NIS2 pulls the health sector into binding cybersecurity risk management, and the manufacture of medical devices sits in its annexes too. ELTON supplies the vulnerability handling measures and the incident answers, both on the directive's timelines.
NIS2 replaced the original NIS Directive with wider scope, named security measures, and harder deadlines. For medical device organizations, two articles do most of the work.
Entities must take proportionate technical and organisational measures, and the article names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure.
A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question, not a legal one.
Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the annexes as well. Where a supplier is not directly regulated, Article 21's supply chain measures reach it anyway, through customer contracts.
Auditors and hospital customers have stopped accepting a policy document as proof. ELTON turns the vulnerability handling measure into a running, documented process, where every claim traces to a test on the device.
A digital twin of each device, continuous discovery across hardware, firmware, software, web, mobile, and network, and AI verification of what is exploitable on the real product. The measure exists because it operates every day, not because a policy says it should.
Every finding and every dismissal is evidenced and scored, with VEX published in CycloneDX. When someone asks how vulnerability handling works here, you show the record: what was found, what was fixed, what was dismissed and why.
ELTON supports verification in 4 hours, an early-warning determination in 24, and a full report in 72. That is the technical half Article 23 depends on: is it real, is it malicious, what is affected, what is the exposure.
One measure has to run continuously, one deadline arrives suddenly. The same platform covers both: the measure and the clock, mapped below to what ELTON produces.
Essential entities must manage supplier risk, so hospitals now ask device vendors for vulnerability handling evidence during procurement. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time.
The workflow that feeds Article 23 also feeds the CRA reporting regime and FDA 524B postmarket duties. One verified record, three filings. See EU MDR/CRAEU RED and FDA §524B.
Start with one device. We stand up the twin, run continuous discovery and verification, and give you the record that answers auditors, customers, and the 24 hour clock.