Blog

Cybersecurity Field Notes for Medical Device Teams.

Notes on FDA, EU MDR and UK cybersecurity expectations for medical devices, written for QA/RA and software leads.

RSS Feed

Blog posts

Alan ParkinsonAlan Parkinson

Is ISO 27001 enough for medical device cybersecurity?

Since the MDR came into force, ISO 27001 has become common advice for medical device manufacturers. It's a sensible place to start, but it isn't the standard your notified body is checking against. Here's how ISO 27001 and IEC 81001-5-1 fit together as two gates with shared evidence.

Alan ParkinsonAlan Parkinson

FDA Cybersecurity Guidance Gets a QMSR Refresh

The FDA published an updated version of its premarket cybersecurity guidance on 3rd February 2026, one day after the QMSR took effect. If you spotted it and felt a familiar twinge of "what's changed now?", the short version: this is a terminology update, not a new set of requirements.

Alan ParkinsonAlan Parkinson

UK medical device cybersecurity: where the rules stand (and don't)

The UK Medical Devices Regulations 2002 contain no explicit cybersecurity requirements. The word doesn't appear once. Yet new postmarket surveillance rules now require reporting security incidents within 15 days and treating security patches as Field Safety Corrective Actions. Where UK medical device cybersecurity stands in 2026, and where it doesn't.

Alan ParkinsonAlan Parkinson

The EU Cyber Resilience Act and medical devices: what's in scope and what isn't

The EU Cyber Resilience Act (CRA) excludes medical devices under MDR. But health apps, wellness products, and companion apps without medical device claims? They're in scope. If you're using the 'launch as wellness first' strategy, cybersecurity regulation still applies from December 2027

Alan ParkinsonAlan Parkinson

Illumina's £9.8M DoJ Settlement: A Cybersecurity Wake-Up Call for Medical Device Manufacturers

The first-of-its-kind cybersecurity settlement shows the DoJ is serious about backing up FDA requirements with real consequences. Here's what QA and RA teams need to know.

Newsletter

Never miss an insight.
Subscribe to The Detective’s Notebook.

Practical cybersecurity regulatory insights and guides for medical device teams. Free, no spam, unsubscribe anytime.