The short answer. Since March 29, 2023, Section 524B of the FD&C Act requires every 510(k), De Novo, PMA, PDP and HDE for a cyber device to include a plan for postmarket vulnerabilities, processes for updates and patches, and a software bill of materials (SBOM). Since October 1, 2023 FDA may refuse to accept submissions that lack them. The current guidance was issued on February 3, 2026.
Is your device a cyber device?
A device is a cyber device if it meets all three conditions in Section 524B(c):
- It includes software validated, installed or authorized by the sponsor, as a device or in a device. FDA reads this to include firmware and programmable logic.
- It has the ability to connect to the internet. FDA counts Wi-Fi, Bluetooth and BLE, cellular, magnetic inductive links and hardware connectors such as USB, Ethernet and serial ports.
- It has characteristics that could be vulnerable to cybersecurity threats.
In practice almost every connected wearable, remote monitor and app-controlled device qualifies.
What the law requires
| Section | Requirement |
|---|---|
| 524B(b)(1) | A plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time, including coordinated vulnerability disclosure |
| 524B(b)(2) | Processes that give reasonable assurance the device and related systems are cybersecure, with updates and patches on a regular cycle and out-of-cycle patches for critical vulnerabilities as soon as possible |
| 524B(b)(3) | An SBOM covering commercial, open source and off-the-shelf software components |
What FDA expects in the submission
- A security risk management plan and report, for example following AAMI TIR57 and ANSI/AAMI SW96, with threat model, cybersecurity risk assessment, vulnerability assessment and assessment of unresolved anomalies.
- Traceability between the threat model, risk assessment, SBOM and test documentation.
- A machine-readable SBOM with the NTIA minimum elements, plus the support level and end-of-support date of each component.
- Architecture views: global system, multi-patient harm, updatability and patchability, security use cases.
- Cybersecurity testing, measures and metrics, a cybersecurity management plan and security information in the labeling.
Changes that are likely to affect cybersecurity, such as new authentication or encryption algorithms, new connectivity features or a different software update mechanism, need a new look at these documents.
Guidance history
| Date | Document |
|---|---|
| March 30, 2023 | Refuse-to-accept policy for cyber devices; policy expired October 1, 2023 |
| September 27, 2023 | Final premarket cybersecurity guidance, replacing the 2014 guidance |
| March 13, 2024 | Draft: select updates for Section 524B |
| June 27, 2025 | Final guidance adding Section VII on cyber devices |
| February 3, 2026 | Current version: Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, aligned with the QMSR |
FDA’s inspection program for the QMSR also tells investigators to consider cyber devices for review.
When to start
Security has to be designed in, not added before submission: the choice of radio, bootloader, update path, encryption and third-party libraries is made during electronics and firmware design. Start the threat model and the SBOM when you choose the architecture, and keep both up to date with every design change. Our engineers design connected devices with these documents in mind; the submission itself stays with your regulatory team.
Sources
- Federal Register: refuse-to-accept policy for cyber devices, March 30, 2023
- Federal Register: cybersecurity guidance, June 27, 2025
- FDA: Cybersecurity in Medical Devices guidance (February 3, 2026)
- FDA: Cybersecurity in medical devices FAQs
- FDA: Compliance Program 7382.850
What OVA does here, and where our responsibility ends
OVA Solutions is a medical device engineering group working under an ISO 13485:2016 certified quality system: 62 engineers, 220 devices developed, $125 per hour, offices in New York, Florida, the United Kingdom, Estonia and Ukraine. We design electronics, firmware and mechanics and take a device from concept to design for manufacturing. We are not a regulatory consultancy and not a contract manufacturer: the regulatory strategy and the submission stay with you or your regulatory consultant.
More from OVA: what medical device development costs, how to choose a development firm, answers from Lisa Voronkova, our quality system.
Updated on October 8, 2026.