Health Canada today publishes its final Guidance Document: Pre-market Requirements for Medical Device Cybersecurity, following public consultation.
Key points
- Manufacturers should build cyber security into device design.
- Cyber security risk management should cover the whole product lifecycle.
- Licence applications should include verification and validation evidence.
- Post-market plans should cover vulnerability monitoring, disclosure and patching.
UK medical device manufacturers applying for Canadian licences should be ready to provide cyber security evidence, including a software bill of materials. The expectations align with UK, EU and US regulators.
Source: Pre-market Requirements for Medical Device Cybersecurity (Health Canada)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.