Securing a connected medical device for its premarket submission is only the beginning. Under Section 524B of the FD&C Act and the FDA's cybersecurity guidance, manufacturers of "cyber devices" carry ongoing post-market obligations that extend across the entire supported life of the product. The FDA has been explicit that cybersecurity is a total product lifecycle (TPLC) responsibility, and post-market deficiencies are an increasing focus of inspections and adverse-event scrutiny. A premarket submission that earns clearance but is not backed by a functioning post-market program leaves both patients and the manufacturer exposed.
The SBOM Is a Living Document
The Software Bill of Materials (SBOM) submitted at premarket is not a one-time artifact. Every commercial, open-source, and off-the-shelf component in your device represents a potential source of newly discovered vulnerabilities. An effective post-market program continuously monitors the components in the SBOM against vulnerability databases such as the National Vulnerability Database (NVD) and CISA's Known Exploited Vulnerabilities catalog, so that a newly disclosed CVE in a third-party library is identified and triaged before it can be exploited in the field. This requires keeping the SBOM current as components are updated and maintaining the tooling to map CVEs back to affected device versions.
Coordinated Vulnerability Disclosure
The FDA expects manufacturers to establish a coordinated vulnerability disclosure (CVD) process - a documented channel through which security researchers, customers, and others can report potential vulnerabilities, and a defined internal workflow for triage, assessment, and response. Participation in an information-sharing and analysis organization (ISAO), such as the Health-ISAC, is strongly encouraged and demonstrates the kind of proactive posture regulators look for. A published security contact and disclosure policy is now considered table stakes for a connected device program.
Patching, Updates, and Risk Assessment
When a vulnerability is identified, the manufacturer must assess its impact on safety and effectiveness and determine an appropriate response. Key elements include:
- Exploitability and harm assessment: Evaluate the vulnerability using a recognized scoring approach and, critically, assess the potential for patient harm - not just IT impact.
- Timely remediation: Maintain the ability to deploy validated security patches and updates throughout the device's supported lifecycle, with patching cadence appropriate to risk.
- Customer communication: Notify affected customers and provide mitigations or compensating controls where an immediate patch is not feasible.
- Reportability analysis: Determine whether a vulnerability or its remediation rises to the level of a reportable correction or removal, or an MDR-reportable event.
The Legacy and End-of-Life Device Challenge
Some of the hardest post-market cybersecurity problems involve legacy devices - products designed before modern security expectations, or those approaching end-of-support. The FDA and IMDRF have published guidance specifically addressing legacy devices, emphasizing shared responsibility between manufacturers and the healthcare delivery organizations that operate them. Manufacturers should define and clearly communicate the supported lifecycle of each device, provide end-of-support timelines so that hospitals can plan, and document compensating controls for devices that can no longer be patched. Silence on end-of-life status is itself a risk.
Integrating Post-Market Cybersecurity into the QMS
Post-market cybersecurity should not operate as a standalone security function. It must be woven into the quality management system - linked to complaint handling, CAPA, risk management (ISO 14971), and post-market surveillance. Vulnerability findings should feed the risk management file, and remediation effectiveness should be verified through the same disciplined processes as any other corrective action. This integration is exactly what FDA investigators look for during inspections.
How Sequence Group Can Help
Sequence Group helps manufacturers build post-market cybersecurity programs that satisfy Section 524B and FDA guidance - from SBOM monitoring workflows and coordinated vulnerability disclosure processes to patch management, legacy-device strategies, and QMS integration. Contact us to assess your post-market cybersecurity readiness before your next inspection or vulnerability event.
Frequently Asked Questions
What are a manufacturer's post-market cybersecurity obligations under Section 524B?
Section 524B and FDA guidance require manufacturers of cyber devices to continuously monitor their SBOM components for newly disclosed vulnerabilities, maintain the ability to deploy security patches throughout the device's supported lifecycle, establish a coordinated vulnerability disclosure process, and notify customers when vulnerabilities affect device safety or effectiveness. Post-market cybersecurity deficiencies are an active focus of FDA inspections.
What is a Software Bill of Materials (SBOM) and why must it be maintained after clearance?
An SBOM is a comprehensive inventory of all commercial, open-source, and off-the-shelf software components in a device. Because new vulnerabilities are discovered in third-party components after a device is cleared, the SBOM must be kept current and actively monitored against vulnerability databases so that newly disclosed CVEs can be identified and triaged before they are exploited in the field.
How should manufacturers handle legacy or end-of-life devices with cybersecurity vulnerabilities?
FDA and IMDRF guidance emphasizes shared responsibility between manufacturers and healthcare delivery organizations for legacy devices. Manufacturers should define and communicate the supported lifecycle for each device, provide end-of-support timelines so hospitals can plan, and document compensating controls for devices that can no longer receive patches. Remaining silent about end-of-life status is itself treated as a risk.
