FDARegulatory IntelligenceGuidanceHIGH INSPECTION RISK
FDA Premarket Cybersecurity (2026)

Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions

FDA's premarket cybersecurity guidance, reissued 3 February 2026. It describes a Secure Product Development Framework — threat modelling, cybersecurity risk assessment, security architecture, and security testing — the documentation FDA expects in premarket submissions, and the statutory obligations of FD&C Act §524B for "cyber devices": a vulnerability-management plan, secure development processes, and a software bill of materials (SBOM). The id retains its original year because ids are stable keys; read the code and date for the current version.

LAST REVISED
February 2026
PRODUCT AREAS
Devices

What this does not cover

stated in the document's own scope
  • A medical-device guidance: it does not govern pharmaceutical manufacturing systems, clinical-trial systems, or pharmacovigilance software.
  • Covers premarket expectations and the §524B obligations; ongoing postmarket cybersecurity practice is addressed by FDA's separate postmarket cybersecurity guidance.
  • Describes documentation and process expectations; the binding cyber-device requirements come from §524B of the FD&C Act itself, and quality-system obligations from the QMSR.
SOURCE & PROVENANCE
ISSUING BODY
Food and Drug Administration
JURISDICTION
United States
DOCUMENT ID
FDA Premarket Cybersecurity (2026)
Official site — Food and Drug Administration

Always verify against the current published text before relying on it for a submission or inspection.

Overview

"Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions" is FDA's premarket cybersecurity guidance, reissued 3 February 2026 and superseding the 27 June 2025 version, which had itself replaced the September 2023 guidance. It describes how security is engineered into a device through a Secure Product Development Framework — threat modelling, cybersecurity risk assessment, security architecture, and security testing — and what a premarket submission should contain to demonstrate it, including a software bill of materials covering commercial, open-source, and off-the-shelf components. It also carries FDA's expectations for the statutory population created by FD&C Act §524B: "cyber devices", whose sponsors must have a plan to monitor, identify, and address postmarket vulnerabilities, processes for secure development and maintenance, and an SBOM.

Scope & applicability

Devices with cybersecurity considerations submitted to FDA, and the statutory §524B population — "cyber devices" that include software, connect to the internet, and could be vulnerable to cybersecurity threats. Quality-system considerations tie the security work into design controls.

Legal basis & how it acquires force

A final guidance from CDRH and CBER. The 27 June 2025 version was announced in the Federal Register the same day; the current version was reissued 3 February 2026 to align the document with the Quality Management System Regulation that took effect the day before. It rests on two legal footings: the quality-system regulation's design-control and validation obligations, and section 524B of the FD&C Act — added by the December 2022 omnibus appropriations act — which imposes binding cybersecurity requirements on sponsors of cyber devices as a condition of premarket submission.

Document structure

PartCovers
Scope and the §524B cyber deviceWhich devices and submissions the guidance addresses, and the statutory definition and obligations of a cyber device
Secure Product Development FrameworkThe life-cycle security process: threat modelling, cybersecurity risk assessment, and interaction with quality-system design controls
Security architectureArchitecture views the submission should document, covering the device and the system it operates within
Cybersecurity testingThe testing evidence expected, proportionate to device risk
Transparency: SBOM and labelingThe software bill of materials and the security information communicated to users
Vulnerability management and postmarket plansThe §524B plan to monitor, identify, and address vulnerabilities and exploits

Key requirements

  • A Secure Product Development Framework spanning the total product life cycle
  • Threat modelling and cybersecurity risk assessment distinct from, and coordinated with, safety risk management
  • A software bill of materials (SBOM) covering commercial, open-source, and off-the-shelf components
  • Security architecture views and security testing evidence in the premarket submission
  • For §524B cyber devices: a plan to monitor, identify, and address postmarket vulnerabilities and exploits

Implementation tips

  • Keep security risk management and ISO 14971 safety risk management as linked-but-separate analyses — collapsing them into one file loses the exploitability dimension FDA expects to see
  • Build the SBOM from the build pipeline, not as a documentation exercise; it must stay maintainable through the postmarket phase

Revision notes

Reissued 3 February 2026, superseding the 27 June 2025 final guidance. The revision retitles the document from "Quality System" to "Quality Management System" and repoints its references from 21 CFR Part 820 as the Quality System Regulation to the Quality Management System Regulation that took effect 2 February 2026; FDA states the technical expectations are unchanged, so a submission already consistent with the June 2025 version does not need reworking. The June 2025 version had itself superseded the September 2023 guidance and integrated the §524B cyber-device obligations introduced by the 2022 omnibus legislation.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

International alignment

The guidance and IEC 81001-5-1 approach the same target from two directions — 81001-5-1 defines the secure development process, while FDA's guidance defines what the resulting premarket submission must demonstrate. The security risk work runs alongside, not inside, ISO 14971 safety risk management, and the quality-system hooks land in the design controls of the device QMS. Its statutory layer, §524B, is US law with no EU equivalent instrument, though EU device legislation reaches similar cybersecurity outcomes through the general safety and performance requirements.

Where to next

Computerised System ValidationWhat CSV covers, and the standards that govern it.

FDA Premarket Cybersecurity (2026): frequently asked questions

Quick answers to common questions about FDA Premarket Cybersecurity (2026).

What is a "cyber device" under §524B?

A device that includes software validated, installed, or authorized by the sponsor, that can connect to the internet, and that contains technological characteristics that could be vulnerable to cybersecurity threats. Sponsors of cyber devices must meet §524B's statutory requirements — vulnerability-management plan, secure development processes, and an SBOM — as part of their premarket submission.

What changed in the February 2026 reissue?

The title moved from "Quality System" to "Quality Management System" and the references to 21 CFR Part 820 were repointed from the Quality System Regulation to the Quality Management System Regulation, which took effect 2 February 2026. FDA states the technical expectations are unchanged, so a submission already consistent with the June 2025 version does not need reworking. The substantive change came earlier: the June 2025 version replaced the September 2023 guidance and folded FDA's §524B cyber-device expectations into one document alongside the Secure Product Development Framework and the submission content.

What must an SBOM in a premarket submission cover?

The software bill of materials should account for the device software's components — commercial, open-source, and off-the-shelf — so that vulnerabilities in third-party components can be identified and managed across the device's life.

Is cybersecurity risk assessment the same as ISO 14971 risk management?

No. They are linked but distinct: safety risk management evaluates harm from device function and failure, while security risk assessment evaluates exploitability of vulnerabilities by threats. The guidance expects both, coordinated so security-relevant hazards flow into the safety risk file.