Why cybersecurity has moved to the top of NB review checklists

Three years ago, cybersecurity documentation was often an afterthought in SaMD technical files — a single paragraph in the risk management file acknowledging that software could be vulnerable to attack. Today, Notified Bodies — see our NB selection guide — have dedicated cybersecurity reviewers and structured questionnaires based on MDCG 2019-16. Technical files that treated cybersecurity as a checkbox routinely receive major non-conformities.

The regulatory pressure comes from multiple directions simultaneously. EU MDR GSPR 17.2 explicitly requires manufacturers to address information security. MDCG 2019-16 defines what that means in practice. The EU AI Act (from August 2026) adds cybersecurity governance requirements for AI systems. And IEC 62304's 2015 amendment embedded cybersecurity into the software lifecycle standard. For connected SaMD in 2026, cybersecurity is not optional — it is a first-class certification requirement.

MDCG 2019-16: the framework

MDCG 2019-16 structures cybersecurity for medical devices around a pre-market and post-market framework, consistent with how other medical device safety requirements are structured.

Pre-market: security by design

Security by design means that cybersecurity requirements are defined and implemented during development — not added as a compliance exercise before submission. MDCG 2019-16 expects manufacturers to:

Security risk management

The security risk management process runs parallel to the ISO 14971 safety risk management process and should be documented in the Security Risk Management File. For each identified threat:

Security testing

MDCG 2019-16 expects manufacturers to conduct security testing appropriate to the device's connectivity and risk profile. For most connected SaMD, this means:

Post-market cybersecurity obligations

Cybersecurity does not stop at certification. MDCG 2019-16 requires ongoing post-market cybersecurity management, which must be integrated into your QMS and post-market surveillance process:

EU AI Act cybersecurity obligations (from August 2026)

For AI-powered SaMD, the EU AI Act introduces additional cybersecurity-related obligations from August 2026 that partially overlap with MDCG 2019-16. Specifically, the AI Act requires high-risk AI systems (which include most Class IIa+ AI SaMD) to be designed with resilience against adversarial attacks — attempts to manipulate model outputs by crafting adversarial inputs.

For AI medical software, this means the security risk management must explicitly address adversarial machine learning attacks: data poisoning (manipulation of training data), model inversion (reconstructing training data from model outputs), and adversarial examples (inputs designed to fool the model). While MDCG 2019-16 does not explicitly address these, the AI Act's requirements mean they must now be included in the security risk assessment for AI SaMD.

Connecting cybersecurity to your ISO 14971 risk file: MDCG 2019-16 expects cybersecurity risks that could affect patient safety to be reflected in your ISO 14971 risk management file — not just in a separate security document. A cybersecurity vulnerability that could cause the software to produce incorrect diagnoses is a patient safety risk and must appear in both documents.
Official sources & references