Regulation Comparison Updated: August 2026

Medical Device Regulation (MDR) vs Cyber Resilience Act

Understand the overlap, differences, and compliance synergy between Medical Device Regulation (MDR) and the EU Cyber Resilience Act (CRA).

Core Definition

While Medical Device Regulation (MDR) focuses heavily on device regulation principles, the Cyber Resilience Act specifically targets the cybersecurity of products with digital elements. Compliance with Medical Device Regulation (MDR) provides a strong foundation, but does not completely satisfy CRA requirements. You will still need to ensure CRA-specific mandates like SBOM generation, secure by default configurations, and 24-hour vulnerability reporting to ENISA.

Key Compliance Steps for Medical Device Regulation (MDR)

  1. Map Existing Controls: Identify which Medical Device Regulation (MDR) controls map directly to CRA Annex I requirements (e.g., risk assessments and access control).
  2. Identify CRA Gaps: The CRA has strict product-centric requirements (like 5-year security updates and SBOMs) that Medical Device Regulation (MDR) might not explicitly mandate.
  3. Combine Documentation: Leverage your Medical Device Regulation (MDR) evidence as part of the CRA Technical Documentation package to ease compliance efforts.

How This Plays Out in Practice

Both MDR and CRA expect a documented risk-management file and post-market surveillance process, so your MDR technical file covers much of the same ground.

What to Watch For

MDR-regulated devices are CRA-exempt for the regulated function, but companion apps, cloud dashboards, or accessories outside the MDR's scope usually aren't exempt.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Medical Device Regulation (MDR).

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.