COM(2025) 1023 proposes new cybersecurity reporting routes for medical devices and in vitro diagnostic medical devices, but the duties are not yet in force.
What the Commission proposal would change
On 16 December 2025, the European Commission proposed COM(2025) 1023 under procedure 2025/0404(COD). The proposal would insert Article 87a into the MDR and Article 82a into the IVDR, creating sector-specific cybersecurity reporting routes.
The proposal has not been enacted. Current MDR and IVDR vigilance duties continue to apply while the legislative process proceeds.
The proposed reporting triggers
Proposed Article 87a would require a manufacturer to report either:
- an actively exploited vulnerability contained in a device; or
- a severe incident under Article 14(5) of the Cyber Resilience Act that affects device security.
Proposed Article 82a would create the parallel route for in vitro diagnostic medical devices. The proposal does not make every identified, theoretical or responsibly disclosed vulnerability reportable.
A severe incident for this proposed route is not interchangeable with an MDR or IVDR serious incident. The classifications may overlap in a particular case, but they remain distinct regulatory concepts.
Eudamed, deadline and recipients
Under the Commission text, the manufacturer would submit the report through the Eudamed electronic system no later than 30 days after becoming aware of the actively exploited vulnerability or severe incident.
The proposed report would be available simultaneously to the CSIRTs designated as coordinators in the Member States where the device was made available and to ENISA. A vigilance report that also qualifies as an actively exploited vulnerability or severe incident would follow the same recipient rule.
| Regime | Reporting approach |
|---|---|
| Cyber Resilience Act | Its own reporting sequence and definitions apply to products within its scope. |
| Proposed MDR Article 87a and proposed IVDR Article 82a | A report through Eudamed no later than 30 days after the manufacturer becomes aware of the relevant trigger. |
The proposed 30-day period is separate from the proposal's changes to certain existing MDR and IVDR serious-incident vigilance deadlines.
Why the Cyber Resilience Act still matters
The Cyber Resilience Act excludes products with digital elements covered by Regulation (EU) 2017/745 or Regulation (EU) 2017/746 from its scope. COM(2025) 1023 would nevertheless borrow Cyber Resilience Act concepts and recipients while locating the proposed duties within the MDR and IVDR.
The proposal would also add explicit cybersecurity wording to the general safety and performance requirements in Annex I of both regulations. This would not mean that cybersecurity risk management is absent from the current framework. MDCG 2019-16 Rev.1 remains non-binding lifecycle cybersecurity guidance under the current framework.
Practical preparation
Manufacturers and product-security teams can prepare without treating the proposal as current law by:
- mapping product-security triage to MDR or IVDR vigilance processes;
- preserving evidence relevant to whether a vulnerability has been actively exploited or whether an event could meet the proposed severe-incident trigger;
- documenting how product availability by Member State would affect the proposed recipient route; and
- tracking procedure 2025/0404(COD) and the developing legislative text.
Legislative status and monitoring checklist
As of 2 September 2026, the European Parliament procedure record stated that the proposal was awaiting a committee decision, while Council examination was ongoing. The Council's June 2026 progress report said that the extent to which cybersecurity legislation should be reflected in sectoral rules remained under discussion. The final text and timing may therefore change.
Monitor the Commission proposal, Parliament procedure record and Council developments; reassess any preparation work when an agreed or adopted text becomes available; and continue to meet current MDR and IVDR obligations in the meantime.