Industry Guide Updated: August 2026

Does the Cyber Resilience Act Apply to Medical Devices?

Learn if the EU CRA applies to Medical Devices, what the core compliance requirements are, and how to start preparing your engineering teams automatically.

Core Definition

undefined. Exempt if regulated under MDR/IVDR, otherwise covered. A connected insulin pump regulated under the MDR is CRA-exempt for the device itself, but a companion mobile app not covered by the MDR can fall back under the CRA. If you do not fall into an explicit exemption, your Medical Devices will be subjected to the CRA's strict requirements.

Key Compliance Steps for Medical Devices

  1. Determine Classification: Check if your Medical Devices falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
  2. Perform Risk Assessment: Map out the attack surface for your It Depends and document the mitigations for the "secure by design" requirement.
  3. Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
  4. Generate an SBOM: Ensure all dependencies used in your Medical Devices are documented in a machine-readable Software Bill of Materials.
  5. Avoid the Common Pitfall: Assuming 'we have a CE mark' automatically means CRA-exempt — the exemption depends on which regulation issued that mark.

How This Plays Out in Practice

A connected insulin pump regulated under the MDR is CRA-exempt for the device itself, but a companion mobile app not covered by the MDR can fall back under the CRA.

What to Watch For

Assuming 'we have a CE mark' automatically means CRA-exempt — the exemption depends on which regulation issued that mark.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Medical Devices.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.