Skip to content

INDUSTRY · Medical devices

Medical devices: MDR, IEC 62304 and CRA interaction

Medical devices sit largely outside the CRA by design, but MDR-driven cybersecurity expectations have converged substantially with what the CRA would otherwise require.

LAST REVIEWED

Regulatory picture

The Medical Device Regulation (EU) 2017/745 and the In Vitro Diagnostic Regulation (EU) 2017/746 already impose extensive requirements on connected and software-containing medical devices, including risk management under ISO 14971, software lifecycle processes under IEC 62304, and usability engineering under IEC 62366. Because these regulations already address device-level risk comprehensively, including cybersecurity aspects through MDCG guidance on cybersecurity for medical devices, products fully within MDR or IVDR scope are generally excluded from the CRA. Devices or accessories not falling within the medical device definition, such as general wellness products or hospital IT infrastructure not itself a medical device, can fall within CRA scope instead.

Typical engineering challenges

  • Integrating cybersecurity risk assessment with the ISO 14971 clinical risk management process without creating two disconnected risk registers.
  • Applying IEC 62304 software lifecycle rigour to connected, networked or cloud-integrated device components, not just embedded firmware.
  • Maintaining post-market surveillance and vulnerability monitoring for devices with long clinical service lives, often a decade or more.
  • Coordinating Notified Body technical documentation review, already required under MDR, with the cybersecurity-specific expectations set out in MDCG guidance.
  • Determining device classification boundaries for borderline products, such as clinical decision support software or hospital network equipment that supports but is not itself a medical device.

How CRA interacts with sector rules

For a manufacturer whose product is unambiguously a medical device under MDR or IVDR, the CRA exclusion applies and the relevant cybersecurity obligations flow through MDR's own essential requirements and MDCG guidance rather than the CRA directly. The practical task is less about CRA compliance and more about ensuring the MDR technical file's cybersecurity content — risk management, secure development evidence, vulnerability handling and update processes — meets a standard broadly equivalent to what the CRA would require, since Notified Bodies increasingly expect this depth regardless of formal CRA applicability. Where a manufacturer's portfolio includes accessories or platforms that are not classified as medical devices, those products should be scoped against the CRA independently.

What a typical engagement covers

  • Confirming device classification and the basis for CRA exclusion, documented per product.
  • Integrating cybersecurity risk assessment with ISO 14971 clinical risk management and IEC 62304 software lifecycle documentation.
  • Vulnerability handling and post-market surveillance process design for long-service-life connected devices.
  • Scoping non-device accessories, platforms or wellness products separately against CRA requirements where the medical device exclusion does not apply.

Frequently asked questions

Are all medical devices excluded from the CRA?

Devices genuinely within the scope of the MDR or IVDR, which already address device-level risk including cybersecurity, are generally excluded from the CRA. Products that are not classified as medical devices under those regulations, even if related to healthcare, are not covered by this exclusion and should be assessed against the CRA independently.

What is IEC 62304 and how does it relate to CRA-style secure development?

IEC 62304 sets software lifecycle process requirements for medical device software, covering planning, requirements, architecture, implementation, verification and maintenance. Its rigour around documented lifecycle processes and post-market maintenance closely parallels what the CRA requires for secure development and vulnerability handling, even though the two are legally distinct.

Does MDR require cybersecurity risk assessment?

The MDR's general safety and performance requirements, combined with MDCG guidance on cybersecurity for medical devices, require manufacturers to address cybersecurity risk as part of the overall risk management and technical documentation, even though the MDR does not use CRA terminology directly.

What happens if a product is a borderline case between a medical device and a general product?

Borderline classification should be resolved early and documented, since it determines whether MDR/IVDR or CRA obligations apply, and the two regimes have different technical documentation formats, risk methodologies and conformity assessment routes.