Cybersecurity of connected medical devices — Regulatory and technical requirements
An unsecured connected medical device is not only vulnerable — it is non-compliant. Since the entry into force of MDR 2017/745 and the MDCG 2019-16 guidance, cybersecurity has become a general safety and performance requirement (GSPR) in its own right. This training gives multidisciplinary teams the regulatory and technical keys to integrate cybersecurity from the design stage, document compliance and maintain the security level throughout the product life cycle.
Audience R&D project managers, software and systems engineers, IT managers, regulatory affairs (RA), quality assurance (QA) — any role involved in the design, market placement or maintenance of a connected medical device or a device integrating a software component.
Learning objectives
- ▸ Identify the cybersecurity requirements applicable to connected medical devices in MDR 2017/745 (Annex I, GSPR), IVDR 2017/746 and the MDCG 2019-16 guidance
- ▸ Map the reference normative framework: IEC 81001-5-1, IEC/TR 60601-4-5, IEC 62304, and their articulation with ISO 14971 and ISO 13485
- ▸ Apply a cybersecurity risk analysis method (TARA) adapted to the context of a medical device manufacturer, distinguishing product threats from IT-system risks
- ▸ Structure the technical deliverables expected by a notified body: SBOM (Software Bill of Materials), vulnerability management plan, patch management procedure, minimum security requirements
- ▸ Define inter-team responsibilities (R&D, RA, QA, IT) and the integration points within the ISO 13485 QMS and the MDR technical documentation
- ▸ Prepare the post-market surveillance elements related to cybersecurity (PSUR, cyber PMCF, incident reporting)
Expected outcomes
- ✓ On completion of the training, the participant can take an active part in a cyber design review, contribute to drafting a product cybersecurity plan and argue MDR compliance before an auditor or a notified body.
Accessibility & entry conditions
Access lead time
Registration up to 10 working days before the start of an open-enrolment session. In-house sessions can be scheduled within 3 to 4 weeks.
Prerequisites
General knowledge of the medical device sector is recommended. No proficiency in programming or in IEC 62304 is required. The training is accessible to RA, QA and IT profiles with no prior experience in software development.
Disability access
Any disability situation can be accommodated. Contact our officer before registration to explore possible adjustments (equipment, materials, pacing). Contact our officer →
Funding
- ·This training is not Qualiopi certified and is not fundable via the OPCOs
- ·Funding from own funds or the company's training budget
Detailed programme
A phone interview or positioning questionnaire is sent ahead of the session to calibrate the level, identify expectations and tailor the case studies to participants' real situations.
- 01
European regulatory framework for the cybersecurity of connected medical devices (1 h 30)
- ·Regulatory definition of a connected medical device within the meaning of the MDR
- ·General safety and performance requirements (GSPR) of MDR Annex I applicable to cybersecurity
- ·MDCG 2019-16 rev.1 guidance: scope, CIA principles (confidentiality, integrity, availability), manufacturer obligations in the pre- and post-market phases
- ·Articulation with IVDR 2017/746 and recent regulatory developments (MDCG 2025-4, CE cybersecurity action plan January 2025)
- 02
Applicable normative corpus: IEC 81001-5-1, IEC/TR 60601-4-5, IEC 62304 (1 h)
- ·Comparative presentation of the three reference standards, their respective scopes and their overlap areas
- ·Articulation with ISO 14971 (risk management) and ISO 13485 (QMS)
- ·Harmonisation status of IEC 81001-5-1 with regard to the MDR
- ·FDA references (2023 guidance) and IMDRF for manufacturers with international ambitions
- 03
Cybersecurity risk analysis: method and deliverables (1 h 30)
- ·Introduction to TARA (Threat Analysis and Risk Assessment) applied to medical devices
- ·Identification of assets, threats and attack scenarios specific to connected devices (Bluetooth, Wi-Fi, USB interfaces, medical cloud)
- ·Cybersecurity risk rating, articulation with the ISO 14971 process
- ·Practical case: building a simplified TARA on a connected medical device scenario
- 04
Technical and documentary requirements for MDR compliance (1 h 30)
- ·SBOM (Software Bill of Materials): content, format, updating
- ·Vulnerability management plan and patch management procedure
- ·Minimum security requirements (authentication, encryption, logging, secure update)
- ·Technical documentation expected by the notified body and its integration into the MDR technical documentation (Annexes II and III)
- 05
Internal organisation, QMS and cyber post-market surveillance (1 h)
- ·Allocation of RA / QA / IT / R&D roles in the cybersecurity process
- ·Integration points within the ISO 13485 QMS (design process, change control, non-conformity management)
- ·Cyber post-market surveillance: PSUR obligations, EUDAMED incident reporting, cyber aspect of PMCF
- ·Software update cases and regulatory requalification
- 06
Wrap-up, questions and answers and individual action plan (30 min)
- ·Review of the key points
- ·Cybersecurity maturity self-assessment grid
- ·Identification of the priority actions to carry out in one's organisation
Assessment of learning
Assessment methods
End-of-day QCM (15 to 20 questions covering modules 1 to 5), supplemented by a short scenario based on an extract of a cyber technical documentation file to be analysed.
Certificate
Training certificate issued by Isofac Group on completion of the training, subject to full participation in the session. This certificate does not constitute a certification recognised by the RNCP or the Specific Directory (RS): it attests to participation and to the assessment of acquired knowledge carried out at the end of the session.
Satisfaction and results
Satisfaction rate: Being measured
First learner survey campaign under way — data published once the statistical threshold is reached.
Training team
Training delivered by the ISOFAC ACADEMY teaching team, made up of consultants specialised in medical devices, quality and regulatory affairs. Depending on the module, the session is led by a specialist with hands-on operational expertise in MDR compliance, ISO 13485 quality management systems, ISO 14971 risk management, clinical evaluation, technical documentation, regulatory audits and CE marking strategy.
Our trainers support manufacturers, distributors, importers, authorised representatives and other economic operators on a daily basis in bringing their medical devices into compliance. See the team's profiles →
Technical resources
In-person
Room equipped at the client site or in a partner centre (Montpellier, Lyon, Paris). Video projector, flipchart, printed materials.
Remote
Zoom (corporate) platform for the virtual classroom. Materials provided in PDF + access to additional resources for 12 months after the session.
Learner equipment
A connected computer with camera and microphone for remote sessions. No software to install.
Materials provided
- ·Training materials in PDF (annotated slides, regulatory memo sheets, MDR / cyber standards correspondence table), provided ahead of the session
- ·Blank TARA template in spreadsheet format
- ·Ready-to-use MDR cybersecurity documentary checklist
Post-course follow-up
Advice line
Hotline included for 30 days after the session for operational questions arising back on the job. Reply within 48 working hours.
Follow-up review
3-month review sent to the sponsor for in-house courses: feedback on the skills put into practice and any residual points.
Open-enrolment price (excl. VAT)
890 €
EU VAT applicable depending on the buyer's status.
In-house price
On request, depending on headcount and location.
Funding
- ·This training is not Qualiopi certified and is not fundable via the OPCOs
- ·Funding from own funds or the company's training budget
Personalised quote within 48 hours.
Would you like to attend this course?
Tell us your preferred format (open-enrolment, in-house or virtual classroom), the number of participants and your schedule. We will get back to you within 48 hours with the next available dates and a firm quote.