Medical devices & IoMT · compliance & governance (no device testing)

Medical-Device & IoMT Compliance, MDR, CRA, IEC 80001 and SBOM, legally led

Connected medical devices and IoMT sit under several overlapping cybersecurity regimes. We lead compliance and governance on the legal side: SBOM review, vulnerability-handling process, legal mapping of manufacturer, importer and operator duties, an auditable programme for notified bodies. Hands-on device and firmware testing is carried out by a specialised test partner, not by us.

legally led (Dr. iur., CIPP/E) compliance & governance, no device testing DE · FR · EN
Compliance and governance for connected medical devices and IoMT

For medical-device and IoMT makers, connected-device makers and hospital biomedical/medtech, regulatory-affairs and procurement teams

Legally led Dr. iur. · CIPP/E
MDR / IVDR cybersecurity duties
CRA & IEC 80001 vulnerabilities & network risk
ISO 27001 ISMS integration
TTP escrow source code & keys
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

Converging cybersecurity duties for connected medical devices

Orientation, not legal advice. Several frameworks now apply to connected medical devices and IoMT at the same time, and they overlap. We verify dates and scope case by case.

The cybersecurity requirements of the EU Medical Device Regulation (MDR) and the IVDR are already in force: manufacturers must already demonstrate IT security across the whole lifecycle, including requirements for software, updates and safe operation in networked environments. This is not a future topic but an existing obligation.

IEC 80001 addresses risk management when medical devices are integrated into IT networks, a responsibility shared between the manufacturer and the operating organisation, such as the hospital. On top of this come growing expectations of a Software Bill of Materials (SBOM): notified bodies, operators and procurement increasingly require manufacturers to make the included software components transparent and to track vulnerabilities within them.

The EU Cyber Resilience Act (CRA) adds further vulnerability and reporting duties for products with digital elements, staggered across 2026/2027. The precise dates and exact scope must be verified in each case. For medical devices it has to be clarified to what extent MDR/IVDR prevail over the CRA as lex specialis and how the duties overlap. Resolving exactly this overlap cleanly is the core of our work.

What SIDD delivers, and what we explicitly do not do

We deliver compliance and governance at the documentation and process level. Hands-on testing of the device itself is not part of it.

We review and structure your Software Bill of Materials (SBOM) and map the included components to the regulatory expectations. We design a robust vulnerability-handling process: from intake of a reported vulnerability through assessment and coordinated disclosure to update delivery, as a documented procedure you can present to a notified body.

We produce a legal mapping of duties along the supply chain: what does the manufacturer owe, what the importer, what the operating organisation? We connect MDR/IVDR, IEC 80001 and the CRA duties into a single, auditable compliance programme rather than isolated, one-off records. Where a device embeds AI, we integrate the requirements of the EU AI Act so that medical AI and device compliance stay consistent.

What we explicitly do not do: we perform no hands-on penetration or firmware testing on the medical device and no hands-on device or IoMT testing. We refer and coordinate such testing with a specialised test partner; we then fold the results into your compliance programme and technical documentation. We offer penetration tests and vulnerability scans only for the associated software layers, such as companion apps, portals and cloud backends, not for the device or firmware itself.

Why SIDD for device compliance

For connected medical devices, the depth of the compliance documentation decides whether a notified body, an operator or procurement is convinced. That is exactly where our focus lies.

Notified-body-grade depth

We produce compliance documentation at the depth that stands up to a notified body: a traceable SBOM review, a documented vulnerability-handling process and a clear duty mapping as part of the technical documentation. This speeds up conformity assessments and reduces follow-up queries.

TTP escrow supports device assurance

As a Trusted Third Party we hold source code and cryptographic keys in escrow. This supports device assurance: operators and procurement gain the certainty that critical software and keys remain available even if the manufacturer fails, a solid argument in negotiations and audits.

Legally led

The duty mapping between manufacturer, importer and operator and the relationship of MDR/IVDR to the CRA are legal questions. We lead them with doctorate-level lawyers holding CIPP/E, backed by an in-house technical team. So the interpretation stays solid and not merely technical.

Integration with ISO 27001

We attach the device-compliance programme to an existing or newly built ISO 27001 ISMS. That makes vulnerability management, supplier control and evidence-keeping part of a maintained management system rather than one-off documents.

AI governance integrated

If a device embeds AI, we additionally assess it against the EU AI Act and connect it to our AI Governance Check. This creates a consistent picture across device, cyber and AI compliance, a field that purely technical test providers barely cover.

Multilingual & independent

We work in German, French and English, relevant for Swiss manufacturers, EU parent companies and international supply chains. Because we deliberately hand device testing to specialists and do not sell an in-house SOC, our recommendations stay independent.

Entry: Device & CRA gap assessment

Device compliance programme

on request

Ongoing mandate: from the gap assessment we build an auditable, maintained compliance programme and keep it current across the product lifecycle.

  • Build-out of the technical documentation for conformity assessment
  • Ongoing maintenance of SBOM and the vulnerability-handling process
  • Integration with ISO 27001 / ISMS and supplier control
  • EU AI Act mapping where the device embeds AI
  • TTP escrow for source code and keys as an assurance building block

Related services

Building blocks we connect with device compliance:

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your device-compliance programme, concretely, LexCommand sets the overlapping MDR/IVDR, IEC 80001 and CRA duties side by side as a crosswalk, each statement traced to its source, and reads the staggered 2026/2027 CRA deadlines as of the relevant reference date per product line.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Do you perform device penetration testing?

No. We do not perform hands-on penetration or firmware testing on the medical device. We refer and coordinate such testing with a specialised test partner and fold the results into your compliance programme and technical documentation. Our work is compliance and governance, SBOM review, the vulnerability-handling process and legal duty mapping.

Do you at least test the software around the device?

Yes, for the associated software layers. We offer penetration tests and vulnerability scans for companion apps, portals and cloud backends, not for the device or firmware itself. On-device testing remains the specialised test partner's task.

Do MDR/IVDR prevail over the CRA for medical devices?

That must be verified case by case. For medical devices, MDR/IVDR may prevail over the CRA as lex specialis, and the duties can overlap. We resolve this relationship case by case and consolidate it into a single, auditable programme. CRA dates are staggered across 2026/2027. We verify the precise deadlines per product.

What is an SBOM and why do notified bodies ask for it?

A Software Bill of Materials lists the software components contained in a product. It makes transparent which parts are built in, so vulnerabilities within them can be tracked. Notified bodies, operators and procurement increasingly expect it as part of the cybersecurity evidence. We review your SBOM and map it to the regulatory expectations.

Does this also help the operating organisation, such as the hospital?

Yes. IEC 80001 distributes responsibility between manufacturer and operating organisation when a medical device is integrated into the IT network. We help biomedical, medtech, regulatory-affairs and procurement teams to allocate the duties clearly and to demand the right evidence from the manufacturer, such as an SBOM, a vulnerability process and escrow agreements.

Ready for a Device & CRA gap assessment?

We assess your device compliance per product line, SBOM review, duty mapping and vulnerability-handling process, with a board-ready report. Device testing is coordinated with a specialised test partner.