Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA's premarket cybersecurity guidance, reissued 3 February 2026. It describes a Secure Product Development Framework — threat modelling, cybersecurity risk assessment, security architecture, and security testing — the documentation FDA expects in premarket submissions, and the statutory obligations of FD&C Act §524B for "cyber devices": a vulnerability-management plan, secure development processes, and a software bill of materials (SBOM). The id retains its original year because ids are stable keys; read the code and date for the current version.
What this does not cover
stated in the document's own scope- A medical-device guidance: it does not govern pharmaceutical manufacturing systems, clinical-trial systems, or pharmacovigilance software.
- Covers premarket expectations and the §524B obligations; ongoing postmarket cybersecurity practice is addressed by FDA's separate postmarket cybersecurity guidance.
- Describes documentation and process expectations; the binding cyber-device requirements come from §524B of the FD&C Act itself, and quality-system obligations from the QMSR.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
"Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions" is FDA's premarket cybersecurity guidance, reissued 3 February 2026 and superseding the 27 June 2025 version, which had itself replaced the September 2023 guidance. It describes how security is engineered into a device through a Secure Product Development Framework — threat modelling, cybersecurity risk assessment, security architecture, and security testing — and what a premarket submission should contain to demonstrate it, including a software bill of materials covering commercial, open-source, and off-the-shelf components. It also carries FDA's expectations for the statutory population created by FD&C Act §524B: "cyber devices", whose sponsors must have a plan to monitor, identify, and address postmarket vulnerabilities, processes for secure development and maintenance, and an SBOM.
Scope & applicability
Devices with cybersecurity considerations submitted to FDA, and the statutory §524B population — "cyber devices" that include software, connect to the internet, and could be vulnerable to cybersecurity threats. Quality-system considerations tie the security work into design controls.
Legal basis & how it acquires force
A final guidance from CDRH and CBER. The 27 June 2025 version was announced in the Federal Register the same day; the current version was reissued 3 February 2026 to align the document with the Quality Management System Regulation that took effect the day before. It rests on two legal footings: the quality-system regulation's design-control and validation obligations, and section 524B of the FD&C Act — added by the December 2022 omnibus appropriations act — which imposes binding cybersecurity requirements on sponsors of cyber devices as a condition of premarket submission.
Document structure
| Part | Covers |
|---|---|
| Scope and the §524B cyber device | Which devices and submissions the guidance addresses, and the statutory definition and obligations of a cyber device |
| Secure Product Development Framework | The life-cycle security process: threat modelling, cybersecurity risk assessment, and interaction with quality-system design controls |
| Security architecture | Architecture views the submission should document, covering the device and the system it operates within |
| Cybersecurity testing | The testing evidence expected, proportionate to device risk |
| Transparency: SBOM and labeling | The software bill of materials and the security information communicated to users |
| Vulnerability management and postmarket plans | The §524B plan to monitor, identify, and address vulnerabilities and exploits |
Key requirements
- A Secure Product Development Framework spanning the total product life cycle
- Threat modelling and cybersecurity risk assessment distinct from, and coordinated with, safety risk management
- A software bill of materials (SBOM) covering commercial, open-source, and off-the-shelf components
- Security architecture views and security testing evidence in the premarket submission
- For §524B cyber devices: a plan to monitor, identify, and address postmarket vulnerabilities and exploits
Implementation tips
- Keep security risk management and ISO 14971 safety risk management as linked-but-separate analyses — collapsing them into one file loses the exploitability dimension FDA expects to see
- Build the SBOM from the build pipeline, not as a documentation exercise; it must stay maintainable through the postmarket phase
Revision notes
Reissued 3 February 2026, superseding the 27 June 2025 final guidance. The revision retitles the document from "Quality System" to "Quality Management System" and repoints its references from 21 CFR Part 820 as the Quality System Regulation to the Quality Management System Regulation that took effect 2 February 2026; FDA states the technical expectations are unchanged, so a submission already consistent with the June 2025 version does not need reworking. The June 2025 version had itself superseded the September 2023 guidance and integrated the §524B cyber-device obligations introduced by the 2022 omnibus legislation.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
The guidance and IEC 81001-5-1 approach the same target from two directions — 81001-5-1 defines the secure development process, while FDA's guidance defines what the resulting premarket submission must demonstrate. The security risk work runs alongside, not inside, ISO 14971 safety risk management, and the quality-system hooks land in the design controls of the device QMS. Its statutory layer, §524B, is US law with no EU equivalent instrument, though EU device legislation reaches similar cybersecurity outcomes through the general safety and performance requirements.
FDA Premarket Cybersecurity (2026): frequently asked questions
Quick answers to common questions about FDA Premarket Cybersecurity (2026).
What is a "cyber device" under §524B?
A device that includes software validated, installed, or authorized by the sponsor, that can connect to the internet, and that contains technological characteristics that could be vulnerable to cybersecurity threats. Sponsors of cyber devices must meet §524B's statutory requirements — vulnerability-management plan, secure development processes, and an SBOM — as part of their premarket submission.
What changed in the February 2026 reissue?
The title moved from "Quality System" to "Quality Management System" and the references to 21 CFR Part 820 were repointed from the Quality System Regulation to the Quality Management System Regulation, which took effect 2 February 2026. FDA states the technical expectations are unchanged, so a submission already consistent with the June 2025 version does not need reworking. The substantive change came earlier: the June 2025 version replaced the September 2023 guidance and folded FDA's §524B cyber-device expectations into one document alongside the Secure Product Development Framework and the submission content.
What must an SBOM in a premarket submission cover?
The software bill of materials should account for the device software's components — commercial, open-source, and off-the-shelf — so that vulnerabilities in third-party components can be identified and managed across the device's life.
Is cybersecurity risk assessment the same as ISO 14971 risk management?
No. They are linked but distinct: safety risk management evaluates harm from device function and failure, while security risk assessment evaluates exploitability of vulnerabilities by threats. The guidance expects both, coordinated so security-relevant hazards flow into the safety risk file.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.