Skip to Content

MDR and Cybersecurity overview for Medical Device Software

TEF-Health Service
Consulting

Service Description

The service aims to provide, based on the company’s own description of its medical device software (Software as a Medical Device, SaMD), an overview and understanding of how the product is classified under the EU Medical Device Regulation (MDR) and how the product is handled in relation to applicable cybersecurity requirements. The service gives insight into which risk class the product belongs to under and the regulatory implications and actions that follow from this classification. In parallel, the service reviews how the product addresses relevant cybersecurity requirements for medical device software, and the relations between cyber security and MDR. The work is carried out in close dialogue with the company through interactive workshops. The process starts with a scoping phase, adapted to the maturity of the product, followed by an in‑depth workshop session and regulatory review. These sessions enable joint analysis of the product’s technical characteristics, intended use and risks, with direct expert feedback on MDR classification and cybersecurity aspects. Functional safety and risk analysis will also be discussed.

Deliverables: Workshop notes: documentation from the workshops capturing discussions and conclusions.

Keywords: MDR Cybersecurity Medical device regulation (EU) 2017/745 (MDR) medical device software
Provider Logo

Provider & Contact

Provider Country Sweden
Organisation Website http://ri.se
Billing: per hour
Full Price 130–190 EUR
Reduced Price 0–130 EUR

Operational Details

Service Inputs To perform the service, the company provides relevant information about the product and its regulatory context. The exact inputs are adapted to the maturity of the product and agreed during the workshop.
Service Outputs Provides the company with an understanding of how their medical device software is handled in relation to MDR and cyber security legislation. By addressing classification and cybersecurity aspects early, regulatory uncertainty is reduced and the company is supported in planning further development, certification and secure long‑term use of the product. Recommendations for next steps, supporting further work towards MDR compliance and robust cybersecurity handling, including suggestions for additional support or follow‑up services where relevant.