Blogs Why MedTech Manufacturers Should Pay Attention to the Cyber Resilience Act

Why MedTech Manufacturers Should Pay Attention to the Cyber Resilience Act

September 8, 2026

René Zölfl is a Global Industry Advisor for MedTech at PTC, where he works with leading medical device companies to drive digital transformation and regulatory‑compliant innovation across the product lifecycle. He supports organizations in becoming more agile, connected, and resilient while meeting the demands of global regulatory frameworks.

René built and scaled PTC’s MedTech practice in Germany and brings deep expertise in how digital technologies can create measurable value across R&D, manufacturing, quality, and service. His work bridges technology, business strategy, and regulation, helping MedTech manufacturers translate digitalization into real operational and compliance outcomes.

As Chair of the PTC MedTech Customer Advisory Board, René leads strategic engagements and executive workshops with PTC’s most important MedTech customers, shaping discussions around industry trends, regulatory expectations, and future business models.

He actively contributes to the MDIC Center for Manufacturing Innovation & Quality. René joined PTC in 2010 after serving in consulting, portfolio management, and marketing roles at Siemens.

See All From This Author

This blog was written in collaboration with Maxime Hernandez, Program Manager of Cybersecurity Services, TÜV SÜD.

Cybersecurity has become a board-level issue for MedTech manufacturers. As products become more connected and software-dependent, regulators are placing greater scrutiny on how organizations manage cybersecurity risk throughout the device lifecycle. While the EU Cyber Resilience Act (CRA) does not apply directly to medical devices regulated under the MDR or IVDR, it reflects a broader shift in regulatory expectations that MedTech organizations cannot afford to ignore.

Medical devices and in vitro diagnostic medical devices regulated under the EU MDR or IVDR are excluded from the CRA. However, MedTech portfolios often include connected software, wellness technologies, hospital infrastructure, or other digital products that may still fall within the regulation's scope. While regulated medical devices already face cybersecurity requirements under frameworks such as FDA guidance and the MDR/IVDR, the CRA reinforces a broader industry trend: cybersecurity must be managed throughout the device lifecycle rather than addressed as a standalone compliance exercise.

For the Non-medical wellness devices (general fitness trackers, appointment engagement platforms, Hospital IoT infrastructure) in scope of the CRA compliance with all the requirement is needed for 2027-12.

Why this is becoming harder to manage 

Cybersecurity is becoming essential to market access. Premarket submissions increasingly need a clear cybersecurity plan, threat modeling, and a software bill of materials (SBOM). In Europe, manufacturers also need to manage cybersecurity risk across the device lifecycle. That creates a important change for engineering, quality, and regulatory teams: instead of gathering (sometimes creating) evidence via manual searches, spreadsheets, colleagues’ knowledge, there is a need to establish a framework where each member of the product's team contribute to cybersecurity compliance since it needs to be by design.

Most manufacturers know cybersecurity matters. The harder part is proving control across fragmented systems: threats in one place, requirements in another, test evidence somewhere else, and vulnerability data often tracked manually. When a new vulnerability is disclosed, teams need to know quickly which products are affected, what evidence exists, and what action is required. 

What cyber resilience looks like in practice 

In practice, cyber resilience depends on traceability. Organizations need to understand which products, software components, requirements, tests, and released versions are affected when a vulnerability is discovered. Without that visibility, responding to cybersecurity events becomes slower, more expensive, and more difficult to defend during audits or regulatory reviews.

With the EU CRA, a manufacturer must be able to trace a threat to the risk it creates the security objective(s) that addresses it, the test that verifies it, and the release where the control was delivered. During the design phase of the product, including cybersecurity is primordial to avoid doing a re-design; also the design team must be aware of cybersecurity constraint that might impact some functionalities.

Traceability does more than support an audit. It helps teams understand the impact of change before it reaches the field. When requirements, risks, tests, releases, and vulnerabilities stay connected, teams can respond faster and with more confidence.

Connected traceability also helps teams understand the impact of a design change before it reaches the field, reducing compliance risk and supporting more informed engineering decisions.

Where to start 

Manufacturers do not need to solve everything at once. A useful first step is to assess where the most important gap is and start with that. 

  • Do we have a cybersecurity risk assessment framework in place?
  • Can we generate and maintain a machine-readable SBOM?
  • When a vulnerability is discovered, can we identify affected products and versions quickly?
  • Are triage, scoring, assessment, and patching activities performed within defined timelines?
  • Are these activities documented through formal "Vulnerability Handling" processes, and are responsible people identified? Are responsibilities clearly assigned and understood across teams?

Is there a cybersecurity risk assessment framework in place? is the SBOM in a machine-readable format created and when a vulnerability is discovered, can the triage, scoring, assessment, patching done according to a defined timeframe? Are these documented by processes (called “Vulnerability handling”) and are the responsible persons identified? The answers usually show where to focus first. 

Cybersecurity in MedTech will keep getting more demanding as devices become more connected and regulatory expectations continue to rise. Manufacturers that build security into the lifecycle and keep their evidence connected will be better prepared to meet compliance expectations and maintain trust with patients, providers, and regulators. 

Regardless of whether a specific product falls under the CRA, the regulation highlights a broader reality: cybersecurity can no longer be treated as a separate compliance activity managed at the end of development.

Organizations that treat cybersecurity, traceability, and change management as connected disciplines will be better positioned to meet evolving regulatory expectations while maintaining trust with patients, providers, and regulators.

Topics Closed-Loop Quality Connected Devices Digital Thread Quality Management Regulatory Compliance Requirements Management Risk & Test Management Software Development
Up Next

Medical device cybersecurity standards guide

Learn how leading MedTech manufacturers are building cybersecurity into the product lifecycle to improve traceability, accelerate vulnerability response, and support regulatory compliance. Read the Blog
René Zölfl

René Zölfl is a Global Industry Advisor for MedTech at PTC, where he works with leading medical device companies to drive digital transformation and regulatory‑compliant innovation across the product lifecycle. He supports organizations in becoming more agile, connected, and resilient while meeting the demands of global regulatory frameworks.

René built and scaled PTC’s MedTech practice in Germany and brings deep expertise in how digital technologies can create measurable value across R&D, manufacturing, quality, and service. His work bridges technology, business strategy, and regulation, helping MedTech manufacturers translate digitalization into real operational and compliance outcomes.

As Chair of the PTC MedTech Customer Advisory Board, René leads strategic engagements and executive workshops with PTC’s most important MedTech customers, shaping discussions around industry trends, regulatory expectations, and future business models.

He actively contributes to the MDIC Center for Manufacturing Innovation & Quality. René joined PTC in 2010 after serving in consulting, portfolio management, and marketing roles at Siemens.

Continue Reading