EU Cyber Resilience Act
CRA and medical software
Medical software can be affected by both the Cyber Resilience Act and sector-specific EU rules. Where products are already covered by equivalent requirements under other EU law, overlaps are handled to avoid double regulation — but the cybersecurity evidence still has to exist.
The MDR/IVDR carve-out, precisely
The CRA doesn't create a blanket exemption for “medical software” — the actual carve-out is narrower and product-specific. For example, personal wearables with a health-monitoring purpose are only pulled out of the CRA's important-products list where Regulation (EU) 2017/745 (the Medical Devices Regulation) or (EU) 2017/746 (the In Vitro Diagnostic Regulation) actually applies to them. If your product doesn't meet the definition of a medical device or IVD under those regulations, that carve-out doesn't apply to it, and the CRA's ordinary categories apply as they would to any other connected product.
Two regimes, overlapping evidence
Where MDR or IVDR genuinely applies and already covers a product's cybersecurity requirements, the CRA avoids duplicating those specific obligations — but the two regimes aren't identical, and exactly where the overlap starts and ends is a legal question specific to your product, not a general rule. In practice, the underlying evidence (SBOM, vulnerability handling, technical documentation) is largely reusable across both regimes even where the legal analysis differs.
When in doubt, don't assume the exemption
Because the carve-out depends on whether another regulation genuinely applies to your specific product — not on the product being health-adjacent in a general sense — treat it as a question to answer, not an assumption. If MDR/IVDR doesn't apply, run the CRA classification as you would for any other connected product.
What to focus on
- Confirm whether MDR/IVDR actually applies to your specific product before assuming an exemption.
- Where it does apply, cybersecurity evidence (SBOM, vulnerability handling) is largely reusable across both regimes.
- Where it doesn't, classify and comply as you would for any connected product.
- Document which essential requirements you meet and how.
Frequently asked questions
- Does the CRA apply to medical software?
- It can, and it interacts with existing medical-device rules; where other EU law already imposes equivalent requirements, duplication is avoided. Confirm scope for your specific product.
- If my wearable already complies with MDR, do I still need to worry about the CRA?
- Only to the extent MDR (or IVDR) doesn't already cover the same cybersecurity ground for your specific product. The carve-out is tied to that regulation genuinely applying — not to the product being health-adjacent in general.
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.