Cybersecurity Can Complicate CE Marking Long Before A Device Reaches The Market. For Manuf

Cybersecurity can complicate CE marking long before a device reaches the market. For manufacturers, understanding CE mark medical device cybersecurity requirements becomes especially important when a product includes software, connected interfaces, or remote access features.

The risk is already visible across healthcare environments. Claroty’s 2025 research across 351 healthcare organizations found known exploited vulnerabilities in 99% of them. In 89%, medical systems were also exposed to publicly available exploits alongside insecure internet connectivity.

For manufacturers, the difficult part is often knowing what regulators expect you to prove. Vulnerability testing matters, but so do the records, security decisions, lifecycle controls, and technical evidence behind it.

With EU MDR, MDCG guidance, SBOMs, security standards, and postmarket duties all entering the picture, it is easy to lose sight of what actually belongs in your CE marking preparation. This guide sorts that out.

Understanding Cybersecurity Under EU MDR (2017/745)

EU MDR does not contain one standalone section covering every cybersecurity obligation. Instead, EU MDR software security requirements appear across safety, risk management, software development, technical documentation, user information, and postmarket activities.

Some of the key Annex I requirements include:

GSPR 1 to 4: Establish the safety, performance, benefit-risk, and risk management foundation.
GSPR 14.2: Addresses risks linked to the operating environment, including negative interaction between software and the IT environment.
GSPR 17.1: Requires repeatability, reliability, and performance in line with the device’s intended use.
GSPR 17.2: Covers software lifecycle principles, risk management including information security, verification, validation, and state of the art.
GSPR 17.4: Requires manufacturers to define minimum hardware, IT network, and IT security requirements, including protection against unauthorized access.
Cybersecurity is not limited to privacy. Altered therapy settings, manipulated alarms, corrupted diagnostic information, or device unavailability can affect safety without exposing patient data. Physical interfaces such as USB can also create attack paths even when a device is not directly connected to the internet.

For medical device CE marking, manufacturers should be able to trace applicable GSPRs to cybersecurity requirements, identified risks, controls, verification evidence, residual risks, and the relevant technical documentation. This provides a clearer conformity argument than relying on a penetration testing certificate alone.

Source: https://qualysec.com/ce-mar ...
返回 下一个