The short answer. Since March 29, 2023, Section 524B of the FD&C Act requires every 510(k), De Novo, PMA, PDP and HDE for a cyber device to include a plan for postmarket vulnerabilities, processes for updates and patches, and a software bill of materials (SBOM). Since October 1, 2023 FDA may refuse to accept submissions that lack them. The current guidance was issued on February 3, 2026.

Is your device a cyber device?

A device is a cyber device if it meets all three conditions in Section 524B(c):

  1. It includes software validated, installed or authorized by the sponsor, as a device or in a device. FDA reads this to include firmware and programmable logic.
  2. It has the ability to connect to the internet. FDA counts Wi-Fi, Bluetooth and BLE, cellular, magnetic inductive links and hardware connectors such as USB, Ethernet and serial ports.
  3. It has characteristics that could be vulnerable to cybersecurity threats.

In practice almost every connected wearable, remote monitor and app-controlled device qualifies.

What the law requires

SectionRequirement
524B(b)(1)A plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time, including coordinated vulnerability disclosure
524B(b)(2)Processes that give reasonable assurance the device and related systems are cybersecure, with updates and patches on a regular cycle and out-of-cycle patches for critical vulnerabilities as soon as possible
524B(b)(3)An SBOM covering commercial, open source and off-the-shelf software components

What FDA expects in the submission

Changes that are likely to affect cybersecurity, such as new authentication or encryption algorithms, new connectivity features or a different software update mechanism, need a new look at these documents.

Guidance history

DateDocument
March 30, 2023Refuse-to-accept policy for cyber devices; policy expired October 1, 2023
September 27, 2023Final premarket cybersecurity guidance, replacing the 2014 guidance
March 13, 2024Draft: select updates for Section 524B
June 27, 2025Final guidance adding Section VII on cyber devices
February 3, 2026Current version: Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, aligned with the QMSR

FDA’s inspection program for the QMSR also tells investigators to consider cyber devices for review.

When to start

Security has to be designed in, not added before submission: the choice of radio, bootloader, update path, encryption and third-party libraries is made during electronics and firmware design. Start the threat model and the SBOM when you choose the architecture, and keep both up to date with every design change. Our engineers design connected devices with these documents in mind; the submission itself stays with your regulatory team.

Sources

What OVA does here, and where our responsibility ends

OVA Solutions is a medical device engineering group working under an ISO 13485:2016 certified quality system: 62 engineers, 220 devices developed, $125 per hour, offices in New York, Florida, the United Kingdom, Estonia and Ukraine. We design electronics, firmware and mechanics and take a device from concept to design for manufacturing. We are not a regulatory consultancy and not a contract manufacturer: the regulatory strategy and the submission stay with you or your regulatory consultant.

More from OVA: what medical device development costs, how to choose a development firm, answers from Lisa Voronkova, our quality system.

Updated on October 8, 2026.