Global Bio: MDR Transition Countdown — SV Surveillance and Applus+ Build a One-Stop MDR & FDA Security Compliance Channel for Taiwan's Medical Devices
On June 29, Secure Vectors Surveillance and Applus+ Laboratories formally signed their alliance: Taiwanese medical device makers can now complete the full path from QMS and security testing to EU Notified Body review locally.

Coverage by Global Bio | By Wu Kang-wei
On June 29, Secure Vectors Surveillance Inc. (SV Surveillance) and the Spanish testing and certification group Applus+ Laboratories announced their formal alliance, making SV Surveillance Applus+ Laboratories' strategic partner and recognized security laboratory in Taiwan. Taiwanese medical device manufacturers can now complete the entire journey locally — from management systems and security testing to technical documentation review and EU Notified Body (NB) assessment. Beyond providing the most effective laboratory services locally, the goal is process integration: helping clients complete their compliance path more efficiently while cutting the costs of cross-border communication, duplicate testing and repeated submissions. Final conformity-assessment decisions remain the independent responsibility of the Notified Body.
Applus+ Laboratories' dual Notified Bodies (NB 2764 & NB 3121) and SV Surveillance's ISO 17025-accredited security lab
Medical devices are going connected. Once a product adds Wi-Fi, Bluetooth and cloud functions, market-entry requirements multiply and the regulatory bar rises. Josep Prat, General Manager for China at Applus+ Laboratories, notes that the group holds dual Notified Bodies — NB 2764 (Türkiye) and NB 3121 (Slovenia) — giving Taiwanese manufacturers a more direct, diversified route to export certification.
Vincent Huang, CEO of SV Surveillance, adds that Taiwan's device-certification industry has a structural problem: there is no shortage of laboratories — what is scarce is an efficient path that connects straight through to the MDR and the US FDA. Security testing has grown stricter by the year; manufacturers used to find a Notified Body overseas and a security lab locally on their own, with language, time zones and document formats out of sync between the two tracks — certification routinely dragged on for twelve to eighteen months.
SV Surveillance's security laboratory grew out of its parent, Secure Vectors Information Technologies Inc., which has specialized in payment security certification since 2010. Because the financial industry uses broader information technology and offers attackers stronger incentives, the intensity and frequency of attacks there exceed the medical field — SV Surveillance carries that depth of experience into medical device security testing.
SV Surveillance brings local security-testing strength; Applus+ Laboratories brings not only dual EU Notified Bodies but also two Common Criteria (CC) laboratories — the highest tier of security testing. Both sides describe the partnership as complementary in service footprint and testing technology, and what the alliance is built to open is exactly this last mile.
Connected-device security: IEC 81001-5-1 and MDCG 2019-16 raise the entry bar sharply
Josep Prat explains that once a medical device adds Wi-Fi, BLE or cloud functions, it must satisfy — on top of MDR and FDA safety review — both IEC 81001-5-1 (the health software security lifecycle standard) and the MDCG 2019-16 cybersecurity guidance. Both regulator-recognized frameworks put security inside the whole development lifecycle. RED 3.3 and EN 18031 legally exclude medical devices (Delegated Reg 2022/30 Art. 2), but the technical thinking is shared — manufacturers are advised to reference the framework at the design stage and prepare for the future CRA harmonized standards.
These standards trip up Taiwanese manufacturers regularly. Vincent Huang identifies four interlocking pitfalls: insufficient testing lacking third-party independence; document silos without a unified traceability matrix; ISO 13485 quality systems not integrated with IEC 81001-5-1 security risk management; and the continuous monitoring and compliance burden of post-market surveillance (PMS). EU security legislation accelerated from 2022 and enforcement has tightened sharply since 2025, leaving small and mid-size manufacturers under enormous pressure.
For Class IIa/IIb/III software devices, the MDR mandates no specific technical standard, but industry demonstrates “state of the art” with a set of benchmark standards: ISO 13485 quality management, ISO 14971 risk management, IEC 62304 software lifecycle, IEC 81001-5-1 security lifecycle and MDCG 2019-16 review guidance. These used to sit with different providers; through the SV Surveillance–Applus+ collaboration, all five workstreams are checked within one integrated testing process — catching problems before submission instead of being sent back for rework by the NB or regulator.
Additional-information requests and rejections are now routine — and the certification clock is ticking
The direct consequence of the higher bar is that rejections have become routine. Vincent Huang cites a recent case: a device-to-phone Bluetooth pairing that had always passed was rejected by the FDA, which now sees the technique as a high-risk attack vector requiring added safeguards and testing. Since Section 524B took effect, the FDA holds the statutory right to Refuse to Accept (RTA) 510(k) submissions over insufficient cybersecurity documentation; cases of additional-information requests — or suspended review — over incomplete SBOMs, missing penetration tests and unclear threat-model boundaries keep surfacing.
The clock is ticking too: in the EU's MDD-to-MDR transition, high-risk products must be certified by December 31, 2027, and low/medium-risk products by December 31, 2028. With only about fifty MDR Notified Bodies worldwide, capacity is limited; current MDR projects average 12–18 months, depending on document readiness and how fast gaps are fixed.
Vincent Huang points out that the risks differ in kind: in the EU, Notified Bodies are congested and manufacturers can only queue; the US FDA simply refuses to accept filings with incomplete security documents, writing off the prior investment. Neither side forgives mistakes. As for the CRA — medical devices are excluded not as a free pass, but because MDR Annex I §17 made security a mandatory threshold back in 2021, an equivalent-regulation principle.
Three-stage collaboration plus two accelerators: a one-stop compliance solution
The partners' answer is a three-stage collaboration model centered on process integration and information symmetry. Work starts at the design stage: SV Surveillance runs the IEC 81001-5-1 security-management gap assessment while Applus+ Laboratories reviews the MDR technical documentation in parallel, and the two produce a joint action list — so manufacturers know what to strengthen before submission, rather than paying multiplied rework costs after an additional-information request.
The time savings come from parallel processing. In the traditional path, documents go in first; only after the NB reports security gaps does the manufacturer engage a lab, then resubmit and wait again — a rejection unwinds much of the earlier investment. The new model overlaps the sequence: security testing and technical documentation review proceed together, reports feed straight into the technical file, and neither side idles — the main reason project timelines compress by more than thirty percent.
The deliverable changes too: instead of two separate reports, manufacturers receive a single evidence package satisfying both MDR and FDA — one submission file for both Europe and the US. One SBOM, one penetration test report and one threat model map simultaneously to the EU MDR, the US FDA (Section 524B and UL 2900-2-1) and China's NMPA (YY/T 1843); with format adjustments, the same package can also support submissions in Japan, Korea and beyond.
Two accelerators complete the picture. SV Surveillance's ISO 17025-accredited reports meet the technical requirements for test reports recognized by the FDA and EU Notified Bodies, serving as core submission evidence and sparing repeat testing. And Applus+ Laboratories' hundreds of medical device certification projects, combined with localized service, mean R&D teams can fix findings immediately, with no time-zone lag.
The CE mark is only the starting point — post-market surveillance (PMS) is in scope as well. SV Surveillance will help Taiwanese manufacturers build reporting SOPs and monitor the security posture and incident handling of products already on the market, so certificates aren't withdrawn at a later audit.
From MDR compliance to Asia-Pacific security compliance hub
Beyond medical devices, the partners lay out a three-horizon roadmap for Taiwan: near term, deliver the first MDR cases and a compliance toolkit by the end of 2026; mid term, fully localize laboratory capacity so the Taiwan lab serves local clients faster, extending security testing to IoT, CRA, electric vehicles, drones and other industries where Taiwan is strong; long term, leverage Taiwan's complete supply chain and engineering talent density to become the Asia-Pacific hub for security compliance services.
In support, the partners are rolling out MDR security workshops, ISO 13485 and IEC 81001-5-1 internal auditor training, and first-hand EU CRA analysis. “Taiwan used to wait passively for overseas certification,” says Vincent Huang. “Now European and US compliance can be completed locally in one pass — that is the real meaning of this alliance.”
The SV Surveillance website offers an MDR compliance self-check and related training courses — learn more at www.securevectorlab.com. For training sessions and registration, visit the CRA, MDR & ISO 13485 training page; for an in-depth look at the CRA rules, see CRA Countdown: Compliance Guide for Taiwan ICT Manufacturers.
Original coverage: Global Bio (GBI Monthly)