IMDRF N60 gave regulators a shared set of premarket and postmarket cybersecurity principles, and N73 extended them to legacy devices. ELTON produces one verified evidence set that travels: FDA, EU, Japan, Australia, UK.
IMDRF wrote the common ground, N60 in 2020 and N73 for legacy devices in 2023, and national regulators built on it. That is why submissions in different markets keep asking the same questions in different templates.
Security across the total product life cycle: risk management and security testing before market, vulnerability monitoring and handling after, with coordinated disclosure and information sharing among manufacturers, providers, and regulators. The premarket and postmarket halves are one system, not two documents.
Devices outlive their software everywhere, and N73 treats that as a phase to manage: know what is fielded, keep assessing risk as support winds down, and communicate end of support clearly to the people still running the device.
Both documents point one direction: security claims should rest on objective evidence. Testing records, vulnerability dispositions, SBOM transparency, and documented decisions rather than assertions.
Regulators aligned on IMDRF principles differ in template more than substance. The economical move is one rigorous evidence model, produced once and filed everywhere, so every reviewer reads the same facts.
ELTON builds a digital twin from quality system documentation and runs continuous discovery across hardware, firmware, software, web, mobile, and network. Nothing in the model is specific to one regulator, so nothing gets rebuilt per market.
AI verifies which findings are exploitable on the running product. Scoring uses the MDDT-recognized CVSS rubric, developed with MITRE and qualified by FDA, plus SSVC style dimensions: automatable, total compromise, vectors, proof of concept.
Evidenced dispositions and VEX in CycloneDX. The same record supports FDA 524B and eSTAR, CRA and NIS2 duties in the EU, and IMDRF aligned reviews in Japan, Australia, and the UK.
This is the point of harmonization: produce the evidence once, then format per jurisdiction instead of retesting per jurisdiction. Format changes at the border. The testing does not.
A twin can be built for fielded devices from documentation you already hold. Verification then separates legacy findings that are exploitable in the field from the ones that are noise, which is exactly the risk picture N73 asks you to manage and communicate.
Teams burn quarters reformatting the same security story for each market. Start from one verified evidence set and the per jurisdiction work shrinks to formatting. See FDA §524B, EU MDR/CRAEU RED, and NIS2.
Start with one device. We build the twin, verify what is exploitable, and produce dispositions and VEX your regulatory team reuses across jurisdictions.