FDA Issues Revised Cybersecurity Guidelines for Medical Devices to Address Emerging Risks
The U.S. Food and Drug Administration released updated guidance on September 27, 2023, that requires medical device makers to submit a cybersecurity risk management plan and a software bill of materials with premarket
The U.S. Food and Drug Administration released updated guidance on September 27, 2023, that requires medical device makers to submit a cybersecurity risk management plan and a software bill of materials with premarket applications. The document expands prior expectations by directing manufacturers to maintain a Secure Product Development Framework across the full device lifecycle. These steps respond to growing reports of cyber threats targeting connected health equipment. The FDA also maintains a dedicated cybersecurity page that outlines the regulatory approach and related efforts.
Background on the Revision
The FDA published the final guidance titled Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions. It replaces earlier, less detailed advice with explicit requirements for risk assessment, vulnerability tracking, and postmarket monitoring. Agency pages confirm the change addresses increased frequency and sophistication of attacks on networked devices. A separate FDA document on device software functions provides additional context for how cybersecurity fits into broader regulatory policy.
Requirements for Manufacturers
Device sponsors must now document a Secure Product Development Framework that integrates security controls from design through decommissioning. They must also provide a Software Bill of Materials listing components and known vulnerabilities. The guidance further directs ongoing surveillance after market entry, including processes to identify, evaluate, and fix new threats.
Postmarket Surveillance Expectations
Manufacturers are expected to monitor devices for emerging vulnerabilities once they reach health care settings. The FDA outlines incident response procedures that include timely communication with the agency and users. This shifts emphasis from one-time premarket review to continuous oversight.
What this means
The revised document sets clearer documentation standards that may raise the bar for premarket clearance of connected devices. It also signals greater regulatory attention to supply-chain transparency through required SBOMs. Health systems could see improved visibility into device components, which may aid coordinated vulnerability response.
Key takeaways
- The FDA guidance dated September 27, 2023, mandates a cybersecurity risk management plan in premarket submissions [1].
- Manufacturers must include a Software Bill of Materials to list components and vulnerabilities [1].
- Ongoing postmarket monitoring for new threats is now an explicit expectation [1].
- The updates apply to devices under U.S. jurisdiction and build on earlier software policy documents [3].
- Related agency resources describe the overall regulatory approach to device cybersecurity [2].
Limitations
The guidance applies primarily to devices regulated under U.S. jurisdiction; global uptake may vary. Manufacturers may face challenges integrating new processes into existing workflows. Some recommendations are nonbinding, and effective enforcement will depend on the FDA's oversight capacity and manufacturers' compliance.
Last updated: October 5, 2026
- Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions (Final Guidance), U.S. Food and Drug Administration, https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions
- Cybersecurity, U.S. Food and Drug Administration, https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
- Policy for Device Software Functions and Mobile Medical Applications Guidance for Industry and Food and Drug Administration Staff, U.S. Food and Drug Administration, https://www.fda.gov/regulatory-information/search-fda-guidance-documents/policy-device-software-functions-and-mobile-medical-applications