Don’t do SECURITY. Do business SECURELY.

Australia’s TGA publishes medical device cyber security guidance

Australia’s TGA issues guidance on meeting the Essential Principles for medical device cyber security across the product lifecycle.

The Therapeutic Goods Administration (TGA) publishes its Medical device cyber security guidance for industry, setting out how manufacturers can meet the Essential Principles for devices supplied in Australia.

Key points

  • Cyber security risks must be minimised across the whole device lifecycle, from design to decommissioning.
  • Manufacturers are expected to apply risk management and secure design practices.
  • Post-market monitoring, vulnerability management and patching are expected.
  • Companion guidance helps healthcare providers and users manage device cyber risks.

UK medical device manufacturers selling into Australia need documented cyber security risk management as part of their conformity evidence. The expectations align closely with UK MHRA and EU MDR requirements.

Source: Medical device cyber security guidance for industry (TGA)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights