EU proposal COM(2025) 1023 introduces CRA-like reporting obligations for cybersecurity of medical devices and IVDs, with reporting via Eudamed to CSIRTs and ENISA.
Key points in brief
- The proposal COM(2025) 1023 introduces new reporting obligations in Article 87a MDR and Article 82a IVDR for actively exploited vulnerabilities and serious security incidents affecting medical devices and in vitro diagnostics.
- Recipients are the member states’ CSIRTs designated as coordinators and the EU Agency for Cybersecurity ENISA — analogous to the reporting regime under the Cyber Resilience Act (Cyber Resilience Act, Article 14).
- Reporting is to be done via Eudamed; CSIRTs and ENISA will be given direct access to the European medical devices database.
- The notification deadline is uniformly 30 days after becoming aware of the event, which deviates markedly from the CRA’s staggered deadlines (24 hours, 72 hours, 14 days).
- Annex I of MDR and IVDR will be amended to explicitly include cybersecurity as part of the essential safety and performance requirements.
- The proposal has not yet been adopted. The public consultation closed in early May 2026; entry into force is earliest expected late 2026 or early 2027.
What happened
The Commission presented proposal COM(2025) 1023 as a targeted simplification responding to persistent criticism of MDR and IVDR since 2024: procedures considered too complex, lack of predictability, disproportionate burdens on SMEs, and bottlenecks at notified bodies. The proposal addresses eight topic areas, from streamlining conformity assessment to international cooperation.
One dedicated section covers the interplay with other Union legislation. It is here that the new cybersecurity reporting obligations are anchored. Recital 44 of the proposal identifies the underlying gap directly: medical devices are excluded from the Cyber Resilience Act; the vigilance systems of MDR and IVDR capture cybersecurity incidents only where they qualify as serious incidents, systematically leaving out incidents without an immediate patient-safety link. The Commission characterises this as a “significant gap in cybersecurity” and closes it via two new articles.
What changes specifically
The central change consists of three elements: a precise definition of what must be reported, a new reporting obligation via Eudamed, and an explicit embedding of cybersecurity in Annex I. The following sections describe the mechanics.
What is an actively exploited vulnerability?
An actively exploited vulnerability is, for the purposes of Article 3(42) of Regulation (EU) 2024/2847 (Cyber Resilience Act), a vulnerability for which sufficient evidence exists that a malicious actor has exploited it in a system without the manufacturer’s consent. The new Article 87a MDR refers directly to this definition.
Today: vigilance based on patient safety, no cybersecurity reporting
Under the current framework, manufacturers report only serious incidents to the competent authorities under Article 87 MDR. “Serious” means death, a serious deterioration in health, or the potential for such outcomes. Cybersecurity incidents that affect a product’s integrity or availability but have no immediate patient-safety impact do not fall under this duty. Because medical devices are expressly excluded from the Cyber Resilience Act, there is currently no mandatory reporting channel for this scenario.
In future: additional cybersecurity obligation via Eudamed
The new Article 87a MDR (parallel: Article 82a IVDR) requires manufacturers to report any of the following events:
- any actively exploited vulnerability present in the product within the meaning of Article 3(42) CRA,
- any serious security incident within the meaning of Article 14(5) CRA that affects the safety of the product.
The notification must be made through the electronic system referred to in Article 92 MDR (i.e., Eudamed) and must at the same time be made accessible to the member states’ CSIRTs designated as coordinators and to ENISA. A vigilance report under Article 87 MDR that also qualifies as an actively exploited vulnerability or a serious security incident will be mirrored to CSIRTs and ENISA. These bodies will be granted access to Eudamed for this purpose.
Comparison of deadlines
| Regime | Deadline for actively exploited vulnerabilities / serious security incidents |
|---|---|
| Cyber Resilience Act, Article 14 | 24-hour early warning, 72-hour update, 14-day final report |
| MDR proposal, Article 87a | 30 days after becoming aware |
The proposal adopts the addressees and definitions from the CRA but not the tiered deadlines. The uniform 30-day deadline is considerably longer than the CRA early warning and reflects the nature of medical devices and the parallel vigilance logic. Organisations that already implement CRA-compliant processes will find the deadline easy to meet; those that only operate under MDR vigilance will need to extend their vulnerability triage.
Cybersecurity in Annex I
Alongside the new reporting duty, the proposal amends Annex I MDR and Annex I IVDR to explicitly mention cybersecurity among the essential safety and performance requirements. Until now, industry derived these requirements from the general safety provisions and the MDCG guidelines on cybersecurity (MDCG guidelines on cybersecurity). The proposal makes the requirement explicit.
Implications for manufacturers
For manufacturers of cybersecurity-relevant products (for example, networked infusion pumps with wireless connectivity, imaging devices with remote maintenance, point-of-care diagnostics with a cloud component, or patient monitors in OT networks) the regulatory logic shifts in three ways.
First the triage becomes more complex. Previously, an incident had to be assessed for its reportability as a serious incident under Article 87 MDR. Going forward, a second assessment dimension is added: is there an actively exploited vulnerability or a serious security incident with a product link? Both assessments are independent and both can (also in parallel) trigger reporting obligations.
Second the stakeholder landscape in incident management changes. Cybersecurity and vigilance responsibilities must align their processes so that a cybersecurity incident without a patient-safety link is nevertheless routed into the reporting path. Organisations that currently separate these roles administratively or organisationally should reconsider the interfaces.
Third Eudamed becomes the common transmission channel for different addressee groups. The CSIRTs designated as coordinators and ENISA are already known in the cybersecurity context from the CRA and the NIS2 directive. With the proposal they gain a formal channel into the medical devices regime for the first time.
The mechanics therefore resemble the CRA reporting system while remaining sector-specific. Manufacturers that produce both CRA-covered products and medical devices (for example, suppliers of components used in both domains) will need to master both reporting paths without conflating them.
Those with CRA-compliant processes will meet the 30-day deadline
The templates describe the reporting process under the Cyber Resilience Act: vulnerability triage, responsibilities, escalation paths and deadline monitoring. Manufacturers producing both medical devices and CRA-covered products need this structure for both reporting streams.
Download templates for free
When does it apply
The proposal is not in force. The public consultation closed on 6 May 2026; trilogue negotiations were expected in mid-2026, and adoption is realistically earliest late 2026 or early 2027. Transitional periods are likely to follow before the new reporting obligations become binding. Until then, MDR and IVDR in their current forms remain applicable — including the existing vulnerability management requirements.