The Commission published its targeted MDR and IVDR revision in mid-December 2025. Cybersecurity becomes an integral part of the Annex I general safety and performance requirements: data integrity, confidentiality, availability, secure updates, network connectivity.

Then the teeth. New Articles 87a MDR and 82a IVDR require reporting of actively exploited vulnerabilities and severe security incidents to CSIRTs and ENISA, channelled through Eudamed alongside vigilance, using CRA definitions on a lex specialis basis. That is CRA-style dual-track reporting arriving inside device regulation: safety vigilance in one lane, cyber vulnerability and incident notifications in the other. The Commission is targeting applicability around 2027 after Parliament and Council negotiate.

Plan for two reporting pipelines and for cybersecurity checked as a core GSPR at conformity assessment. The direction is fixed even if the final dates move.