
A Five-Year Head Start: Practical Lessons from Introducing Cybersecurity in Medical Devices
The CRA is on the doorstep. Medical devices were regulated some five years earlier. Practical lessons from that introduction phase.
Topic
When & Where
Details
Format:
it-sa insights
Language:
German
Session description
Speaker: Robert Feld
Medical device manufacturers had to align their product development and processes with binding cybersecurity requirements roughly five years earlier than many other industries. With the Cyber Resilience Act, a great many manufacturers now face the same transition. This talk is a field report from the introduction phase: what worked, what cost unnecessary time, and where the effort actually turned out to sit.
It starts with a gap analysis – and the key question is not what is missing, but what is already there: which standards are already applied, which processes and records can be reused? Added to this is something both worlds share: when the legislation takes effect, the harmonised standards are not yet available in a valid form. I address how to ...

