Reference library Four guides · primary sources only
Medical device security testing, guide by guide
Each guide quotes the instrument or the guidance it describes and links the document it was checked against. Nothing here is second-hand.
Index
All guides
- 01 MDR Annex I point 17: the cybersecurity requirement in full Two paragraphs of law create the entire EU device cybersecurity file. Here is the text, what “state of the art” imports, and how MDCG 2019-16 turns it into evidence. Read
- 02 The penetration test report FDA asks for under section 524B Five named elements, an independence question the guidance answers directly, and a requirement to hand over the original third-party report. What a 524B submission expects from a test. Read
- 03 One test campaign, two evidence packs: EU and US together The technical work behind a CE marking file and an FDA submission is largely the same. How to scope, run and report a single campaign so it serves both without being rewritten. Read
- 04 What an EU hospital asks a device vendor for before it buys ENISA published procurement guidelines for hospitals in July 2026. One baseline control asks buyers to confirm independent security validation before deployment. The vendor produces that evidence. Read