測試服務技術測試諮詢與驗證
Industry
EU CRAFDA & MDR支付與金融新聞關於我們
EN繁中
聯絡我們
US FDA · EU MDR · China NMPA

MEDICAL DEVICE CYBERSECURITY TESTING

Test once. Submit to the world's three largest medical markets.

法規要求

資安證據已成強制要求

FDA、EU MDR 與中國 NMPA 如今都要求同一套資安證據——以三種不同格式提交。

United States

FDA

A threat model, an SBOM, and proof that vulnerabilities were tested and can be patched.

FD&C Act §524B — final guidance updated June 2025
European Union

MDR

The same evidence, reviewed by a Notified Body against MDCG 2019-16 Rev.1 before CE marking.

MDR Annex I §17 · MDCG 2019-16 Rev.1
China

NMPA

The same testing, restructured into NMPA's own documentation format.

YY/T 1843-2022
Same device, three formats. Test once — then it's just a matter of who signs off.
Four attack surfaces
Surface 01

Medical Device

Blood pressure and physiological monitors, implantable devices.
120/80
Our testing services
  • Device testing
  • SBOM scan
  • Firmware vulnerability scanning
  • Source code & firmware review
Risks
  • Tampered firmware falsifies readings → misdiagnosis
  • Missing SBOM → fails FDA 524B / MDR
Surface 02

Mobile App

Phone or tablet interface paired with the device.
Our testing services
  • Penetration testing
  • SBOM scan
  • App vulnerability scanning
Risks
  • MITM attacks stealing patient data
  • GDPR fines up to €20M / 4% of global turnover
Surface 03

API Gateway

Authentication, traffic control, cloud interface.
Our testing services
  • Vulnerability scanning
  • Penetration testing
Risks
  • Weak authentication → large-scale data breach
  • Failed MDCG 2019-16 review → NB non-conformity (NCR)
  • Unpatched vulnerabilities → exploitation
Surface 04

Cloud & Database

Server, data processing, alert notifications.
Our testing services
  • Server & infrastructure vulnerability scanning
  • Penetration testing
  • Cloud security & access control
Risks
  • Cloud ransomware → hospital-wide shutdown
  • Database breach → GDPR fines up to €20M
  • MDR Vigilance, NIS2 & GDPR Reporting Violations
  • FDA/MDR submission blocked at review
Technical inspection tools & methods
SBOMSoftware Bill of Materials
PTPenetration Testing
VAVulnerability Assessment
FWFirmware Scanning

七大階段

一套證據,七大階段,三大市場。

從差距分析到上市後維護——下方每個階段都對應審查人員實際查核的標準。

1Gap Analysis 2Secure Dev 3Risk Mgmt 4Testing 5Reg. Docs 6Post-Market 7Training

The compliance pipeline: gap analysis feeds secure development, which feeds risk management and testing, before documentation, post-market maintenance and training close the loop. Click any stage to jump to its detail below.

IEC 81001-5-1 — security lifecycle backboneMDCG 2019-16 Rev.1 — how a Notified Body reviews itISO 13485 — the QMS everything else hangs off
  • IEC 81001-5-1 readiness assessment
  • MDCG 2019-16 Rev.1 mapping
  • QMS baseline against ISO 13485 / FDA QMSR / MDR Annex IX
IEC 62304 — the software-development process standard
  • Cybersecurity activities wired into the IEC 62304 lifecycle, not bolted on after
ISO 14971 — cybersecurity threats assessed as safety risk
  • STRIDE threat modeling, traced from threat to hazard to control
ISO/IEC 17025 — why our reports count as third-party evidenceFDA §524B — testing evidence required at submission
  • SBOM, penetration testing, vulnerability assessment, firmware scanning
  • Covers all four attack surfaces — see the section above
FDA §524BMDR Annex I §17MDCG 2019-16 Rev.1YY/T 1843-2022
  • The submission package behind CE marking and FDA clearance or approval
MDR PMSFDA §524B
  • Vulnerability monitoring and coordinated disclosure (CVD)
  • Patch management and SBOM update obligations
  • PMS / vigilance / PMCF reporting
ISO 13485IEC 81001-5-1
  • MDR workshop and ISO 13485 internal-audit training
  • On-site support during FDA inspections and Notified Body audits

The actual testing scope and capabilities are subject to the latest official scope of accreditation.

Reference

The standards behind each stage

IEC 81001-5-1

Health software security lifecycle — the security activities regulators expect to see wired into development.

Governs stage127

IEC 62304

Medical device software lifecycle processes. Cybersecurity work attaches to this process — it does not replace it.

Governs stage2

ISO 14971

Risk management for medical devices. Cybersecurity threats are assessed here as patient-safety risk.

Governs stage3

FDA §524B

In force since 2023, with final guidance updated June 2025 — requires a threat model, an SBOM, and evidence that vulnerabilities were tested and can be patched.

Governs stage456

MDR Annex I §17

The EU general safety and performance requirement covering software, IT security and the state of the art.

Governs stage5

MDCG 2019-16 Rev.1

The guidance a Notified Body actually reviews your cybersecurity documentation against before CE marking.

Governs stage15

YY/T 1843-2022

China's NMPA standard for medical device network security — the same evidence, restructured into a third format.

Governs stage5

ISO 13485

The quality management system every other record hangs off, and where an audit or inspection starts.

Governs stage17

ISO/IEC 17025

Testing laboratory accreditation — why our test reports count as independent third-party evidence.

Governs stage4

Summaries for orientation, not compliance advice — the binding text is each standard as published.

關於我們

一間在地實驗室,兩家 EU MDR 公告機構,三大市場送件

測試於台北一次完成建構,即可支撐 FDA、MDR 與 NMPA 三大市場送件。

Alliance partner

Secure Vectors Surveillance (SVS) — backed by its parent company's 10+ years in financial-sector cybersecurity — is Applus+ Laboratories' alliance partner and recognized lab in Taiwan. Applus+ Laboratories (est. 1907, top-10 global TIC, 29,000+ employees in 55+ countries) operates two EU Notified Bodies of its own.

Test — Taipei, ISO/IEC 17025 Review — EU Notified Body Submit — FDA · MDR · NMPA
Notifying authority · Slovenia

NB 3121

NOTICE, storitve ugotavljanja skladnosti, d.o.o. (SI)

Notifying authority · Türkiye

NB 2764

Notice Belgelendirme Muayene ve Denetim Hizmetleri A.Ş. (TR)

Testing scope is subject to the latest official scope of accreditation.

Next step

不確定從何著手?歡迎參加培訓課程。

開放報名
實體課程

ISO 13485 內部稽核員培訓

即將公布

針對醫療器材 QMS 團隊的 ISO 13485 內部稽核員培訓 — 完整課程大綱將於確認日期後一併公布。

適合對象:QA · QC · RA · 品質主管 · 法規窗口
預約席位 →
開放報名
實體課程

MDR 醫療器材資安實作坊

即將公布

MDR 法規解析與連網裝置資安實務

適合對象:研發 · 軟體工程師 · 產品經理 · 技術主管
預約席位 →
FAQ

常見問題

FDA、EU MDR 與 NMPA 是否各自要求獨立的資安測試?

不需要。我們依一套整合協定進行一次測試,同時對齊 FDA §524B(上市前資安)、EU MDR Annex I §17(MDCG 2019-16 Rev.1)與 NMPA YY/T 1843-2022,再將同一套證據包裝成三份送件文件。

IEC 81001-5-1 是什麼?我需要它嗎?

IEC 81001-5-1 是針對健康軟體的安全生命週期標準,法規機關在 MDR 與 FDA 資安文件背後日益期待見到這份依據。它並非取代 IEC 62304,而是將安全活動嵌入您現有的開發生命週期,並與 ISO 14971 風險管理連結。我們的差距分析會明確指出您現行流程的不足之處。

MDR 資安是否需要公告機構?

若您的器材類別在 CE 標示上需要公告機構,您的技術文件(包含依 MDCG 2019-16 Rev.1 的資安內容)將由該公告機構審查。我們透過 Applus+ 旗下公告機構 NOTICE(NB 3121,斯洛維尼亞)與 Notice Belgelendirme(NB 2764,土耳其)協調送件,並在正式遞件前先行預審。

若送件缺少 SBOM 會發生什麼事?

就 FDA 而言,缺漏或不完備的 SBOM 可構成依 FDA §524B 作出拒收(refuse-to-accept)決定的理由。就 MDR 而言,公告機構審查中發現的缺口會轉為不符合報告(Non-Conformity Report),拖延認證進度。我們在技術測試中產出並管理 SBOM(SPDX / CycloneDX),包含開放原始碼元件。

我的器材已經上市,這些規定還適用嗎?

適用。上市後義務貫穿器材的整個生命週期:弱點監控、協調弱點揭露、修補管理與 SBOM 更新。重大變更也可能觸發文件重新審查。我們服務的第六階段正是涵蓋這些工作。