Skip to main content
← All posts·
Regulatory Compliance

CRA Compliance for Medical Device Software: SaMD & Connected Health Devices

Cyber Resilience Act compliance guide for medical device software (SaMD) and connected health devices. Covers CRA-MDR interaction, vulnerability handling, SBOM requirements, secure development lifecycle, and September 2026 reporting obligations.

Luca Berton11 min read

CRA and Medical Devices: The Regulatory Intersection

Medical device software (Software as a Medical Device — SaMD) sits at the intersection of the Cyber Resilience Act (CRA) and the Medical Devices Regulation (MDR 2017/745). The CRA applies to "products with digital elements" — which includes connected medical devices and health software. However, devices already regulated under the MDR may benefit from partial exemption. The interaction is complex and depends on device classification.

Does the CRA Apply to Your Medical Device?

CRA-MDR Interaction

  • MDR-regulated devices (Class IIa, IIb, III): Exempt from CRA cybersecurity requirements IF they meet MDR cybersecurity requirements. However, the CRA's vulnerability reporting obligations still apply.
  • Class I medical devices: May fall under CRA for cybersecurity requirements not covered by MDR
  • Health & wellness software (non-medical): Not MDR-regulated. Fully under CRA. This includes fitness trackers, wellness apps, and connected health devices not classified as medical devices.
  • SaMD (Class IIa+): MDR takes precedence for cybersecurity, but CRA vulnerability reporting and SBOM requirements apply additionally

Key date: September 2026 — CRA vulnerability reporting obligations begin. Manufacturers must report actively exploited vulnerabilities within 24 hours.

CRA Requirements for Health Technology

Vulnerability Handling (CRA Art. 11)

  • Coordinated vulnerability disclosure: Establish a process for receiving and handling vulnerability reports from researchers and users
  • Security updates: Provide timely security patches throughout the product's support period (minimum 5 years or product lifetime)
  • ENISA reporting: Report actively exploited vulnerabilities to ENISA within 24 hours of awareness
  • User notification: Inform users of vulnerabilities and available patches without undue delay

SBOM & Supply Chain (CRA Art. 13)

  • Software Bill of Materials: Machine-readable SBOM listing all components (minimum: top-level dependencies)
  • Third-party component management: Monitor all dependencies for known vulnerabilities
  • Secure development lifecycle: Documented SDLC with security testing at each stage
  • Open-source component governance: Track and assess open-source components for security and licence compliance
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Secure Development for Medical Software

  • Threat modelling: STRIDE analysis for each component — patient safety risks must be elevated above typical IT risk
  • Static analysis: SAST tools integrated into CI/CD pipeline
  • Dependency scanning: Continuous vulnerability monitoring of all software dependencies (Trivy, Snyk)
  • Penetration testing: Annual (minimum) penetration testing by independent testers
  • Fuzzing: Protocol and API fuzzing for connected devices — especially for communication protocols

Implementation Timeline

  1. Now — Q3 2026: Establish vulnerability handling process and ENISA reporting capability (September 2026 deadline)
  2. Q3 2026 — Q4 2026: Implement SBOM generation in CI/CD pipeline. Inventory all third-party components.
  3. 2027: Full CRA compliance — secure development lifecycle, conformity assessment, technical documentation
  4. Ongoing: Continuous vulnerability monitoring, security update delivery, and incident response
🎓 Course with Starweaver

Back-End Infrastructure: Servers, Secure APIs and Data

Build secure back-end infrastructure from the ground up. In collaboration with Starweaver.

Start on Coursera →
CRA
medical devices
SaMD
connected health
cybersecurity
vulnerability management
compliance

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →