Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
US FDA · EU MDR · China NMPA

MEDICAL DEVICE CYBERSECURITY TESTING

Test once. Submit to the world's three largest medical markets.

The Requirement

Cybersecurity Evidence Is Now Mandatory

FDA, EU MDR and China NMPA now all require the same cybersecurity evidence — filed in three different formats.

United States

FDA

A threat model, an SBOM, and proof that vulnerabilities were tested and can be patched.

FD&C Act §524B — final guidance updated June 2025
European Union

MDR

The same evidence, reviewed by a Notified Body against MDCG 2019-16 Rev.1 before CE marking.

MDR Annex I §17 · MDCG 2019-16 Rev.1
China

NMPA

The same testing, restructured into NMPA's own documentation format.

YY/T 1843-2022
Same device, three formats. Test once — then it's just a matter of who signs off.
Four attack surfaces
Surface 01

Medical Device

Blood pressure and physiological monitors, implantable devices.
120/80
Our testing services
  • Device testing
  • SBOM scan
  • Firmware vulnerability scanning
  • Source code & firmware review
Risks
  • Tampered firmware falsifies readings → misdiagnosis
  • Missing SBOM → fails FDA 524B / MDR
Surface 02

Mobile App

Phone or tablet interface paired with the device.
Our testing services
  • Penetration testing
  • SBOM scan
  • App vulnerability scanning
Risks
  • MITM attacks stealing patient data
  • GDPR fines up to €20M / 4% of global turnover
Surface 03

API Gateway

Authentication, traffic control, cloud interface.
Our testing services
  • Vulnerability scanning
  • Penetration testing
Risks
  • Weak authentication → large-scale data breach
  • Failed MDCG 2019-16 review → NB non-conformity (NCR)
  • Unpatched vulnerabilities → exploitation
Surface 04

Cloud & Database

Server, data processing, alert notifications.
Our testing services
  • Server & infrastructure vulnerability scanning
  • Penetration testing
  • Cloud security & access control
Risks
  • Cloud ransomware → hospital-wide shutdown
  • Database breach → GDPR fines up to €20M
  • MDR Vigilance, NIS2 & GDPR Reporting Violations
  • FDA/MDR submission blocked at review
Technical inspection tools & methods
SBOMSoftware Bill of Materials
PTPenetration Testing
VAVulnerability Assessment
FWFirmware Scanning

Seven Stages

1 evidence set. 7 stages. 3 markets.

From gap analysis to post-market maintenance — each stage below maps to the standards a reviewer will actually check it against.

1Gap Analysis 2Secure Dev 3Risk Mgmt 4Testing 5Reg. Docs 6Post-Market 7Training

The compliance pipeline: gap analysis feeds secure development, which feeds risk management and testing, before documentation, post-market maintenance and training close the loop. Click any stage to jump to its detail below.

IEC 81001-5-1 — security lifecycle backboneMDCG 2019-16 Rev.1 — how a Notified Body reviews itISO 13485 — the QMS everything else hangs off
  • IEC 81001-5-1 readiness assessment
  • MDCG 2019-16 Rev.1 mapping
  • QMS baseline against ISO 13485 / FDA QMSR / MDR Annex IX
IEC 62304 — the software-development process standard
  • Cybersecurity activities wired into the IEC 62304 lifecycle, not bolted on after
ISO 14971 — cybersecurity threats assessed as safety risk
  • STRIDE threat modeling, traced from threat to hazard to control
ISO/IEC 17025 — why our reports count as third-party evidenceFDA §524B — testing evidence required at submission
  • SBOM, penetration testing, vulnerability assessment, firmware scanning
  • Covers all four attack surfaces — see the section above
FDA §524BMDR Annex I §17MDCG 2019-16 Rev.1YY/T 1843-2022
  • The submission package behind CE marking and FDA clearance or approval
MDR PMSFDA §524B
  • Vulnerability monitoring and coordinated disclosure (CVD)
  • Patch management and SBOM update obligations
  • PMS / vigilance / PMCF reporting
ISO 13485IEC 81001-5-1
  • MDR workshop and ISO 13485 internal-audit training
  • On-site support during FDA inspections and Notified Body audits

The actual testing scope and capabilities are subject to the latest official scope of accreditation.

Reference

The standards behind each stage

IEC 81001-5-1

Health software security lifecycle — the security activities regulators expect to see wired into development.

Governs stage127

IEC 62304

Medical device software lifecycle processes. Cybersecurity work attaches to this process — it does not replace it.

Governs stage2

ISO 14971

Risk management for medical devices. Cybersecurity threats are assessed here as patient-safety risk.

Governs stage3

FDA §524B

In force since 2023, with final guidance updated June 2025 — requires a threat model, an SBOM, and evidence that vulnerabilities were tested and can be patched.

Governs stage456

MDR Annex I §17

The EU general safety and performance requirement covering software, IT security and the state of the art.

Governs stage5

MDCG 2019-16 Rev.1

The guidance a Notified Body actually reviews your cybersecurity documentation against before CE marking.

Governs stage15

YY/T 1843-2022

China's NMPA standard for medical device network security — the same evidence, restructured into a third format.

Governs stage5

ISO 13485

The quality management system every other record hangs off, and where an audit or inspection starts.

Governs stage17

ISO/IEC 17025

Testing laboratory accreditation — why our test reports count as independent third-party evidence.

Governs stage4

Summaries for orientation, not compliance advice — the binding text is each standard as published.

About Us

One Local Lab, Two EU MDR Notified Bodies, Three Markets submission

Testing is structured once in Taipei to hold up across three-market submission — FDA, MDR and NMPA.

Alliance partner

Secure Vectors Surveillance (SVS) — backed by its parent company's 10+ years in financial-sector cybersecurity — is Applus+ Laboratories' alliance partner and recognized lab in Taiwan. Applus+ Laboratories (est. 1907, top-10 global TIC, 29,000+ employees in 55+ countries) operates two EU Notified Bodies of its own.

Test — Taipei, ISO/IEC 17025 Review — EU Notified Body Submit — FDA · MDR · NMPA
Notifying authority · Slovenia

NB 3121

NOTICE, storitve ugotavljanja skladnosti, d.o.o. (SI)

Notifying authority · Türkiye

NB 2764

Notice Belgelendirme Muayene ve Denetim Hizmetleri A.Ş. (TR)

Testing scope is subject to the latest official scope of accreditation.

Next step

Not sure where to start? Join a training session.

Open
In Person

ISO 13485 Internal Auditor Training

Coming soon

ISO 13485 internal-auditor training for medical-device QMS teams — full agenda announced with the confirmed date.

For: QA · QC · RA · quality leads · regulatory contacts
Reserve A Seat →
Open
In Person

MDR Medical-Device Security Workshop

Coming soon

MDR regulatory analysis and connected-device security in practice

For: R&D · software engineers · product managers · technical leads
Reserve A Seat →
FAQ

Common Questions

Do FDA, EU MDR and NMPA require separate cybersecurity testing?

No. We test once against a unified protocol aligned with FDA Section 524B (Premarket Cybersecurity), EU MDR Annex I §17 (MDCG 2019-16 Rev.1) and NMPA YY/T 1843-2022, then package the same evidence for all three submissions.

What is IEC 81001-5-1 and do I need it?

IEC 81001-5-1 is the health-software security lifecycle standard regulators increasingly expect behind MDR and FDA cybersecurity documentation. It does not replace IEC 62304 — it embeds security activities into your existing development lifecycle, linked to ISO 14971 risk management. Our gap analysis maps exactly where your current process falls short.

Do I need a Notified Body for MDR cybersecurity?

If your device class requires a Notified Body for CE marking, your technical documentation — including cybersecurity per MDCG 2019-16 Rev.1 — is reviewed by that NB. We coordinate submissions via the Applus+ Laboratories Notified Bodies NOTICE (NB 3121, Slovenia) and Notice Belgelendirme (NB 2764, Türkiye), with pre-review before anything is filed.

What happens if my submission is missing an SBOM?

For FDA, a missing or inadequate SBOM is grounds for a refuse-to-accept decision under FDA Section 524B. For MDR, gaps found in NB review become Non-Conformity Reports that stall certification. We generate and manage SBOMs (SPDX / CycloneDX) as part of technical testing, including open-source components.

My device is already on the market — does any of this still apply?

Yes. Post-market obligations run for the device's lifetime: vulnerability monitoring, coordinated vulnerability disclosure, patch management and SBOM updates. Significant changes can also trigger re-review of your documentation. Stage 6 of our service covers exactly this.