Table 1 Next steps for industry and policymakers
1 | Clarify and extend cybersecurity requirements within existing medical device regulations, such as the EU’s MDR and the US’s FD&C Act, guidance documents by regulatory authorities, and the applicable medical device-specific standards. |
2 | Implement robust security measures from the earliest stages of medical device manufacturing, like adhering to the principle of least authority for secure-by-design systems, integration of Roots of Trust, and deployment of Zero Trust architectures. |
3 | Improve transparency and traceability within complex global medical device supply chains through secure tracking systems and formal verification methods. |
4 | Increase awareness and proactive monitoring of cybersecurity threats throughout the lifecycle of IoMT products. |