MEDICAL DEVICE CYBERSECURITY STANDARDS
Research page and supporting data
As of: 9 October 2026 (UTC)
Editorial identity: The PenTest Index

START HERE

medical-device-cybersecurity-standards.md is the complete page, including valid
YAML frontmatter, the article, source references, dataset blocks, and build and
chart specifications. The editorial audit notes are inside its YAML notes field.
The CSVs supply the full data behind the page and its standards finder. The PNG
and SVG files supply all three charts. Keep the folder structure when unpacking.

This is a dated research snapshot. A check date means the source was checked on
that date; it does not mean that every source was published or last amended then.
Source URLs and source-version details are recorded in the data. Later changes to
live websites do not change this snapshot.

The two ZIP downloads provide a complete page package and a data package. The
data package includes the Markdown page and charts so every reproduction check
can run after extraction. The complete package also includes that ready-to-serve
data ZIP, alongside the same page, data, charts and reproduction files.

REPRODUCE THE CALCULATIONS

Use Python 3; the numerical validator needs only the standard library. Open a
terminal in the unpacked folder, then run:

    python3 reproduce.py

The script recalculates the delivered dataset's totals, percentages, date gaps,
price calculations, and related consistency checks. Read its printed results
and resolve any failed check before relying on a locally edited dataset. The
script finds the data beside itself, so it can also be called from another folder.
If PyYAML is already installed, it also checks the page's YAML frontmatter; PyYAML
is optional, not required for the CSV and numerical checks. These are offline
checks of this fixed snapshot, not a refresh of live prices or regulatory pages.

To rebuild the charts, install Matplotlib if it is not already installed:

    python3 -m pip install matplotlib
    python3 rebuild_charts.py

Chart rebuilding writes the three PNG/SVG pairs under charts/. It uses the
included CSVs, so changing a CSV changes the chart. Preserve an untouched copy
of the original package if you intend to edit the data.

Recalculation checks the supplied data and stated math. It does not re-audit
all source documents, establish which law applies to a particular device, or
recreate vendor research whose underlying observations are not public. Follow
the source URLs to examine the underlying evidence. Source documents, paid
standards and their complete text are not bundled in these files.

CSV INVENTORY — 17 FILES

  fda-recognized-security-standards.csv — 24 selected FDA recognition records,
    representing 22 distinct standards. Separate CVSS versions count as separate
    recognition records. Includes recognition scope, dates and source links.

  fda-recognized-all-records.csv — All 1,738 records in the checked FDA database
    snapshot; the denominator and title-rule selection can be reproduced.

  fda-524b-record-evidence.csv — The separate 31-record "524B" result set,
    preserving record-level scope wording rather than assuming identical notes.

  standards.csv — 31 selected standards and frameworks used by the finder,
    including market mentions, editorial job categories and publisher evidence.

  regulator-standard-matrix-wide.csv — 31 rows with 11 market columns and totals.

  regulator-standard-matrix.csv — The same 341 cells in long form, with the
    specified document sets, sources, evidence locations and cell notes.

  regulators.csv — 11 market summaries, including guidance, named standards,
    penetration-testing wording and limits of each finding.

  regulator-source-manifest.csv — The exact matrix document corpus and the
    primary sources used to verify national-adoption relationships.

  penetration-testing-wording.csv — 32 rows: 15 guidance, scheme or questionnaire
    rows, followed by 17 specified legal/regulatory text rows.

  penetration-testing-search-evidence.csv — Those 17 text checks, with the
    exact versions, languages, search rules, match counts and processed-text
    fingerprints. Text identifiers refer to audited sources, not bundled files.

  fda-cybersecurity-guidance-timeline.csv — 11 guidance events, with dates,
    version status and primary references.

  eu-mdr-harmonised-entries.csv — The 70 numbered entries in the EU MDR
    harmonised list consolidated on 17 June 2026.

  cisa-medical-advisory-records.csv — 191 unique medical-advisory identifiers:
    188 from the pinned official CISA repository and three legacy CISA web
    advisories absent from that repository.

  cisa-medical-advisories-by-year.csv — 11 annual totals, grouped by the year in
    each advisory ID, not the page's latest revision date.

  repeated-statistics-traced.csv — Six repeated claims traced to the sources
    we could locate, with evidence quality and limits recorded.

  publisher-price-evidence.csv — 14 publisher price records with edition, format,
    currency, page-count availability, terms and source evidence.

  exchange-rate-used.csv — The one exchange-rate observation used for the
    estimated USD conversion, with observation and release dates.

OTHER FILES

  calculation-snapshot.json — The calculated results recorded for this snapshot.
  cisa-count-snapshot.json — The pinned CISA repository state and counting rules.
  fda-testing-comparison.json — The bounded comparison of the penetration-testing
    paragraph and its five report elements in three FDA guidance versions.
  penetration-testing-search-method.json — Language-specific search terms,
    normalization rules, scope and limits of the 17-text search.
  reproduce.py — Dataset recalculation and consistency checks.
  rebuild_charts.py — Portable chart generation from the included data.
  charts/chart-1-fda-recognition-timeline.png and .svg
  charts/chart-2-regulators-naming-standards.png and .svg
  charts/chart-3-cisa-medical-advisories.png and .svg

CSV files are UTF-8 with a byte-order mark for spreadsheet compatibility;
Python readers should use encoding="utf-8-sig". Fields with commas, quotes or
line breaks follow standard CSV quoting. Use a CSV parser, not a simple split on
commas. Source dates, check dates, publication dates and price observation dates
serve different purposes and should retain their labels.

METHOD AND SCOPE

FDA selection: apply the case-insensitive title rule security|vulnerabilit to the
1,738-record database snapshot. The result is 24 records and 22 distinct standards.
The same rule produces the same selected set within the separate 31-record
"524B" result. "24" is this compilation's count by this rule, not a count published
by FDA or a list of standards every device must use.

International matrix: compare 31 selected entries against defined official
medical-device guidance, software documents, standards lists and voluntary-scheme
documents across 11 markets. A Yes is a literal name, acronym/full-name match or
verified national adoption in the specified documents. A No is absence from that
corpus only. Neither value decides whether a standard is required or sufficient.
Whole-series mentions do not count for a specific part. General cybersecurity
laws are outside this matrix. The UK column covers Great Britain's designated
standards list, not Northern Ireland's separate regime.

National adoptions are not all identical. China's YY/T 0664-2020 is a modified
adoption of IEC 62304:2015. The 2022 Chinese guideline also names GB/T 22080-2016,
an adoption of ISO/IEC 27001:2013 that was withdrawn on 1 January 2026. That remains
a historical name in the checked guide, not a recommendation to buy the withdrawn
edition. The disclosed IEC 80001-5-1:2021 misprint in that guide is mapped to
IEC 81001-5-1 using its full title. Cell notes preserve these distinctions.

Penetration testing: 10 of the 11 checked market device-guidance sets mention it.
Saudi Arabia's qualifying mention is a question in officially hosted, reprinted
IMDRF material; it is not an SFDA testing recommendation. Guidance, a voluntary
label condition, an association questionnaire and a binding rule are different
kinds of source and are labelled accordingly.

The legal/regulatory term search covers 17 specified texts, including one UK
draft, the original published Brazilian resolutions and the specified Saudi
MDS-REQ1 v6 requirements. It is not a current consolidated census of all laws,
amendments or implementing rules. No searched penetration-testing term occurs
in these 17 texts. That result does not establish an exemption from testing under
broader safety, security or conformity-assessment duties.

Publisher evidence: public catalog pages, previews and official explanations were
read; complete paid standards were not. Keep edition, recognition, withdrawal and
publisher-revision status separate. Prices refer to the specified electronic/PDF
formats and verified terms on the check date. Currency conversion is an estimate
using the recorded rate, not a live quote.

CISA: count each of the 191 advisory IDs once. The first and final years are
partial. An advisory is not a count of attacks, unique vulnerabilities or affected
devices. The pinned repository state and three additional legacy records make the
annual totals reproducible.

Third-party statistics: reported vendor percentages cannot be independently
recomputed without their raw observations, survey responses and methods. The
files identify the original claims and their limits; they do not turn those
figures into representative estimates of the entire medical-device market.

CITATION AND REUSE

Use the page's How to cite block for its complete title and canonical URL.
Credit The PenTest Index by name for its original compilation, counts and charts.
No link is required. Preserve the source line when reusing a chart and keep the
relevant source, version, check date and scope beside a reused number.

Permission to reuse The PenTest Index's contribution does not license third-party
standards, titles, quotations, source documents or datasets beyond their own terms.
Keep their attribution and rights. Do not present a compiled count as an official
FDA, EU or other regulator statistic, or a limited document search as a legal
compliance decision.
