The guidelines help hospitals and healthcare providers integrate cybersecurity objectives across all phases of the procurement life cycle, setting out cybersecurity requirements and the information suppliers must provide. With respect to the GDPR, the guidelines align procurement criteria with security-of-processing obligations for the personal and health data handled by medical devices and IT systems procured by healthcare entities.
Author: ENISA
Status: Adopted / Published
Adoption date: 2026-07-22
Last updated: 19 Aug 2026
Category: Guidance
Subcategory: Official recommendations