# FDA Medical Device Cybersecurity Compliance

Cybersecurity & Data Protection Laws

###### 🇺🇸 FDA Medical Device Cybersecurity

## FDA Rejected 700% More Submissions for Cybersecurity Deficiencies Since 2023. Is Your Next Premarket Filing Ready?

FDA medical device cybersecurity compliance now requires mandatory SBOMs, vulnerability management plans, and coordinated disclosure processes for every cyber device. Section 524B of the FD&C Act makes cybersecurity a legal prerequisite for market authorization—not a recommendation. The June 2025 final guidance consolidates all requirements into 12 mandatory eSTAR documents. Certivo automates cybersecurity evidence collection from supplier SBOM data through audit-ready premarket submission packages.

## Regulation Overview

**Jurisdiction**: United States (applies to all manufacturers marketing cyber devices in the U.S.)  
**Regulatory Body**: U.S. Food and Drug Administration (FDA), Center for Devices and Radiological Health (CDRH)  
**Regulation Number**: Section 524B, FD&C Act (added by FDORA, December 2022); Final Guidance issued June 27, 2025  
**Effective Date**: Section 524B effective March 29, 2023; Final guidance June 27, 2025; QMSR effective February 2026  
**Official Source**: [FDA Official Source](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity)
  
**Key Threshold**: All cyber devices—any device containing software or that is itself software

# What is FDA Medical Device Cybersecurity Guidance?

FDA medical device cybersecurity guidance is the primary regulatory framework governing cybersecurity requirements for medical devices sold in the United States. Section 524B of the FD&C Act, enacted through FDORA in December 2022, makes cybersecurity a mandatory component of every premarket submission for cyber devices. The June 2025 final guidance supersedes all prior versions and consolidates FDA's expectations into a single document. FDA now defines a cyber device as any device that contains software or is itself software—regardless of network connectivity.

## Key Components / Sub-Frameworks

### Obligation
- Mandatory SBOM, vulnerability plan, and reasonable assurance of cybersecurity

### Section 524B (FD&C Act)
- Statutory cybersecurity requirements for cyber devices

### Obligation
- Security risk management from design through decommissioning

### SPDF (Secure Product Development Framework)
- Lifecycle security framework embedded in QMS

### Obligation 
- Machine-readable, covering commercial, open-source, and off-the-shelf components

### SBOM Requirement
- Software Bill of Materials for all software components

### Obligation
- Coordinated disclosure, timely patches, customer notifications

### Vulnerability Management Plan
- Postmarket monitoring and patching obligations

### Obligation
- 12 required cybersecurity documents for premarket review

### eSTAR Cybersecurity Section
- Standardized submission template

### Obligation
- Cybersecurity risk management must integrate with QMS processes

### QMSR (Feb 2026)
- Quality Management System Regulation harmonized with ISO 13485

# Key Compliance Requirements

## Who Must Comply
- Manufacturers of medical devices containing software sold in the U.S. market
- Importers and distributors placing cyber devices on the U.S. market
- Contract manufacturers producing software-enabled medical devices for U.S. sponsors
- Non-U.S. companies seeking FDA clearance or approval for cyber devices
- Companies modifying previously authorized devices requiring new premarket submissions
- Software suppliers providing components integrated into FDA-regulated cyber devices

# Key Thresholds

#### Any device with software
- Classified as cyber device under Section 524B—guidance applies

#### March 29, 2023
- Date Section 524B requirements became effective for all premarket submissions

#### 12 documents
- Required cybersecurity documentation items in eSTAR template

#### 30 days
- Recommended timeline for customer notification of discovered vulnerabilities

## Core Obligations

1. **SBOM Submission**: Provide machine-readable SBOM listing all commercial, open-source, and off-the-shelf components  
   **DEADLINE**: Included in every premarket submission

2. **Vulnerability Management Plan**: Submit plan to monitor, identify, and address postmarket vulnerabilities and exploits  
   **DEADLINE**: Included in premarket submission; maintained throughout lifecycle

3. **Coordinated Vulnerability Disclosure**: Establish and document CVD policy and procedures  
   **DEADLINE**: Required at submission; operational postmarket

4. **Security Risk Assessment**: Conduct cybersecurity risk assessment per SPDF covering device and related systems  
   **DEADLINE**: Documented in Design History File and premarket submission

5. **Postmarket Cybersecurity Maintenance**: Provide timely patches and updates; violations classified under Section 301(q)  
   **DEADLINE**: Ongoing throughout device lifecycle

## Frequently Asked Questions

1. **What medical devices are subject to FDA cybersecurity requirements under Section 524B?**  
   - Section 524B applies to all cyber devices—defined as any medical device that contains software or is itself software. The June 2025 final guidance clarifies that this includes devices regardless of whether they are network-enabled.

2. **What happens if a premarket submission lacks cybersecurity documentation?**  
   - FDA applies a Refuse to Accept policy for cyber device submissions missing required cybersecurity documentation.

3. **What SBOM format does FDA require for premarket submissions?**  
   - FDA requires a machine-readable SBOM listing all commercial, open-source, and off-the-shelf software components. SPDX and CycloneDX are the preferred formats.

4. **How does Certivo help with FDA cybersecurity premarket submissions?**  
   - Certivo collects supplier SBOMs and security attestations at scale, extracts component metadata to version level, validates against vulnerability databases, and generates all 12 eSTAR cybersecurity documentation items.
