Beyond MDR and IVDR: The EU Regulatory Landscape for Medical Devices in 2026

8/31/20269 min read

blue and yellow star flag
blue and yellow star flag

AI, cybersecurity, health data, product liability and other EU rules that medical device manufacturers should not overlook

Last week, I had the opportunity to participate in a HealthTech Finland cybersecurity session. The discussions there motivated me to take a broader look at the current EU regulatory landscape for medical devices and medical device software.

For a medical device manufacturer, compliance does not end with the MDR or IVDR.

A connected medical device may simultaneously raise questions under data protection, cybersecurity, artificial intelligence, radio equipment, environmental, health-data and product-liability legislation. Medical device software may have an even wider regulatory footprint.

The practical challenge is therefore no longer simply “Does my product comply with MDR or IVDR?” but also:

Which other EU and national legislation applies to the company, the device or the device family and where is that assessment documented?

1. MDR and IVDR remain the foundation

Regulation (EU) 2017/745 on medical devices (MDR) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) remain the primary product legislation.

They cover areas such as classification, conformity assessment, quality management, risk management, clinical or performance evaluation, technical documentation, labelling, UDI, post-market surveillance and vigilance.

Two developments are particularly important in 2026.

The first four EUDAMED modules, Actor registration, UDI/Device registration, Notified Bodies & Certificates and Market Surveillance, became mandatory on 28 May 2026.

Article 10a MDR/IVDR also requires manufacturers to assess whether an interruption or discontinuation of supply could cause serious harm or a risk of serious harm to patients or public health. The Commission published revised guidance on this obligation in April 2026.

There is also an important proposed revision of MDR and IVDR. The Commission presented its simplification proposal in December 2025, and the legislative process is still ongoing. Manufacturers should monitor it, but proposed changes should not yet be treated as applicable requirements.

Manufacturer consideration: Keep the MDR/IVDR regulatory strategy, EUDAMED registrations, Article 10a process and applicable implementing legislation under active review.

Sources:

[European Commission – Medical Devices Regulations]
(https://health.ec.europa.eu/medical-devices-new-regulations/overview_en)

[European Commission – EUDAMED]
(https://health.ec.europa.eu/medical-devices-eudamed/overview_en)

2. Artificial Intelligence Act

Regulation (EU) 2024/1689, the AI Act adds another regulatory layer where a medical device or IVD contains artificial intelligence.

Under the current AI Act, an AI system can be classified as high-risk where it is itself a product or a safety component of a product covered by legislation listed in Annex I and the product requires third-party conformity assessment. MDR and IVDR are currently included in that Annex.

This means that many MDR/IVDR devices requiring a notified body may also become high-risk AI systems. In contrast, many self-certified MDR Class I and non-sterile IVDR Class A devices will not meet this NB assessment, although other AI Act provisions may still apply.

Following the 2026 amendment to the AI Act, the main high-risk requirements for systems classified through Annex I product legislation are scheduled to apply from 2 August 2028.

However, there is a significant complication. The Commission's pending MDR/IVDR simplification proposal would move MDR and IVDR from Section A to Section B of AI Act Annex I, substantially reducing regulatory overlap between the AI Act and medical device legislation. This is only a proposal at present.

Manufacturer consideration: Determine whether the product contains an AI system, identify the manufacturer's AI Act role and document whether the system meets the current high-risk criteria. Monitor the MDR/IVDR revision before building assumptions about the final 2028 regulatory model.

Source:

[Artificial Intelligence Act – EUR-Lex]
(https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng)

3. Cybersecurity: more than one regulation

There is no single EU “medical device cybersecurity regulation”.

Cybersecurity requirements may arise from several different legal layers.

MDR and IVDR already require appropriate protection for software and programmable systems throughout the device lifecycle. For a connected device, cybersecurity therefore remains part of device safety, risk management and state of the art.

NIS2, implemented through national legislation, addresses cybersecurity mainly at organisation level rather than through CE marking of an individual device. Manufacturers of medical devices and IVDs are explicitly included in the manufacturing sector covered by NIS2, subject to the applicable size, sector and criticality criteria.

In Finland, FIMEA supervises the medical-device and IVD sectors under the Finnish Cybersecurity Act and maintains the relevant NIS2 entity information.

Manufacturer consideration: Keep product cybersecurity under MDR/IVDR separate from organisational cybersecurity obligations under NIS2. Determine and document whether the company itself falls within national NIS2 scope.

Sources:

[NIS2 Directive – EUR-Lex]
(https://eur-lex.europa.eu/eli/dir/2022/2555/oj)

[FIMEA – NIS2 information]
(https://asiointi.fimea.fi/en-US/nis2asiointi/tietoa-palvelusta/)

4. Cyber Resilience Act – usually not for the medical device itself

The Cyber Resilience Act (EU) 2024/2847 does not apply to products to which the MDR or IVDR applies.

However, this exclusion does not necessarily cover all digital components used in a medical device. The CRA expressly covers software and hardware components that are placed separately on the EU market.

A third-party software library, operating system, middleware component or other software component, potentially managed as SOUP under IEC 62304, may therefore itself fall within the CRA if it is supplied separately and is not an MDR/IVDR product.

The medical device manufacturer still remains responsible under MDR/IVDR for the cybersecurity and lifecycle management of the component when it is incorporated into the device.

Manufacturer consideration: Identify third-party software and hardware components used in the device. Determine whether they are separately supplied products subject to the CRA, and ensure that supplier controls, vulnerability management and software lifecycle processes address the resulting dependencies.

Source:

[Cyber Resilience Act – EUR-Lex]

(https://eur-lex.europa.eu/eli/reg/2024/2847/2024-11-20/eng)

5. GDPR

The General Data Protection Regulation (EU) 2016/679 applies whenever personal data are processed within its scope. Health data require particular attention because they belong to special categories of personal data.

For medical-device software, GDPR requirements may affect architecture and development decisions from the beginning. Data protection by design and by default is an explicit GDPR requirement, and higher-risk processing may require a Data Protection Impact Assessment.

MDR or IVDR compliance does not replace GDPR compliance.

Manufacturer consideration: Define whether the manufacturer acts as controller, processor or neither in each intended use scenario, identify the lawful basis for processing, minimise personal data and integrate privacy requirements into system architecture, cybersecurity and supplier controls.

Source:

[General Data Protection Regulation – EUR-Lex]

(https://eur-lex.europa.eu/eli/reg/2016/679/oj)

6. European Health Data Space

Regulation (EU) 2025/327 – the European Health Data Space, EHDS introduces a new framework for electronic health data.

The EHDS is particularly important for medical devices and IVDs where the manufacturer claims interoperability with EHR systems. In such cases, relevant interoperability and logging requirements can apply in addition to MDR or IVDR.

The EHDS applies in stages. The Regulation generally applies from March 2027, while important product and interoperability provisions phase in mainly from 2029 and 2031.

Manufacturer consideration: For software exchanging data with electronic health record systems, document whether EHDS interoperability is claimed and start mapping the future requirements well before the applicable date.

Source:

[European Health Data Space Regulation – EUR-Lex]
(https://eur-lex.europa.eu/eli/reg/2025/327/oj/)

7. Data Act

The Data Act (EU) 2023/2854 is easy to overlook because it is not medical-device-specific.

However, the Regulation expressly recognises medical and health devices as possible connected products. It creates user rights concerning data generated by connected products and obligations concerning access to and use of that data.

The Data Act has applied generally since September 2025. Importantly, the design obligation requiring connected-product data to be made accessible applies to products placed on the market after 12 September 2026.

That date is now very close.

Manufacturer consideration: For connected devices, identify what product and related-service data are generated, who can access them, how access is technically implemented and whether contracts and product architecture comply with the Data Act without compromising GDPR, cybersecurity or medical-device safety.

Source:

[Data Act – EUR-Lex]

(https://eur-lex.europa.eu/eli/reg/2023/2854)

8. New Product Liability Directive

Directive (EU) 2024/2853 on liability for defective products modernises EU product liability rules for the digital era.

Most importantly for medical-device software manufacturers, software is explicitly considered a product, regardless of whether it is embedded, downloaded, cloud-based or provided as software-as-a-service.

The new regime applies to products placed on the market or put into service after 9 December 2026, following national implementation of the Directive.

Software updates, cybersecurity and changes made while a product remains under the manufacturer's control may become relevant when defectiveness and liability are assessed.

Manufacturer consideration: Product-liability risk should be considered throughout software maintenance, cybersecurity, update management and post-market processes, not only at initial CE marking.

Source:

[Product Liability Directive – EUR-Lex]
(https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng)

9. Radio Equipment Directive

A medical device containing Wi-Fi, Bluetooth, cellular radio or another intentional radio transmitter may also fall within the Radio Equipment Directive 2014/53/EU, RED.

RED addresses, among other things, radio-spectrum use, safety and electromagnetic compatibility. Cybersecurity-related requirements have also been activated for certain categories of connected radio equipment.

Manufacturer consideration: Do not assume that MDR conformity alone covers the radio function. Assess RED applicability separately and include the applicable legislation in the EU Declaration of Conformity where required.

Source:

[Radio Equipment Directive – European Commission]
(https://single-market-economy.ec.europa.eu/sectors/electrical-and-electronic-engineering-industries-eei/radio-equipment-directive-red_en)

10. Machinery legislation

Some medical equipment also meets the definition of machinery.

The Machinery Regulation (EU) 2023/1230 will apply from 20 January 2027. It provides that where risks are already covered by more specific Union harmonisation legislation, the Machinery Regulation does not apply to those risks to the extent that the specific legislation covers them.

Manufacturer consideration: For devices containing powered mechanical movement or machinery functions, document the interaction between MDR and machinery legislation and identify any additional requirements not already covered by the MDR.

Source:

[Machinery Regulation – EUR-Lex]
(https://eur-lex.europa.eu/eli/reg/2023/1230/oj)

11. Environmental, chemical and battery legislation

Physical medical devices may also be affected by legislation that has little to do with the clinical intended purpose.

RoHS Directive 2011/65/EU restricts hazardous substances in electrical and electronic equipment and specifically includes medical devices and IVDs, subject to exemptions.

WEEE Directive 2012/19/EU creates obligations concerning waste electrical and electronic equipment. Medical devices are generally within its open scope, although specific exclusions exist, for example for certain devices expected to be infective before end of life.

Battery Regulation (EU) 2023/1542 applies to batteries incorporated into products and contains requirements concerning removability, replaceability, information and the battery lifecycle. Certain specific medical equipment has derogations.

REACH Regulation (EC) 1907/2006 can also affect substances, mixtures and articles used in medical devices.

Manufacturer consideration: Maintain a material and environmental compliance assessment covering the actual product configuration and supply chain. Do not treat CE marking under MDR/IVDR as evidence that these requirements have automatically been addressed.

Sources:

[RoHS – EUR-Lex]
(https://eur-lex.europa.eu/eli/dir/2011/65/oj)

[WEEE – EUR-Lex]
(https://eur-lex.europa.eu/eli/dir/2012/19/oj)

[Battery Regulation – EUR-Lex]
(https://eur-lex.europa.eu/eli/reg/2023/1542/oj)

[REACH – EUR-Lex]
(https://eur-lex.europa.eu/eli/reg/2006/1907/oj)

12. Finland: FIMEA and national requirements

EU Regulations do not eliminate national medical-device legislation.

In Finland, the Medical Devices Act 719/2021 supplements MDR and IVDR. Among other matters, it establishes national language requirements and FIMEA's supervisory powers.

Information necessary for the safe use of a device must be provided in Finnish and Swedish. The manufacturer determines through risk analysis which information is necessary for safe use. For devices intended for patients or other consumers, the instructions for use and other information necessary for safe use must be available in both languages.

FIMEA also supervises applicable NIS2 obligations for medical-device and IVD manufacturers in Finland.

Manufacturer consideration: EU regulatory assessments should always be supplemented with applicable national requirements in every Member State where the product or company activities create national obligations.

Sources:

[Finnish Medical Devices Act 719/2021 – Finlex]
(https://finlex.fi/fi/lainsaadanto/2021/719)

[FIMEA – NIS2 information]
(https://asiointi.fimea.fi/en-US/nis2asiointi/tietoa-palvelusta/)

How should manufacturers manage this regulatory landscape?

The answer is not to create twelve disconnected compliance projects.

A medical device manufacturer should maintain a company-level Regulatory Requirements Register, Regulatory Requirements Matrix or equivalent controlled QMS document identifying the EU and national legislation that may apply to the company and its products.

For each requirement, the company should document:

- whether it is applicable
- why it is applicable
- which company process or function is responsible for compliance
- how compliance is achieved
- what evidence demonstrates compliance and
- where a requirement has been assessed as not applicable, the justification for that conclusion.

This company-level assessment should then be reflected in the product-specific regulatory documentation.

For each device or device family, the manufacturer should determine which legislation applies and document how it affects the product, its development, technical documentation, labelling, cybersecurity, data processing, post-market activities and other relevant obligations.

In simple terms:

First map the regulatory landscape at company level. Then demonstrate applicability and compliance at device or device-family level.

A useful first screening for a new device might therefore ask:

- Does it contain AI?
- Does it process personal or health data?
- Does it exchange information with an EHR system?
- Is it a connected product generating data?
- Does it contain Wi-Fi, Bluetooth or another radio?
- Does the company fall within NIS2 scope?
- Does it contain batteries or regulated substances?
- Is it electrical or electronic equipment?
- Does it include machinery functions?
- Which national requirements apply in the markets where it is sold?

The regulatory answer will probably not be identical for every product, even within the same company.

And that is precisely why the applicability assessment should be a controlled part of the quality management system rather than something reconstructed from memory every time a new project starts.

All in all, there is a lot going on in the regulatory landscape for medical devices and IVDs. Identifying the applicable requirements, keeping the regulatory framework up to date and translating it into practical product and QMS actions is not always straightforward.

This is where experienced regulatory support can help.

Quality and Regulatory Consulting

Expert services in medical device regulation and quality compliance.

contact information

Karkinen Consulting Oy, Helsinki, Finland
Business ID: 3103786-9
info@karkinen.com

© 2026. All rights reserved.