The Consolidated Appropriations Act of 2023 added Section 524B to the Federal Food, Drug, and Cosmetic Act, establishing mandatory cybersecurity requirements for devices that meet the definition of a "cyber device" - that is, any device that contains software, is intended or reasonably expected to connect to the internet, or contains any technological characteristics that could be vulnerable to cybersecurity threats. The FDA's final premarket cybersecurity guidance, finalized in 2025, provides the detailed framework for meeting these statutory requirements in 510(k), De Novo, and PMA submissions. The guidance reflects the FDA's determination that cybersecurity is a safety issue, not merely an IT concern.
What Section 524B Requires
Under Section 524B, manufacturers of cyber devices must submit specific cybersecurity documentation as part of any premarket submission. The statutory requirements include:
- Software Bill of Materials (SBOM): A comprehensive inventory of all commercial, open-source, and off-the-shelf software components incorporated in the device, enabling identification of vulnerabilities in third-party software components
- Cybersecurity plan: A documented plan to monitor, identify, and address cybersecurity vulnerabilities and exploits after commercialization, including the manufacturer's processes for issuing patches and updates
- Reasonable assurance documentation: Evidence that the device design provides reasonable assurance of cybersecurity, including the results of threat modeling, vulnerability assessment, and penetration testing
- Secure product development framework (SPDF): Evidence that the device was developed using a documented, risk-based SPDF that integrates security practices throughout the design and development lifecycle
Threat Modeling and Security Risk Assessment
The FDA guidance places particular emphasis on threat modeling as a foundational cybersecurity activity. Manufacturers are expected to identify the assets that need protection (such as patient data, device functionality, and network integrity), enumerate plausible threat actors and their capabilities, analyze attack vectors and vulnerabilities, and document the security controls implemented to mitigate identified threats. The threat model must be specific to the device's intended use environment - a hospital-deployed infusion pump faces a different threat landscape than a consumer wearable - and must be updated when the device is modified or when new vulnerability information becomes available.
Post-Market Cybersecurity Obligations
Section 524B and the FDA guidance impose ongoing post-market cybersecurity obligations that extend well beyond the premarket submission. Manufacturers must maintain the ability to provide security updates and patches throughout the device's supported lifecycle and must communicate with customers about vulnerabilities that may affect device safety or effectiveness. The FDA expects manufacturers to have processes for monitoring vulnerability databases, participating in information sharing organizations such as the Health ISAC, and coordinating with FDA on vulnerabilities that rise to the level of a potential MDR-reportable event. The FDA has indicated that failure to address known cybersecurity vulnerabilities in cleared devices may constitute a violation of the FD&C Act.
Integration with Design Controls and Risk Management
The most effective approach to FDA cybersecurity compliance integrates security requirements into the existing design control and risk management framework rather than treating cybersecurity as a separate track. The threat model outputs should feed directly into the device's risk management file under ISO 14971, with cybersecurity risks assessed alongside traditional safety hazards. Security-focused design inputs should be documented in the design history file, and security verification and validation testing should be part of the design verification and validation plan. This integrated approach ensures that security is designed into the device rather than bolted on at the end of development, which is both the FDA's expectation and the most cost-effective path to a compliant submission.
Practical Steps for Submission Readiness
Manufacturers preparing cybersecurity submissions under the current guidance should begin by confirming whether their device meets the "cyber device" definition - if it contains any software and has any connectivity, it almost certainly does. They should then conduct or update a threat model, generate or obtain an SBOM from their software development team or suppliers, document their SPDF, and plan their post-market cybersecurity monitoring and patching processes. Engaging a cybersecurity specialist with medical device regulatory experience early in the development process is strongly recommended, as cybersecurity documentation that meets FDA expectations requires both security domain expertise and familiarity with the agency's submission requirements.
Frequently Asked Questions
What is a "cyber device" under Section 524B of the FD&C Act?
Section 524B defines a cyber device as any device that contains software, is intended or reasonably expected to connect to the internet, or contains technological characteristics that could be vulnerable to cybersecurity threats. In practice, virtually any device containing software with any form of connectivity meets this definition. Manufacturers should confirm whether their device qualifies as a cyber device as an early step in planning their premarket submission.
What cybersecurity documentation must be included in a 510(k) or PMA for a cyber device?
Under Section 524B and the FDA's final cybersecurity guidance, required submission content includes a Software Bill of Materials (SBOM) listing all commercial, open-source, and off-the-shelf software components; a documented cybersecurity plan for post-market monitoring and patching; reasonable assurance documentation from threat modeling, vulnerability assessment, and penetration testing; and evidence that the device was developed using a documented, risk-based Secure Product Development Framework (SPDF).
What are the ongoing post-market cybersecurity obligations under Section 524B?
Manufacturers must maintain the ability to provide security updates and patches throughout the device's supported lifecycle, communicate with customers about vulnerabilities that may affect device safety or effectiveness, monitor vulnerability databases, and participate in information sharing organizations such as the Health-ISAC. The FDA has indicated that failure to address known cybersecurity vulnerabilities in cleared devices may constitute a violation of the FD&C Act. These obligations apply throughout the device's market life, not only at the time of submission.
