GxPlex

Citation graph

62 citations between tracked documents. An edge means one document's retained text contained a form another document is published under, on the date shown, with the words it was read from.

contextual mapping — not a regulatory applicability determination The policy, stated once

An edge cannot tell the manner of a citation: a document naming another in order to exclude it produces the same entry as one adopting it wholesale.

Citation arcs between the 37 documents that carry one An arc diagram of the documents that carry at least one citation. They sit along a baseline in alphabetical order within their authority group, groups alphabetical. Each arc is one citation. The table below carries the same information with quotes and sources. Cybersecurity and Infrastructure Security Agency European Medicines Agency European Parliament and Council IEC / ISA ISO/IEC International Council for Harmonisation National Institute of Standards and Technology Pharmaceutical Inspection Co-operation Scheme US Food and Drug Administration US National Institute of Standards and Technology CISA CPG 2.0 names IEC 62443 as “IEC 62443” CISA CPG 2.0 names NIST CSF 2.0 as “NIST Cybersecurity Framework” CISA CPG 2.0 names NIST CSF 2.0 as “CSF 2.0” CISA CPG 2.0 names NIST SP 800-82 as “NIST SP 800-82” CISA CPG 2.0 names NIST SP 800-82 as “SP 800-82” Annex 11 concept paper names ISO/IEC 27001 as “ISO 27001” EMA data quality framework names ISO 13485 as “ISO 13485” EU AI Act names EU IVDR as “Regulation (EU) 2017/746” EU AI Act names EU MDR as “Regulation (EU) 2017/745” EU Cyber Resilience Act names EU AI Act as “Regulation (EU) 2024/1689” EU Cyber Resilience Act names EU IVDR as “Regulation (EU) 2017/746” EU Cyber Resilience Act names EU MDR as “Regulation (EU) 2017/745” EU Cyber Resilience Act names EU NIS2 Directive as “Directive (EU) 2022/2555” EU Cyber Resilience Act names EU NIS2 Directive as “NIS 2” EU IVDR names EU MDR as “Regulation (EU) 2017/745” EU MDR names EU IVDR as “Regulation (EU) 2017/746” EU NIS2 Directive names EU IVDR as “Regulation (EU) 2017/746” EU NIS2 Directive names EU MDR as “Regulation (EU) 2017/745” Regulation (EU) 2026/1744 names EU AI Act as “Regulation (EU) 2024/1689” Regulation (EU) 2026/1744 names EU Cyber Resilience Act as “Regulation (EU) 2024/2847” Regulation (EU) 2026/1744 names EU Cyber Resilience Act as “Cyber Resilience Act” Regulation (EU) 2026/1744 names EU IVDR as “Regulation (EU) 2017/746” Regulation (EU) 2026/1744 names EU MDR as “Regulation (EU) 2017/745” ICH Q14 names ICH Q12 as “ICH Q12” ICH Q14 names ICH Q2(R2) as “ICH Q2(R2)” ICH Q2(R2) names ICH Q14 as “ICH Q14” ICH Q9(R1) names ISO 14971 as “ISO 14971” ICH Q9(R1) names ICH Q12 as “ICH Q12” NISTIR 8183 names IEC 62443 as “IEC 62443” NISTIR 8183 names NIST SP 800-82 as “NIST SP 800-82” PIC/S Annex 11 names PIC/S GMP Guide as “PIC/S GMP Guide” PIC/S PI 011 names PIC/S GMP Guide as “PIC/S GMP Guide” PIC/S PI 011 names PIC/S PI 041 as “Good Practices for Data Management” PIC/S PI 011 names PIC/S PI 041 as “PI 041” PIC/S PI 041 names PIC/S GMP Guide as “PIC/S GMP Guide” 21 CFR Part 820 (QMSR) names ISO 13485 as “ISO 13485” FDA AI guidance names ISO/IEC 22989 as “ISO/IEC 22989” FDA AI guidance names 21 CFR Part 211 as “21 CFR Part 211” FDA AI guidance names FDA PCCP as “Predetermined Change Control Plan” FDA device cybersecurity names IEC 62443 as “ISA-62443” FDA device cybersecurity names ISO 13485 as “ISO 13485” FDA device cybersecurity names ISO 14971 as “ISO 14971” FDA device cybersecurity names NIST CSF 2.0 as “NIST Cybersecurity Framework” FDA device cybersecurity names NIST SP 800-82 as “NIST SP 800-82” FDA device cybersecurity (2026) names IEC 62443 as “ISA-62443” FDA device cybersecurity (2026) names ISO 13485 as “ISO 13485” FDA device cybersecurity (2026) names ISO 14971 as “ISO 14971” FDA device cybersecurity (2026) names NIST CSF 2.0 as “NIST Cybersecurity Framework” FDA device cybersecurity (2026) names NIST SP 800-82 as “NIST SP 800-82” FDA electronic systems (clinical) names 21 CFR Part 11 as “21 CFR Part 11” FDA Part 11 scope names ISO 14971 as “ISO 14971” FDA Part 11 scope names 21 CFR Part 11 as “Electronic Records; Electronic Signatures” FDA Part 11 scope names 21 CFR Part 11 as “21 CFR Part 11” FDA Part 11 scope names 21 CFR Part 211 as “21 CFR Part 211” NIST AI 600-1 names NIST AI RMF as “AI RMF 1.0” NIST AI 600-1 names NIST AI RMF as “AI RMF” NIST AI RMF names ISO/IEC 22989 as “ISO/IEC 22989” NIST AI RMF names NIST AI RMF Playbook as “NIST AI RMF Playbook” NIST AI RMF names NIST CSF 2.0 as “NIST Cybersecurity Framework” NIST AI RMF Playbook names NIST AI RMF as “NIST AI RMF” NIST AI RMF Playbook names NIST AI RMF as “AI RMF 1.0” NIST AI RMF Playbook names NIST AI RMF as “AI RMF” CISA CPG 2.0 Annex 11 concept paper EMA data quality framework EU AI Act EU Cyber Resilience Act EU IVDR EU MDR EU NIS2 Directive Regulation (EU) 2026/1744 IEC 62443 ISO 13485 ISO 14971 ISO/IEC 22989 ISO/IEC 27001 ICH Q12 ICH Q14 ICH Q2(R2) ICH Q9(R1) NISTIR 8183 PIC/S Annex 11 PIC/S GMP Guide PIC/S PI 011 PIC/S PI 041 21 CFR Part 11 21 CFR Part 211 21 CFR Part 820 (QMSR) FDA AI guidance FDA device cybersecurity FDA device cybersecurity (2026) FDA electronic systems (clinical) FDA Part 11 scope FDA PCCP NIST AI 600-1 NIST AI RMF NIST AI RMF Playbook NIST CSF 2.0 NIST SP 800-82
A view of the table below, which is the record. 62 citations met the evidence standard; the remaining 95 of 132 tracked entries have none that did. Documents are placed alphabetically within authority groups — position and arc size carry no meaning, and no layout on this page is computed from how connected a document is.

Every citation, with its evidence

62 citation(s), each quoted and dated
Citing document Names As Quoted from the citing text Read
CISA CPG 2.0 IEC 62443 IEC 62443 or framework, such as NIST CSF or ISA/IEC 62443, and all CPGs map to source (opens in new tab) cisa.gov
CISA CPG 2.0 NIST CSF 2.0 NIST Cybersecurity Framework to The goal’s reference to the NIST Cybersecurity Framework version 2.0. dispose of the source (opens in new tab) cisa.gov
CISA CPG 2.0 NIST CSF 2.0 CSF 2.0 implemented. achieving the security outcome. NIST CSF 2.0 REFERENCE(S) COST IMPACT EASE OF IMPLEMENTATION source (opens in new tab) cisa.gov
CISA CPG 2.0 NIST SP 800-82 NIST SP 800-82 permitted to access the resources. From: NIST SP 800-82 Rev. 3 Administrative Domain: A source (opens in new tab) cisa.gov
CISA CPG 2.0 NIST SP 800-82 SP 800-82 PM-29 Cyber Storm National Cybersecurity Exercise SP 800-82 Rev 3: PS-2 Executive Cybersecurity Leadership source (opens in new tab) cisa.gov
Annex 11 concept paper ISO/IEC 27001 ISO 27001 important topics. In line with ISO 27001, a section on IT security should 109 source (opens in new tab) ema.europa.eu
EMA data quality framework ISO 13485 ISO 13485 from medical devices or diagnostic products: ISO 13485 Quality System Regulation (QSR) • Data source (opens in new tab) ema.europa.eu
EU AI Act EU IVDR Regulation (EU) 2017/746 5.5.2017, p. 1 ). ( 22 ) Regulation (EU) 2017/746 of the European Parliament source (opens in new tab) eur-lex.europa.eu
EU AI Act EU MDR Regulation (EU) 2017/745 apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing that certain changes should source (opens in new tab) eur-lex.europa.eu
EU Cyber Resilience Act EU AI Act Regulation (EU) 2024/1689 to Article 6 of Regulation (EU) 2024/1689 of the European Parliament and of the source (opens in new tab) eur-lex.europa.eu
EU Cyber Resilience Act EU IVDR Regulation (EU) 2017/746 down rules on medical devices and Regulation (EU) 2017/746 of the European Parliament and source (opens in new tab) eur-lex.europa.eu
EU Cyber Resilience Act EU MDR Regulation (EU) 2017/745 for such products. (25) Regulation (EU) 2017/745 of the European Parliament and of the source (opens in new tab) eur-lex.europa.eu
EU Cyber Resilience Act EU NIS2 Directive Directive (EU) 2022/2555 Council ( 3 ) and Directive (EU) 2022/2555 of the European Parliament and of source (opens in new tab) eur-lex.europa.eu
EU Cyber Resilience Act EU NIS2 Directive NIS 2 repealing Directive (EU) 2016/1148 (NIS 2 Directive) ( OJ L 333, 27.12.2022, p. 80 source (opens in new tab) eur-lex.europa.eu
EU IVDR EU MDR Regulation (EU) 2017/745 in this Regulation and in Regulation (EU) 2017/745 of the European Parliament and of source (opens in new tab) eur-lex.europa.eu
EU MDR EU IVDR Regulation (EU) 2017/746 by this Regulation and by Regulation (EU) 2017/746 of the European Parliament and of source (opens in new tab) eur-lex.europa.eu
EU NIS2 Directive EU IVDR Regulation (EU) 2017/746 Article 2, point (2), of Regulation (EU) 2017/746 of the European Parliament and of source (opens in new tab) eur-lex.europa.eu
EU NIS2 Directive EU MDR Regulation (EU) 2017/745 2, point (1), of Regulation (EU) 2017/745 of the European Parliament and of the source (opens in new tab) eur-lex.europa.eu
Regulation (EU) 2026/1744 EU AI Act Regulation (EU) 2024/1689 4 ) , Whereas: (1) Regulation (EU) 2024/1689 of the European Parliament and of source (opens in new tab) eur-lex.europa.eu
Regulation (EU) 2026/1744 EU Cyber Resilience Act Regulation (EU) 2024/2847 (EU) 2024/1689 and Regulation (EU) 2024/2847 of the European Parliament and of the Council source (opens in new tab) eur-lex.europa.eu
Regulation (EU) 2026/1744 EU Cyber Resilience Act Cyber Resilience Act and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) ( OJ L, 2024/2847, source (opens in new tab) eur-lex.europa.eu
Regulation (EU) 2026/1744 EU IVDR Regulation (EU) 2017/746 ). ( 14 ) Regulation (EU) 2017/746 of the European Parliament and of the source (opens in new tab) eur-lex.europa.eu
Regulation (EU) 2026/1744 EU MDR Regulation (EU) 2017/745 ( 13 ) Regulation (EU) 2017/745 of the European Parliament and of the Council source (opens in new tab) eur-lex.europa.eu
ICH Q14 ICH Q12 ICH Q12 into effect* 14 June 2024* * For ICH Q12 concepts within ICH Q14, refer source (opens in new tab) ich.org
ICH Q14 ICH Q2(R2) ICH Q2(R2) Range and Working Range) with ICH Q2(R2), Minor Format corrections to Table 1 and source (opens in new tab) ich.org
ICH Q2(R2) ICH Q14 ICH Q14 the analytical procedure lifecycle, as described within ICH Q14 Analytical Procedure Development. ICH Q2(R2) source (opens in new tab) ich.org
ICH Q9(R1) ISO 14971 ISO 14971 studies) – Application guide. 10. ISO 14971:2019 – Medical devices - Application of risk source (opens in new tab) ich.org
ICH Q9(R1) ICH Q12 ICH Q12 (Chemical Entities and Biotechnological/Biological Entities). 4. ICH Q12 Technical and Regulatory Considerations for Pharmaceutical source (opens in new tab) ich.org
NISTIR 8183 IEC 62443 IEC 62443 general informative references of ISA/IEC 62443 [5] from the Framework are also listed in source (opens in new tab) csrc.nist.gov
NISTIR 8183 NIST SP 800-82 NIST SP 800-82 Additional input came from NIST SP 800-82, Rev. 2, both in section 6.2 (Guidance source (opens in new tab) csrc.nist.gov
PIC/S Annex 11 PIC/S GMP Guide PIC/S GMP Guide for harmonisation has been the PIC/S GMP Guide. Originally, the latter derives from the source (opens in new tab) picscheme.org
PIC/S PI 011 PIC/S GMP Guide PIC/S GMP Guide for harmonisation has been the PIC/S GMP Guide. Originally, the latter derives from the source (opens in new tab) picscheme.org
PIC/S PI 011 PIC/S PI 041 Good Practices for Data Management for Inspectors Guidance documents PIC/S Good Practices for Data Management and Integrity in Regulated source (opens in new tab) picscheme.org
PIC/S PI 011 PIC/S PI 041 PI 041 and Integrity in Regulated GMP/GDP Environments PI 041-1 Documents for Inspectors Guidance documents PIC/S source (opens in new tab) picscheme.org
PIC/S PI 041 PIC/S GMP Guide PIC/S GMP Guide for harmonisation has been the PIC/S GMP Guide. Originally, the latter derives from the source (opens in new tab) picscheme.org
21 CFR Part 820 (QMSR) ISO 13485 ISO 13485 the extent that any clauses of ISO 13485 (incorporated by reference, see § 820.7 source (opens in new tab) ecfr.gov
FDA AI guidance ISO/IEC 22989 ISO/IEC 22989 transition probabilities in a Markov model (adapted from ISO/IEC 22989:2022 Information Technology - Artificial source (opens in new tab) fda.gov
FDA AI guidance 21 CFR Part 211 21 CFR Part 211 of the FD&C Act and 21 CFR part 211). For example, with regard to source (opens in new tab) fda.gov
FDA AI guidance FDA PCCP Predetermined Change Control Plan FDA staff Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled source (opens in new tab) fda.gov
FDA device cybersecurity IEC 62443 ISA-62443 Health IT Joint Security Plan version 2 (JSP2). 27ANSI/ISA-62443-4-1 Security for industrial automation and source (opens in new tab) fda.gov
FDA device cybersecurity ISO 13485 ISO 13485 incorporates by reference the 2016 edition of ISO 13485.12 By incorporating ISO 13485 by source (opens in new tab) fda.gov
FDA device cybersecurity ISO 14971 ISO 14971 safety risk management as described in ISO 14971. The distinction in the performance of source (opens in new tab) fda.gov
FDA device cybersecurity NIST CSF 2.0 NIST Cybersecurity Framework generally referred to as the NIST Cybersecurity Framework or NIST CSF.25 FDA recommends that source (opens in new tab) fda.gov
FDA device cybersecurity NIST SP 800-82 NIST SP 800-82 Life Cycle Processes. 102Definition is cited from NIST SP 800-82 Guide to Operational Technology source (opens in new tab) fda.gov
FDA device cybersecurity (2026) IEC 62443 ISA-62443 Health IT Joint Security Plan version 2 (JSP2). 27ANSI/ISA-62443-4-1 Security for industrial automation and source (opens in new tab) fda.gov
FDA device cybersecurity (2026) ISO 13485 ISO 13485 incorporates by reference the 2016 edition of ISO 13485.12 By incorporating ISO 13485 by source (opens in new tab) fda.gov
FDA device cybersecurity (2026) ISO 14971 ISO 14971 safety risk management as described in ISO 14971. The distinction in the performance of source (opens in new tab) fda.gov
FDA device cybersecurity (2026) NIST CSF 2.0 NIST Cybersecurity Framework generally referred to as the NIST Cybersecurity Framework or NIST CSF.25 FDA recommends that source (opens in new tab) fda.gov
FDA device cybersecurity (2026) NIST SP 800-82 NIST SP 800-82 Life Cycle Processes. 102Definition is cited from NIST SP 800-82 Guide to Operational Technology source (opens in new tab) fda.gov
FDA electronic systems (clinical) 21 CFR Part 11 21 CFR Part 11 regarding the requirements under 21 CFR part 11 (part 11), pursuant to which FDA source (opens in new tab) fda.gov
FDA Part 11 scope ISO 14971 ISO 14971 for information security management (ISO/IEC, 2000) ISO 14971:2002 Medical Devices- Application of risk management source (opens in new tab) fda.gov
FDA Part 11 scope 21 CFR Part 11 Electronic Records; Electronic Signatures of the Code of Federal Regulations; Electronic Records; Electronic Signatures (21 CFR Part 11). source (opens in new tab) fda.gov
FDA Part 11 scope 21 CFR Part 11 21 CFR Part 11 Records; Electronic Signatures (21 CFR Part 11). 2 This document provides guidance to persons source (opens in new tab) fda.gov
FDA Part 11 scope 21 CFR Part 211 21 CFR Part 211 Good Manufacturing Practice regulations (21 CFR Part 211), the Quality System regulation (21 CFR source (opens in new tab) fda.gov
NIST AI 600-1 NIST AI RMF AI RMF 1.0 for the AI Risk Management Framework (AI RMF 1.0) for Generative AI,1 pursuant to source (opens in new tab) nvlpubs.nist.gov
NIST AI 600-1 NIST AI RMF AI RMF and Trustworthy Artificial Intelligence.2 The AI RMF was released in January 2023, and is source (opens in new tab) nvlpubs.nist.gov
NIST AI RMF ISO/IEC 22989 ISO/IEC 22989 tooperatewithvaryinglevelsofautonomy(Adaptedfrom: OECDRecommendation onAI:2019; ISO/IEC 22989:2022). Whiletherearemyriadstandardsandbestpracticestohelporganizationsmitigatetherisks source (opens in new tab) nist.gov
NIST AI RMF NIST AI RMF Playbook NIST AI RMF Playbook to mapping AI risks are described in the NIST AI RMF Playbook. Table 2liststhe source (opens in new tab) nist.gov
NIST AI RMF NIST CSF 2.0 NIST Cybersecurity Framework use may be said to be secure. Guidelines in the NIST Cybersecurity Framework and source (opens in new tab) nist.gov
NIST AI RMF Playbook NIST AI RMF NIST AI RMF be updated after the AI RMF is revised. NIST AI RMF Playbook The Playbook source (opens in new tab) airc.nist.gov
NIST AI RMF Playbook NIST AI RMF AI RMF 1.0 official, secure websites. The AI RMF 1.0 is being updated. The Playbook will be source (opens in new tab) airc.nist.gov
NIST AI RMF Playbook NIST AI RMF AI RMF The Playbook will be updated after the AI RMF is revised. NIST AI RMF source (opens in new tab) airc.nist.gov

Every quote above is re-checked against the snapshot it was read in on every build. The check confirms three things: the snapshot is present, the quote appears in it verbatim, and the designator appears inside the quote. A row that fails stops the build rather than shipping. Method and vocabulary are on the methodology page; the same data is at /api/v1/citations.json.

Last updated: