The 28th IMDRF Management Committee met in Sapporo in mid-September 2025, chaired by Japan PMDA, and approved a new work item for the cybersecurity working group: guidance on cybersecurity controls and testing considerations, extending the existing N60, N70 and N73 family.
IMDRF documents are not law anywhere. They are the draft national regulators quietly converge on, so watching this working group is watching your future submission requirements take shape. The committee also pushed a Predetermined Change Control Plan draft into a 60-day consultation, the mechanism that lets you pre-authorize software and security updates instead of resubmitting for each one.
Security testing evidence, penetration and fuzzing and verification, is what the new work item points at. If you are not generating that evidence in a form a regulator will accept, the harmonized guidance will eventually make you.