver
What the MDR requires
MDR Annex I — software & IT security GSPRs
Programmable systems designed for reliability; software developed to the state of the art with information-security risk management (17.2); minimum hardware / IT-network / IT-security requirements against unauthorised access (17.4).
IVDR Annex I — the same GSPRs for IVDs
IVDR 2017/746 carries the identical obligations under different numbering: 16.2 mirrors MDR 17.2 (state of the art, including information security) and 16.4 mirrors MDR 17.4 (minimum hardware, IT-network and IT-security requirements).
Operating environment & IFU
Risks from interaction with the operating environment reduced; the Instructions for Use state the minimum IT and IT-security measures needed to run the device safely — MDR 23.4(ab), IVDR 20.4.1(ah).
Cybersecurity guidance for medical devices
The interpreting guidance: secure by design, defence in depth, security capabilities, the manufacturer/operator responsibility split, and pre- and post-market cybersecurity documentation.
Secure product lifecycle
The recognised state-of-the-art secure development lifecycle for health software — the evidence that satisfies GSPR 17.2. Aligns with IEC 62443-4-1.
Security risk, connected to safety risk
Security risk management per AAMI TIR57, with risks that can cause patient harm integrated into the ISO 14971 safety risk file.
How an engagement runs
Understand the device
Class, connectivity, software, cloud/app, update mechanism, target markets, and where you are in the CE timeline.
Architecture, threat model & gap assessment
Security architecture and threat model; posture measured against MDCG 2019-16 and IEC 81001-5-1.
Risk file, SBOM & testing
Security risk management file linked to ISO 14971; SBOM and vulnerability management; security testing strategy and VAPT.
Fix and retest
Your team closes critical and high findings with our guidance; we retest to a clean result.
Technical file & readiness sign-off
Cybersecurity section assembled; CE cybersecurity readiness assessment issued for the Notified Body submission.
Common questions
Do you issue the CE mark?
No. CE marking is issued through a Notified Body conformity assessment. We prepare and validate the cybersecurity portion of your technical file — the threat model, gap assessment, security risk file, SBOM, testing evidence, and readiness assessment — so that cybersecurity is not what holds up your submission. We work alongside your CE / ISO 13485 partner, who leads the regulatory and quality-system side.
Is cybersecurity really required for CE marking?
Yes. The EU MDR General Safety and Performance Requirements (Annex I, especially 17.2 and 17.4) require software to be developed to the state of the art with information-security risk management, and require minimum IT-security measures against unauthorised access. MDCG 2019-16 sets out how a Notified Body expects that to be demonstrated. For a device with software or connectivity, it is part of the technical documentation — not optional.
Does this apply to IVDs as well?
Yes. MDCG 2019-16 is the joint guidance for both the MDR and the IVDR, and EN IEC 81001-5-1:2022 is the recognised state of the art for both. The IVDR carries the same obligations under different numbering — Annex I 16.2 mirrors MDR 17.2, 16.4 mirrors 17.4, and 20.4.1(ah) mirrors 23.4(ab) for the Instructions for Use. The evidence set is identical. What differs is the harm pathway: for an IVD a compromise shows up as a wrong, delayed or unavailable result rather than physical injury, so severity is assessed against clinical decision impact — and the connectivity surface is usually LIS/LIMS and middleware over HL7 or ASTM rather than DICOM and PACS.
What standards do you work to?
EU MDR 2017/745 (the GSPRs on software and IT security), MDCG 2019-16 (the cybersecurity guidance), IEC 81001-5-1 (secure product lifecycle), IEC 62304 (software lifecycle), ISO 14971 with AAMI TIR57 (security risk management), and SBOM practice. These are the recognised state of the art a reviewer looks for.
Our device isn't heavily connected — do we still need this?
If it contains software, yes — but the scope is smaller. You still need a secure development lifecycle, a security risk assessment, an SBOM for third-party components, and the minimum IT-security documentation. Connectivity, wireless, cloud or companion apps, and remote update each add scope. We size the engagement to what your device actually is.
We also want to sell in the US — does that change anything?
Yes. The FDA premarket cybersecurity expectations under Section 524B of the FD&C Act require a vulnerability-management plan, reasonable assurance of security, an update/patch process, and a mandatory SBOM for 'cyber devices'. We can extend the engagement to cover FDA premarket cybersecurity alongside the EU MDR work — available on request.
How does this fit with our CE / regulatory consultant?
Cleanly. Your CE consultant leads CE marking, ISO 13485, the technical file, and the Notified Body relationship. We cover the cybersecurity slice that sits inside that technical file — a specialist discipline most regulatory firms do not do in-house. The two run in parallel so the cybersecurity evidence is ready when your submission is.
Getting a device CE-marked?
30-minute scoping call. We look at your device, connectivity, and timeline, and give you a right-sized, fixed-fee proposal to get the cybersecurity evidence ready for your Notified Body.
Book a free scoping call →Further reading: MDCG 2019-16 — what a Notified Body actually checks