IMDRF N60 / N73

One evidence model, every jurisdiction.

IMDRF N60 gave regulators a shared set of premarket and postmarket cybersecurity principles, and N73 extended them to legacy devices. ELTON produces one verified evidence set that travels: FDA, EU, Japan, Australia, UK. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.

The guidance

What N60 and N73 established

IMDRF wrote the common ground, N60 in 2020 and N73 for legacy devices in 2023, and national regulators built on it. That is why submissions in different markets keep asking the same questions in different templates.

N60: life cycle principles

Security across the total product life cycle: risk management and security testing before market, vulnerability monitoring and handling after, with coordinated disclosure and information sharing among manufacturers, providers, and regulators. The premarket and postmarket halves are one system, not two documents.

N73: legacy is a stage, not an excuse

Devices outlive their software everywhere, and N73 treats that as a phase to manage: know what is fielded, keep assessing risk as support winds down, and communicate end of support clearly to the people still running the device.

Principles that expect evidence

Both documents point one direction: security claims should rest on objective evidence. Testing records, vulnerability dispositions, SBOM transparency, and documented decisions rather than assertions.

The ELTON mapping

Test once.
Let the evidence travel.

Regulators aligned on IMDRF principles differ in template more than substance. The economical move is one rigorous evidence model, produced once and filed everywhere, so every reviewer reads the same facts.

A jurisdiction neutral twin

ELTON builds a digital twin from quality system documentation and runs continuous discovery across hardware, firmware, software, web, mobile, and network. Nothing in the model is specific to one regulator, so nothing gets rebuilt per market.

Verification on the real product

AI verifies which findings are exploitable on the running product. Scoring uses the MDDT-recognized CVSS rubric, developed with MITRE and qualified by FDA, plus SSVC style dimensions: automatable, total compromise, vectors, proof of concept.

Outputs every reviewer can read

Evidenced dispositions and VEX in CycloneDX. The same record supports FDA 524B and eSTAR, CRA and NIS2 duties in the EU, and IMDRF aligned reviews in Japan, Australia, and the UK.

One record, five reviews

Where the evidence goes

This is the point of harmonization: produce the evidence once, then format per jurisdiction instead of retesting per jurisdiction. Format changes at the border. The testing does not.

One verified evidence set, filed in every marketregulators aligned on IMDRF N60 / N73ELTON evidence settwin · verified findingsdispositions · VEX (CycloneDX)US FDA524B · eSTAREuropean UnionCRA · NIS2 · MDRJapan PMDAIMDRF aligned guidanceUK MHRAIMDRF aligned reviewAustralia TGAdevice cyber guidance
N60 aligned regulators ask the same questions. Answer once, with evidence.
Legacy fleets

N73 without the archaeology

A twin can be built for fielded devices from documentation you already hold. Verification then separates legacy findings that are exploitable in the field from the ones that are noise, which is exactly the risk picture N73 asks you to manage and communicate.

Harmonization in practice

Five templates, one record

Teams burn quarters reformatting the same security story for each market. Start from one verified evidence set and the per jurisdiction work shrinks to formatting. See FDA §524B, EU MDR/CRAEU RED, and NIS2.

Get started

One evidence set for every market you sell in.

Start with one device. We build the twin, verify what is exploitable, and produce dispositions and VEX your regulatory team reuses across jurisdictions.

Questions

Common questions about IMDRF N60 and N73.

What is IMDRF N60?

IMDRF N60, published in 2020, gave regulators a shared set of cybersecurity principles across the total product life cycle: risk management and security testing before market, vulnerability monitoring and handling after, with coordinated disclosure and information sharing among manufacturers, providers and regulators. The premarket and postmarket halves are one system, not two documents.

What does IMDRF N73 say about legacy devices?

N73, published in 2023, extended the N60 principles to legacy devices and treats legacy as a stage to manage rather than an excuse. It expects a manufacturer to know what is fielded, keep assessing risk as support winds down, and communicate end of support clearly to the people still running the device.

Which regulators follow IMDRF cybersecurity guidance?

National regulators built on N60, which is why submissions in different markets keep asking the same questions in different templates. One evidence set supports FDA 524B and eSTAR in the US, CRA, NIS2 and MDR duties in the EU, and IMDRF aligned reviews in Japan, Australia and the UK.

Do we have to retest for every market we sell in?

No. Regulators aligned on IMDRF principles differ in template more than substance, so the economical approach is one rigorous evidence model, produced once and filed everywhere. Format changes at the border. The testing does not, and the per jurisdiction work shrinks to formatting.

What kind of evidence do the IMDRF principles expect?

Both N60 and N73 point one direction: security claims should rest on objective evidence rather than assertion. That means testing records, vulnerability dispositions, SBOM transparency and documented decisions. ELTON produces evidenced dispositions and VEX in CycloneDX, scored on the MDDT recognized CVSS rubric developed with MITRE and qualified by FDA.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON