Cybersecurity Requirements for Connected Devices: A Cross-Market Comparison
FDA, EU, and NMPA are all tightening cybersecurity expectations for connected medical devices. We compare pre-market requirements, post-market obligations, and the emerging consensus on SBOM mandates.
Cybersecurity has transitioned from a best-practice consideration to a hard regulatory requirement across every major device market within the span of approximately three years. The FDA's December 2022 omnibus legislation gave the agency explicit statutory authority to require cybersecurity information in premarket submissions, which it exercised through the final cybersecurity guidance issued in March 2023 and supplemented by refuse-to-accept policy changes that took effect in October 2023. The EU's Medical Device Regulation, read in conjunction with the 2024 Cybersecurity Resilience Act, imposes parallel obligations under the general safety and performance requirements. China's NMPA issued its own cybersecurity technical guidance in mid-2025, completing a regulatory encirclement that now covers the three largest device markets simultaneously.
The Software Bill of Materials requirement has emerged as the most operationally demanding element of the new cybersecurity regime. FDA's guidance requires a complete SBOM enumerating all commercial, open-source, and off-the-shelf software components — including version numbers and known vulnerability status — as a condition of premarket submission acceptance. The EU Cybersecurity Resilience Act imposes a similar obligation for connected devices placing the CE mark after its applicability date. Our analysis of FDA premarket submission deficiency letters since October 2023 shows that SBOM incompleteness is the most frequently cited cybersecurity deficiency, appearing in approximately 38% of cybersecurity-related additional information requests.
Post-market obligations are where the three jurisdictions diverge most meaningfully. FDA requires manufacturers to have a documented coordinated vulnerability disclosure policy and to report exploited vulnerabilities under the existing MDR and malfunction reporting framework. The EU's NIS2 Directive creates separate incident reporting obligations to national cybersecurity authorities that run in parallel to — and do not satisfy — MDR vigilance reporting obligations, creating a potential dual-track reporting burden that regulatory affairs teams need to map explicitly. NMPA's post-market cybersecurity obligations are less prescriptive but include a requirement for ongoing vulnerability monitoring and patch deployment timelines.
The practical implication for device manufacturers is that cybersecurity is no longer a software engineering workstream that intersects with regulatory affairs at submission time. It must be a continuous cross-functional discipline embedded in design controls, supplier qualification, post-market surveillance, and incident response planning. Companies that have invested in dedicated product security teams and tooling for automated SBOM generation and vulnerability tracking are meeting these requirements at significantly lower marginal cost per submission than those managing cybersecurity documentation manually. The SBOM tooling ecosystem has matured considerably in the past eighteen months, and the business case for systematic investment is now straightforward.