NIS2 pulls the health sector into binding cybersecurity risk management, and the manufacture of medical devices sits in its annexes too. ELTON supplies the vulnerability handling measures and the incident answers, both on the directive's timelines. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.
NIS2 replaced the original NIS Directive with wider scope, named security measures, and harder deadlines. For medical device organizations, two articles do most of the work.
Entities must take proportionate technical and organisational measures, and the article names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure.
A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question, not a legal one.
Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the annexes as well. Where a supplier is not directly regulated, Article 21's supply chain measures reach it anyway, through customer contracts.
Auditors and hospital customers have stopped accepting a policy document as proof. ELTON turns the vulnerability handling measure into a running, documented process, where every claim traces to a test on the device.
A digital twin of each device, continuous discovery across hardware, firmware, software, web, mobile, and network, and AI verification of what is exploitable on the real product. The measure exists because it operates every day, not because a policy says it should.
Every finding and every dismissal is evidenced and scored, with VEX published in CycloneDX. When someone asks how vulnerability handling works here, you show the record: what was found, what was fixed, what was dismissed and why.
ELTON supports verification in 4 hours, an early-warning determination in 24, and a full report in 72. That is the technical half Article 23 depends on: is it real, is it malicious, what is affected, what is the exposure.
One measure has to run continuously, one deadline arrives suddenly. The same platform covers both: the measure and the clock, mapped below to what ELTON produces.
Essential entities must manage supplier risk, so hospitals now ask device vendors for vulnerability handling evidence during procurement. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time.
The workflow that feeds Article 23 also feeds the CRA reporting regime and FDA 524B postmarket duties. One verified record, three filings. See EU MDR/CRAEU RED and FDA §524B.
Start with one device. We stand up the twin, run continuous discovery and verification, and give you the record that answers auditors, customers, and the 24 hour clock.
Article 21 requires proportionate technical and organisational measures, and it names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure. Auditors and hospital customers have stopped accepting a policy document as proof, so each measure has to be demonstrable.
Article 23 sets three. A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question rather than a legal one.
Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the NIS2 annexes as well. Where a supplier is not directly regulated, the Article 21 supply chain measures reach it anyway, through customer contracts.
Because essential entities must manage supplier risk, so procurement now asks device vendors for vulnerability handling evidence. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time. The record that satisfies an auditor satisfies the customer.
By running it, not describing it. ELTON keeps a digital twin of each device, runs continuous discovery across hardware, firmware, software, web, mobile and network, and verifies what is exploitable on the real product. Every finding and every dismissal is scored and evidenced, with VEX published in CycloneDX for an auditor to walk.