The December 2025 MDR and IVDR revision proposal is moving through Brussels. Most teams skimmed the classification changes and moved on. The cyber sections are the part worth reading twice.
GSPRs get explicit design requirements for data integrity, confidentiality and availability, including software updates and network connectivity. Annex VIII adjusts so decision support software stops getting reflexively up-classified. And there’s a new well established technology concept: software with a long history of safe clinical use and consistent evidence can take a streamlined conformity route.
The teeth: report actively exploited vulnerabilities and severe security incidents within 30 days, through Eudamed, shared with cybersecurity authorities at the same time. CRA logic, MDR badge.
EU device cyber is moving from guidance you interpret to obligations with clocks. Build the Eudamed workflow now. Argue about classification later.