Regulatory Guides

Every jurisdiction. One evidence model.

Plain-language guides to the cybersecurity expectations medical device manufacturers actually face, written by a team that has taken 1,000+ FDA submissions through review.

United States

FDA

Section 524B, eSTAR, postmarket guidance, QMSR, and the metrics that follow you after clearance.

European Union

CRA, NIS2, MDR

Product regulation, entity regulation, and certificate renewal, each with its own clock.

Global

IMDRF and beyond

Harmonization means the same evidence, asked for in different accents.

Scoring

CVSS, MDDT, and defensible ratings

The rating is what reviewers argue with. Make it rules-based.

Get started

Bring your regulation. Leave with a plan.

Tell us which jurisdictions you sell into and we will show you the single evidence model that satisfies all of them.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about the regulatory guides.

Which medical device cybersecurity regulations do the guides cover?

Three regions. The United States: FDA Section 524B, eSTAR, postmarket guidance, QMSR and the metrics that follow clearance. The European Union: the Cyber Resilience Act, NIS2 and MDR recertification. Global: IMDRF N60 and N73, Japan's adopted standards, and what NMPA registration expects under China's CSL.

Do we need different cybersecurity evidence for every country we sell into?

No. Harmonization means the same evidence asked for in different accents. The IMDRF N60 and N73 guide sets out one evidence model reused across FDA, EU, Japan, Australia and the UK, so the underlying work is done once and presented in the form each regulator expects.

Do devices cleared before 2023 still have cybersecurity obligations?

Yes. The legacy device guide answers it plainly: devices cleared before 2023 still carry monitoring and testing duties. A companion guide on the 2016 postmarket guidance explains that most SBOM findings do not require a patch, if you can evidence why, which is the part older programs usually cannot produce.

What do the EU cybersecurity guides cover?

Product regulation, entity regulation and certificate renewal, each with its own clock. The Cyber Resilience Act guide covers vulnerability handling and reporting duties. The NIS2 guide covers Articles 21 and 23 for health sector entities and the timelines they impose. The MDR guide covers what MDCG expects on cybersecurity when legacy certificates come up for renewal.

How should medical device vulnerabilities be scored for a regulator?

With a rules based rubric rather than expert opinion, because the rating is what reviewers argue with. The scoring guides cover the CVSSv4 migration now that FDA has recognized CVSSv4, why the FDA qualified MDDT rubric holds up in front of a reviewer, and how to operationalize the MITRE rubric with rationale metadata.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON