Statistics · Medical device cybersecurity
FDA Cybersecurity Guidance: What Changed in 2026 and What Is Law
The current FDA premarket cybersecurity guidance for medical devices was issued February 3, 2026. It runs 64 pages and replaces June 2025. About 3% of the 2026 wording was flagged as new or changed by The PenTest Index's comparison in October 2026. Most flagged words concern FDA's new quality rule. Here's what moved, and what's law.
Full comparison · Download the CSV tables
Key FDA cybersecurity guidance statistics
- About 3% of the wording in FDA's February 3, 2026 premarket cybersecurity guidance is flagged as new or changed from June 27, 2025: 780 of 25,498 words (3.1%). All 16 comparison runs landed between 2.8% and 4.0% (The PenTest Index comparison, October 2026). Our finding.
- About 7 in 10 of the words flagged as new or changed in FDA's February 2026 guidance are in passages about its new quality rule: 539 of 780 words (69%). Mentions of "QMSR" went from 0 to 29, and "ISO 13485" from 1 to 28 since June 2025 (The PenTest Index comparison, October 2026). Our finding.
- All 4 kinds of security testing FDA names, and all 5 listed penetration-test report elements, appear as the same list in both the June 2025 and February 2026 editions, with one standard reference reworded (The PenTest Index comparison of Section V.C, October 2026). Our finding.
- February 3, 2026: FDA issued the current premarket cybersecurity guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions." It is 64 pages (FDA, checked October 8, 2026).
- 3 final editions in 860 days: FDA issued final premarket cybersecurity guidance on September 27, 2023, June 27, 2025 and February 3, 2026. The edition before them stood for 3,282 days (The PenTest Index count from FDA covers, checked October 8, 2026). Our finding.
- 9 pages to 64: FDA's premarket cybersecurity guidance grew to about 7 times as many pages between its first final edition (October 2, 2014) and February 3, 2026 (The PenTest Index page counts, checked October 8, 2026). Our finding.
- 3 named duties are law: For covered cyber-device submissions from March 29, 2023, section 524B requires a postmarket vulnerability plan, secure processes with updates and patches, and a software bill of materials. This covers the five submission pathways listed below (21 U.S.C. 360n-2).
- "Should" 175 times: FDA's 2026 cybersecurity guidance uses "should" 175 times (The PenTest Index count, checked October 8, 2026). FDA says "should" in its guidance "means that something is suggested or recommended, but not required" (FDA guidance, Section I).
- 14 lines: FDA's February 2026 summary table has 6 top-level entries and 8 nested entries, the same 14 lines as in September 2023 and June 2025 (FDA guidance, Appendix 4).
- "(e.g., annually)": FDA says cybersecurity testing after a device's release "should be performed at regular intervals commensurate with the risk (e.g., annually)" (FDA guidance, Section V.C).
- 16 recall events: FDA's enforcement database lists 16 medical device recall events, covering 59 product records, whose stated reason uses the word "cybersecurity," from February 2019 to June 2026. Two are Class I, and both began in 2025 (The PenTest Index count from openFDA, data updated September 30, 2026). Our finding.
- 18 safety-list entries: FDA's cybersecurity safety communications and alerts table has 18 entries dated June 13, 2013 to January 30, 2025. For those, FDA says it "is not aware of any patient injuries or deaths associated with cybersecurity incidents" (FDA Cybersecurity page, checked October 8, 2026).
- 30 and 60 days: FDA's postmarket cybersecurity guidance, dated December 28, 2016, calls for action as soon as possible, with 30 days for communication and planning and 60 days for a validated, deployable fix, as two of four conditions for not enforcing Part 806 reporting. Both clocks start when the maker learns of the vulnerability; they are not general patch deadlines (FDA postmarket guidance, Section VII.B).
- 0 mentions: VEX, CycloneDX, SPDX, PCCP, STRIDE and eSTAR each appear zero times in FDA's February 2026 cybersecurity guidance (The PenTest Index text search, October 2026). Our finding.
Which FDA cybersecurity guidance is current?
The two core FDA references here are the premarket and postmarket cybersecurity guidances. The premarket one, issued February 3, 2026, is 64 pages and covers what to send FDA in a premarket submission. The postmarket one, issued December 28, 2016, covers devices already on the market.
A "guidance" is FDA's written advice. It explains how FDA reads the law, but it is not the law itself. More on that below.
One snag: when we checked on October 8, 2026, FDA's main Cybersecurity page (last updated July 6, 2026) still listed the June 27, 2025 edition. The PDF's own cover says "Document issued on February 3, 2026." Trust the cover.
Which source answers which question
| What you need | Where to look |
|---|---|
| FDA's current premarket advice | February 3, 2026 guidance (PDF) |
| The edition it replaced | June 27, 2025 guidance (PDF, HHS copy) |
| Advice for devices already on the market | Postmarket guidance, December 28, 2016 (PDF) |
| What the law requires for cyber devices | Section 524B, 21 U.S.C. 360n-2 |
| When the law started and how FDA screens submissions | FDA Cybersecurity FAQs |
| The quality rule the 2026 edition was updated to match | FDA QMSR page |
Source: The PenTest Index, links checked October 8, 2026.
Source: The PenTest Index, links checked October 8, 2026.
FDA device cybersecurity guidance tracker, 2005–2026
This tracker covers 12 FDA device cybersecurity guidance documents and drafts from 2005–2026: 7 final and 5 drafts. Four of the finals are editions of the same premarket guidance. The current premarket edition and the 2016 postmarket guidance are the two core references used on this page.
The PenTest Index FDA Cybersecurity Guidance Tracker
| # | Issued | Document | Type | PDF pages | Status on October 8, 2026 |
|---|---|---|---|---|---|
| 1 | Jan 14, 2005 | Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software | Final | 7 | Historical guidance; this audit did not establish a formal withdrawal |
| 2 | Jun 14, 2013 | Content of Premarket Submissions for Management of Cybersecurity in Medical Devices | Draft | not counted | Finalized Oct 2, 2014 |
| 3 | Oct 2, 2014 | Content of Premarket Submissions for Management of Cybersecurity in Medical Devices | Final | 9 | Replaced Sept 27, 2023 |
| 4 | Jan 22, 2016 | Postmarket Management of Cybersecurity in Medical Devices | Draft | 25 | Finalized Dec 28, 2016 |
| 5 | Dec 28, 2016 | Postmarket Management of Cybersecurity in Medical Devices | Final | 31 | Current |
| 6 | Oct 18, 2018 | Content of Premarket Submissions for Management of Cybersecurity in Medical Devices | Draft | 24 | Draft; followed by the April 2022 draft and September 2023 final |
| 7 | Apr 8, 2022 | Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions | Draft | 49 | Finalized Sept 27, 2023 |
| 8 | Mar 30, 2023 | Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B | Final | 6 | Temporary refuse-to-accept policy ended Oct 1, 2023 |
| 9 | Sept 27, 2023 | Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions | Final | 57 | Replaced June 27, 2025 |
| 10 | Mar 13, 2024 | Select Updates for the Premarket Cybersecurity Guidance: Section 524B | Draft | 11 | Folded into the June 2025 edition |
| 11 | Jun 27, 2025 | Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions | Final | 64 | Replaced Feb 3, 2026 |
| 12 | Feb 3, 2026 | Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions | Final | 64 | Current |
Source: The PenTest Index, from FDA PDF covers, page counts and Federal Register notices (fda.gov, the HHS guidance portal, and Internet Archive copies of fda.gov files). Checked October 8, 2026. Row 2's date is verified from the 2014 final cover and official notice; its draft PDF was not retrieved. Row 8's PDF cover says March 30, 2023, while FDA's announcement is dated March 29; both dates are in the dataset. The 2016 postmarket PDF's first page is a notice FDA added later about the quality rule; the guidance text itself was not reissued. Full links in the dataset.
Source: The PenTest Index, from FDA PDF covers, page counts and Federal Register notices (fda.gov, the HHS guidance portal, and Internet Archive copies of fda.gov files). Checked October 8, 2026. Row 2's date is verified from the 2014 final cover and official notice; its draft PDF was not retrieved. Row 8's PDF cover says March 30, 2023, while FDA's announcement is dated March 29; both dates are in the dataset. The 2016 postmarket PDF's first page is a notice FDA added later about the quality rule; the guidance text itself was not reissued. Full links in the dataset.
Find the edition that was current on a date
Writing about a 2024 submission? An FDA letter from last summer? Type a date and see which final premarket edition was the current one that day. Dates through October 8, 2026 have been checked.
FDA Premarket Cybersecurity Guidance Edition Finder
Enter a date to see which final edition was current on that date.
Verified through October 8, 2026. Your date is checked in this page's memory only; it is not stored, added to the URL, or sent in an analytics event or session recording.
That date has not been checked. The latest verified edition is February 3, 2026, checked October 8, 2026.
What changed in the February 2026 FDA cybersecurity guidance?
About 3% of the wording in the February 3, 2026 edition is flagged as new or changed from the June 27, 2025 edition, by The PenTest Index's comparison: 780 of 25,498 words (3.1%). Most flagged words are in passages about the new quality rule. The page count, the seven main sections and FDA's 14-line document table stay the same.
Picture a 64-page guide that keeps most of its wording but updates many references to a changed quality rule. It also adds four glossary terms and keeps the same testing lists. That's the pattern here. A small share of changed wording does not tell you how much work a device needs.
FDA's history table describes the purpose of the revision: "Revisions issued under Level 2 guidance procedures (21 CFR 10.115(g)(4)), including revisions to align with the amendments to 21 CFR 820 (the Quality Management System Regulation (QMSR))." Level 2 covers existing practices or minor policy changes under FDA's guidance rule. FDA does not state our 3% figure; it comes from our text comparison.
The last three final editions, measured
| Measure | Sept 27, 2023 | June 27, 2025 | Feb 3, 2026 |
|---|---|---|---|
| PDF pages | 57 | 64 | 64 |
| Main sections | 6 | 7 | 7 |
| Lines in FDA's document table (Table 1) | 14 | 14 | 14 |
| Glossary terms | 48 | 47 | 51 |
| Words (number-only tokens left out) | 22,143 | 25,466 | 25,498 |
| Mentions of "QMSR" | 0 | 0 | 29 |
| Mentions of "ISO 13485" | 1 | 1 | 28 |
| Mentions of "21 CFR 820" or "Part 820" | 44 | 43 | 13 |
| Mentions of "524B" | 14 | 74 | 74 |
| Mentions of "cyber device(s)" | 10 | 48 | 48 |
| Mentions of "SBOM/SBOMs" | 28 | 34 | 34 |
| Mentions of "penetration" | 3 | 3 | 3 |
| Uses of "should" | 161 | 174 | 175 |
| Words flagged as new or changed vs the edition before | n/a | 3,635 (14.3%) | 780 (3.1%) |
Source: The PenTest Index counts from the text of each FDA PDF (2023, 2025, 2026). Checked October 8, 2026. These are exact counts under the published extraction method; other methods can give different counts.
Source: The PenTest Index counts from the text of each FDA PDF (2023, 2025, 2026). Checked October 8, 2026. These are exact counts under the published extraction method; other methods can give different counts.
What the new wording is about
We sorted every passage flagged as new or changed by its main topic. About 7 in 10 of the flagged words are in passages about the new quality rule. Glossary terms, definitions and source notes are the next biggest piece; these include the four new terms.
| What the new or changed words are about | Words | Share |
|---|---|---|
| Switch to the new quality rule (QMSR, ISO 13485 clauses, "design and development") | 539 | 69% |
| Glossary terms, definitions and source notes, including Denial of Service, Least Privilege, Quality of Service and Threat surface | 138 | 18% |
| FDA's guidance history | 33 | 4% |
| Other text differences, including text-reading noise | 70 | 9% |
| Total | 780 | 100% |
Source: The PenTest Index topic sort of all 115 unmatched passages in the central 2026 vs 2025 comparison (PyMuPDF text, 6-word runs, reusable matches: 780 of 25,498 words, or 3.1%). Each whole passage is assigned to its main topic, so the counts can include nearby unchanged words. The 115 passages and their page numbers are in the download. Checked October 8, 2026.
Source: The PenTest Index topic sort of all 115 unmatched passages in the central 2026 vs 2025 comparison (PyMuPDF text, 6-word runs, reusable matches: 780 of 25,498 words, or 3.1%). Each whole passage is assigned to its main topic, so the counts can include nearby unchanged words. The 115 passages and their page numbers are in the download. Checked October 8, 2026.
The "new quality rule" is FDA's Quality Management System Regulation, or QMSR. It took effect February 2, 2026, the day before the new guidance came out. It rewrote FDA's old device quality rule (21 CFR Part 820) to pull in an international standard, ISO 13485:2016, by reference (FDA).
The exact changes in the testing section
Here are the selected reference and wording changes in Section V.C, the part about security testing. The title change is shown for context. The other rows cover Section V.C. These selected edits do not add a named testing category.
| Item | June 2025 text | February 2026 text |
|---|---|---|
| Guidance title | "Quality System Considerations" | "Quality Management System Considerations" |
| What testing shows | "the effectiveness of design controls" | "the effectiveness of design and development activities" |
| Design verification rule cited | 21 CFR 820.30(f) | ISO 13485, Subclause 7.3.6 |
| Design validation rule cited | 21 CFR 820.30(g) | ISO 13485, Subclause 7.3.7 |
| Extra sentence on validation | "Such design validation shall include software validation and risk analysis, where appropriate." | Not in this paragraph |
| Vulnerability testing reference | "such as section 9.4 of ANSI/ISA 62443-4-1" | "described in ANSI/ISA 62443-4-1" |
| IEC 81001-5-1 footnote | Standard number only | Adds the standard's full title |
Source: The PenTest Index line-by-line comparison of Section V.C in the June 2025 and February 2026 editions. Checked October 8, 2026.
Source: The PenTest Index line-by-line comparison of Section V.C in the June 2025 and February 2026 editions. Checked October 8, 2026.
The dropped sentence doesn't mean software validation stopped mattering. The 2026 text points to Subclause 7.3.7 and says design and development validation "includes validation of device software" in another section.
What changed in June 2025
The June 27, 2025 edition was the big one. It added Section VII, "Cyber Devices," which ties the guidance to the law that took effect in 2023. The document grew from 57 to 64 pages and about 15% in words. The comparison flagged 3,635 words, or 14.3%, as new or changed. Mentions of "524B" jumped from 14 to 74.
What has stayed the same since 2023
FDA's document table lists the same 14 lines in the September 2023, June 2025 and February 2026 editions. "SBOM" and "SBOMs" appear 34 times in total in both 2025 and 2026, and "penetration" 3 times in all three. Those lists are stable. They do not, on their own, show whether a submission meets the current recommendations and legal duties.
Is FDA cybersecurity guidance mandatory?
The guidance itself is not law. Its pages carry the banner "Contains Nonbinding Recommendations," and it uses "should" 175 times. But section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act) is law. For covered cyber-device submissions from March 29, 2023, it requires three named duties: a plan to find and fix security holes after sale, secure processes with updates and patches, and a software bill of materials. The covered pathways are 510(k), De Novo, PMA, PDP and HDE, including relevant supplements.
The guidance gives advice; the laws and rules it cites still apply. Think of it like a driving manual and the traffic code. The manual gives advice on how to drive well. The code is what gets you a ticket. FDA's guidance is the manual, and it tells you which parts of the code it is explaining.
FDA spells it out: "The use of the word should in Agency guidance means that something is suggested or recommended, but not required." You can use another approach if it meets the law and the rules.
What is law, and what is advice
| Provision | What it says | Law or advice? | Where the 2026 guidance covers it |
|---|---|---|---|
| 524B(a) | Anyone who submits a 510(k), De Novo, PMA, PDP or HDE for a cyber device "shall include such information as the Secretary may require" | Law | Section VII.A |
| 524B(b)(1) | Submit "a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures" | Law | Sections VII.C.1, VI.B |
| 524B(b)(2) | "Design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure," with patches "on a reasonably justified regular cycle" for known unacceptable vulnerabilities and "as soon as possible out of cycle" for critical vulnerabilities that could cause uncontrolled risks | Law. FDA says failing it is a prohibited act under section 301(q) | Sections VII.C.2, V, VI |
| 524B(b)(3) | Provide "a software bill of materials, including commercial, open-source, and off-the-shelf software components" | Law | Sections VII.C.3, V.A.4 |
| 524B(b)(4) | Meet "such other requirements as the Secretary may require through regulation" | Law: comply with any additional requirements adopted by regulation. The duties in b(1)–b(3) do not await such a rule | Footnotes 14–15 |
| 524B(c) | Defines a cyber device (three tests, below) | Law | Section VII.B |
| 524B(d) | FDA may exempt device types and must publish the list | Law: any exemption list must be published in the Federal Register | Not discussed |
| 21 CFR Part 820 (QMSR) | Quality rule; took effect Feb 2, 2026; pulls in ISO 13485:2016 | Regulation | Section IV.A and throughout |
| Recommendations that do not restate a statute or regulation | FDA describes its current thinking and recommended ways to support a submission. An alternative approach must meet applicable laws and rules | Recommendations are nonbinding; the legal duties they cite remain binding | Introductory statement and Section I; legal references also appear throughout |
Source: 21 U.S.C. 360n-2; FDA guidance, Feb 3, 2026; FDA QMSR page. Checked October 8, 2026.
Source: 21 U.S.C. 360n-2; FDA guidance, Feb 3, 2026; FDA QMSR page. Checked October 8, 2026.
What is a "cyber device"?
A cyber device meets all three tests at once: sponsor-validated, installed or authorized software; the ability to connect to the internet; and sponsor-validated, installed or authorized features that could be open to cyber threats. The sponsor is the person or company making the FDA submission.
| Test | The law's words |
|---|---|
| 1. Software | "includes software validated, installed, or authorized by the sponsor as a device or in a device" |
| 2. Internet | "has the ability to connect to the internet" |
| 3. Exposure | "contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats" |
Source: Section 524B(c), 21 U.S.C. 360n-2(c). Checked October 8, 2026.
Source: Section 524B(c), 21 U.S.C. 360n-2(c). Checked October 8, 2026.
FDA reads test 2 broadly. Wi-Fi, cellular, Bluetooth, network and cloud links, magnetic links to implants, and ports like USB, ethernet or serial can all count. One footnote says a device serviced through a USB connection "is therefore considered to have the ability to connect to the internet," even if the link is brief (Section VII.B, footnote 61).
The guidance reaches beyond section 524B's cyber-device scope. It covers devices "with cybersecurity considerations," including ones that are not network-enabled at all.
Which date is the deadline?
Not every date in this story is a deadline. Here is what each one means.
| Date | What happened | Kind of date |
|---|---|---|
| Dec 29, 2022 | Congress adds section 524B to the FD&C Act | Law signed |
| Mar 29, 2023 | Section 524B takes effect for new submissions | Law takes effect |
| Oct 1, 2023 | FDA's temporary refuse-to-accept policy ends; FDA expects 524B information in covered submissions | Policy ends |
| Feb 2, 2026 | Quality Management System Regulation takes effect | Rule takes effect |
| Feb 3, 2026 | Current premarket guidance issued | Advice issued |
Source: 21 U.S.C. 360n-2 and notes; FDA Cybersecurity FAQs, Q3 and Q5; FDA QMSR page; FDA guidance cover. Checked October 8, 2026.
Source: 21 U.S.C. 360n-2 and notes; FDA Cybersecurity FAQs, Q3 and Q5; FDA QMSR page; FDA guidance cover. Checked October 8, 2026.
What happens if the cybersecurity information is missing?
FDA's temporary refuse-to-accept policy ended October 1, 2023, 186 days after the law took effect. During that policy, FDA generally did not intend to refuse a covered submission based solely on section 524B information; the law still applied. Since then, FDA says, "An eSTAR submission will be put on a Technical Screening hold if it does not contain accurate responses and relevant attachments in the Cybersecurity section of eSTAR." (eSTAR is FDA's electronic submission template.)
Does section 524B reach devices already on the market?
Section 524B does not apply to a submission sent before March 29, 2023, FDA says. But if a maker changes an older cyber device in a way that needs a new FDA review, "the law applies to the new premarket submission" (FDA FAQ, Q3). Other FDA duties can still apply to older devices.
What does FDA want in a premarket cybersecurity submission?
FDA's Table 1 has 14 lines: six top-level entries and eight nested entries. They are a risk management report with six parts, measures and metrics, architecture views with two parts, testing, labeling, and cybersecurity management plans. Two entries directly match documents named in section 524B: the SBOM and the postmarket vulnerability plan. Other entries can support the broader duty to provide reasonable assurance of cybersecurity. This is not a list of 14 separate statutory documents.
FDA's Table 1: recommended cybersecurity documents (Appendix 4)
| # | Group | Document (FDA's label) | Document named in section 524B? |
|---|---|---|---|
| 1 | Cybersecurity Risk Management Report | Cybersecurity Risk Management Report | |
| 2 | Cybersecurity Risk Management Report | Threat Model | |
| 3 | Cybersecurity Risk Management Report | Cybersecurity Risk Assessment | |
| 4 | Cybersecurity Risk Management Report | SBOM | Yes, 524B(b)(3) |
| 5 | Cybersecurity Risk Management Report | Vulnerability Assessment and Software Support | |
| 6 | Cybersecurity Risk Management Report | Unresolved Anomalies Assessment | |
| 7 | Cybersecurity Risk Management Report | Traceability | |
| 8 | Measures and Metrics | Measures and Metrics | |
| 9 | Architecture Views | Architecture Views | |
| 10 | Architecture Views | Requirements | |
| 11 | Architecture Views | Architecture Views | |
| 12 | Testing | Testing | |
| 13 | Labeling | Labeling | |
| 14 | Cybersecurity Management Plans | Cybersecurity Management Plans | Yes, the plan in 524B(b)(1) |
Source: FDA guidance, Feb 3, 2026, Appendix 4, printed pages 51–53. Same 14 lines in the 2023 and 2025 editions. Blank cells mean the document is not named separately in section 524B; they do not mean no legal duty applies. The dataset shows the six top-level and eight nested entries. Checked October 8, 2026.
Source: FDA guidance, Feb 3, 2026, Appendix 4, printed pages 51–53. Same 14 lines in the 2023 and 2025 editions. Blank cells mean the document is not named separately in section 524B; they do not mean no legal duty applies. The dataset shows the six top-level and eight nested entries. Checked October 8, 2026.
FDA adds a warning right next to the table: "This table is not intended to serve as merely a deliverable checklist." In plain words, the documents should come out of real work, not be written to fill boxes.
The SBOM
An SBOM, or software bill of materials, is an ingredient list for software: every software part inside a device. Section 524B requires one for covered cyber-device submissions. FDA asks for it to be machine-readable and to follow the minimum elements set by NTIA (the National Telecommunications and Information Administration) in October 2021. For each part, FDA also wants its support level and its end-of-support date.
The guidance names no file format. It says only, "Industry-accepted formats of SBOMs are encouraged."
The threat model and the four architecture views
A threat model is a map of how someone could attack the device. FDA asks for four types of "architecture views" that show it from different angles: the global system view, the multi-patient harm view, the updatability and patchability view, and security use case views. A type may need more than one view. FDA allows views to be combined, or an explanation when a type does not fit the system.
The eight security control categories (Appendix 1)
Appendix 1 lists eight groups of security controls FDA recommends: authentication, authorization, cryptography, code/data/execution integrity, confidentiality, event detection and logging, resiliency and recovery, and firmware and software updates. FDA says the controls should be built into the design and chosen for the device's risks. Comparable controls can be used with supporting evidence.
Which submissions it covers
For devices with cybersecurity considerations, the guidance lists 8 submission types sent to FDA's device or biologics centers: the Center for Devices and Radiological Health (CDRH) or the Center for Biologics Evaluation and Research (CBER). Section 524B's cyber-device duties attach to 5 pathways: 510(k), De Novo, PMA, PDP and HDE, including relevant supplements.
The eight types are Premarket Notification (510(k)); De Novo requests; Premarket Approval Applications (PMA, including supplements); Product Development Protocols (PDP); Investigational Device Exemption (IDE); Humanitarian Device Exemption (HDE); Biologics License Application (BLA); and Investigational New Drug (IND). The guidance's recommendations can also apply to devices that do not need a premarket submission.
A 510(k) shows that a device is substantially equivalent to a legally marketed device: as safe and effective, with the same intended use. The source explains the tests for different technology. These pathway names come from Section II of the guidance.
Does FDA require penetration testing for medical devices?
FDA recommends it, and section 524B does not name it. The February 2026 guidance lists penetration testing as one of four kinds of security testing and says "Penetration test reports should be provided." The word "penetration" appears three times in the 64 pages.
A penetration test is an authorized, planned attempt to find and use security weaknesses. Testers try to break in the way a real attacker would, then write up what they found.
FDA's whole bullet on penetration testing is 55 words long. Short, but specific about what the report should hold.
The four kinds of security testing FDA names
| Kind of test | What FDA asks for (Section V.C) | In June 2025? | In Feb 2026? |
|---|---|---|---|
| Security requirements | Evidence each security design requirement was built in, plus boundary analysis | Yes | Yes |
| Threat mitigation | Evidence the risk controls work, tied to the threat models | Yes | Yes |
| Vulnerability testing | Six kinds of testing and analysis (below) | Yes | Yes (reference wording changed) |
| Penetration testing | "tests that focus on discovering and exploiting security vulnerabilities in the product" | Yes | Yes |
Source: FDA guidance, Feb 3, 2026, Section V.C and the June 27, 2025 edition. Checked October 8, 2026.
Source: FDA guidance, Feb 3, 2026, Section V.C and the June 27, 2025 edition. Checked October 8, 2026.
The six kinds of vulnerability testing FDA lists are: abuse or misuse cases and malformed inputs (including robustness and fuzz testing); attack surface analysis; vulnerability chaining; closed box testing of known vulnerability scanning; software composition analysis of binary executable files; and static and dynamic code analysis, including tests for credentials that are hardcoded, default, easily guessed or easily compromised.
A vulnerability scan and a penetration test are different things here. A scan checks for known holes. A penetration test tries to use them.
What a penetration test report should include
| # | What FDA says the report should include | In June 2025? | In Feb 2026? |
|---|---|---|---|
| 1 | Independence and technical expertise of testers | Yes | Yes |
| 2 | Scope of testing | Yes | Yes |
| 3 | Duration of testing | Yes | Yes |
| 4 | Testing methods employed | Yes | Yes |
| 5 | Test results, findings, and observations | Yes | Yes |
Source: FDA guidance, Feb 3, 2026, Section V.C and the June 27, 2025 edition. Checked October 8, 2026.
Source: FDA guidance, Feb 3, 2026, Section V.C and the June 27, 2025 edition. Checked October 8, 2026.
FDA also recommends the manufacturer's assessment of the findings, including reasons for leaving a finding unresolved or putting a fix into a later release. If a fix is deferred because the current risk is considered acceptable, the submission should describe the planned release, its timing, which devices will get the update, and how long delivery will take.
These are five things inside one report, not five separate tests. If you are comparing offers, they make a handy yardstick. The site's web application and API provider comparison shows how firms describe scope, reports and retests; it does not list medical-device testing matches.
Who can do the testing, and how often
The guidance does not say an outside firm must do the work. It asks makers to say "by whom the testing was performed (e.g., independent internal testers, external testers)" and how independent they are from the people who built the device. It adds: "In some cases, it may be necessary to use third parties to ensure an appropriate level of independence." If a third party did test, FDA wants the original report.
On timing, FDA says testing should run through development, and after release "at regular intervals commensurate with the risk (e.g., annually)." Annual is FDA's example, not a fixed rule. These lines cover all security testing, not only penetration tests.
FDA's Cybersecurity page also lists a June 29, 2026 white paper from MDIC, the Medical Device Innovation Consortium, on penetration testing best practices.
No test report, from any tester, guarantees that FDA will accept a submission.
If an FDA submission is why you are buying a test, the free Find My PenTest Match checklist can help you write down the scope of the test and the questions your report reader will ask. It is a general scoping aid and asks for no contact details.
How long is FDA's cybersecurity guidance, and how fast has it grown?
FDA's premarket cybersecurity guidance was 9 pages when it was first finalized on October 2, 2014. The current edition is 64 pages, about 7 times as many pages. The 2014 edition listed 5 documentation items; today's table has 14 lines, including headings and nested entries. Those two counts use different structures.
The pace picked up, too. The 2014 edition stood for 3,282 days, about nine years. Then FDA issued three final editions in 860 days.
A longer document isn't automatically a stricter one. The longer document includes explanation, examples and a glossary.
What do FDA's 30-day and 60-day figures mean?
These figures come from FDA's 2016 postmarket guidance. For specified vulnerabilities with uncontrolled risk, FDA says it does not intend to enforce Part 806 reporting when all four conditions are met. Action must be taken as soon as possible: communication and planning no later than 30 days after learning of the vulnerability, and a validated, deployable fix no later than 60 days.
The four conditions, summarized
| # | Condition |
|---|---|
| 1 | "There are no known serious adverse events or deaths associated with the vulnerability" |
| 2 | "As soon as possible but no later than 30 days after learning of the vulnerability," the maker tells its customers and users, identifies interim compensating controls, and makes a plan to bring the remaining risk to an acceptable level |
| 3 | "As soon as possible but no later than 60 days after learning of the vulnerability," the maker fixes it, validates the change, and distributes a deployable fix that brings the remaining risk to an acceptable level |
| 4 | The maker "actively participates as a member of an ISAO" (an Information Sharing and Analysis Organization) that shares medical-device threats and vulnerabilities, and shares its customer communications with it when customers are notified |
Source: FDA, Postmarket Management of Cybersecurity in Medical Devices, Dec 28, 2016, Section VII.B, printed pages 22–23. Checked October 8, 2026.
Source: FDA, Postmarket Management of Cybersecurity in Medical Devices, Dec 28, 2016, Section VII.B, printed pages 22–23. Checked October 8, 2026.
Interim controls are steps that reduce risk while a fix is being prepared. FDA also calls for a reason for the timeline, a customer notice explaining the risk and planned response, and controls that do not create a greater safety risk. A compensating control can sometimes be a long-term solution if the remaining risk is acceptable. Follow-up with users may continue beyond 60 days. The four-condition dataset preserves these details.
Section 524B sets no fixed number of days for those patches. It says "as soon as possible out of cycle" for critical vulnerabilities that could cause uncontrolled risks.
How many medical devices have been recalled for cybersecurity?
FDA's enforcement database lists 16 device recall events, covering 59 product records, whose stated reason uses the word "cybersecurity." The first began February 8, 2019, and the latest June 9, 2026. Two are Class I, the class FDA uses when there is a reasonable chance of serious harm or death, and both began in 2025.
There's no steady climb here. Counts in this result bounce from 0 to 4 a year. This is a keyword-defined subset: a recall that describes a security flaw in other words, like "unauthorized access," doesn't show up in a search for "cybersecurity." The 2026 count is a partial-year snapshot.
Device recall events whose reason cites "cybersecurity"
| Began | Company | Class | Product records | Reason, in short |
|---|---|---|---|---|
| Feb 8, 2019 | Draeger | II | 2 | Patient monitors may reboot or lose communication |
| Jun 27, 2019 | Medtronic MiniMed | II | 16 | Insulin pumps; someone nearby could connect by radio and change settings |
| Sept 13, 2019 | Draeger | II | 1 | Patient monitor may reboot or lose alarms |
| Oct 9, 2019 | Draeger | II | 1 | Denial of service, spoofing and tampering risks |
| Mar 22, 2021 | Datascope | III | 2 | Flaw in a widely used network software library |
| Feb 14, 2022 | Draeger | II | 2 | Ventilator "not equipped against potential cyber security threats" |
| May 3, 2022 | Illumina | II | 2 | "cybersecurity vulnerability" |
| Sept 20, 2022 | Medtronic MiniMed | II | 2 | Pump communication protocol could allow unauthorized access |
| Apr 5, 2023 | Illumina | II | 2 | Sequencing instrument software |
| Dec 11, 2023 | Getinge | II | 5 | Remote login could allow tampering or code execution |
| Apr 7, 2025 | Baxter | I | 2 | Ventilation system; vulnerability "discovered through internal testing" |
| Apr 10, 2025 | Contec | II | 1 | Patient monitor with "nine identified cybersecurity vulnerabilities" |
| Oct 1, 2025 | Abiomed | I | 1 | Heart pump controller's operating system |
| Oct 24, 2025 | Edan | II | 16 | Followed an FDA "It Has Come to Our Attention" letter |
| Jan 30, 2026 | GE Medical Systems | II | 3 | Image viewer; login details may be exposed |
| Jun 9, 2026 | CMR Surgical | II | 1 | Secure Boot "mistakenly not enabled at manufacturing time" |
Source: The PenTest Index, from openFDA device enforcement reports, records grouped by recall event; data updated September 30, 2026; checked October 8, 2026. openFDA says to "assume all results are unvalidated." Class I definition: FDA.
Source: The PenTest Index, from openFDA device enforcement reports, records grouped by recall event; data updated September 30, 2026; checked October 8, 2026. openFDA says to "assume all results are unvalidated." Class I definition: FDA.
Note the Baxter line. The flaw behind one of the two Class I events in this keyword result was found through internal testing. The source does not identify that testing as a penetration test.
FDA's cybersecurity safety communications
FDA's cybersecurity safety communications and alerts table contains 18 entries, dated June 13, 2013 to January 30, 2025. FDA says that for these, it "is not aware of any patient injuries or deaths associated with cybersecurity incidents." By year: 2013: 1 · 2015: 1 · 2017: 2 · 2018: 2 · 2019: 3 · 2020: 2 · 2021: 3 · 2022: 3 · 2025: 1.
Which terms are not in FDA's cybersecurity guidance?
Some advice about FDA submissions uses words the guidance itself never uses. VEX, CycloneDX, SPDX, PCCP, STRIDE, "attack tree," AAMI TIR97, eSTAR, "zero trust" and "refuse to accept" each appear zero times in the February 2026 text.
That doesn't make the advice wrong. Those can be good practice, and some come from other FDA pages (eSTAR is covered on FDA's FAQ page). It means those exact terms do not appear in this document; a related idea may use other words. If a vendor tells you "the FDA guidance requires CycloneDX," you now know to ask where.
| In the 2026 text (mentions) | Not in the 2026 text (0 mentions) |
|---|---|
| cyber device(s) (48) · SBOM/SBOMs (34) · threat model/models/modeling (31) · SPDF (28) · AAMI TIR57 (8) · ANSI/AAMI SW96 (7) · machine-readable (4) · IEC 81001-5-1 (3) · penetration (3) · fuzz (2) · MDS2 (1) | VEX · CycloneDX · SPDX · PCCP · STRIDE · attack tree · AAMI TIR97 · eSTAR · zero trust · refuse to accept |
Source: The PenTest Index text search of the February 3, 2026 guidance. Checked October 8, 2026.
Source: The PenTest Index text search of the February 3, 2026 guidance. Checked October 8, 2026.
Why does this matter now?
- The quality rule changed on February 2, 2026, and FDA reissued its cybersecurity guidance the next day. Files that cite "21 CFR 820.30" now point to a rule that has been rewritten.
- FDA's own main cybersecurity page still listed the June 2025 edition when we checked on October 8, 2026. The old label can make the current edition hard to spot.
- FDA has issued three final editions in 860 days, and Congress told FDA to review the guidance "periodically thereafter as appropriate." This tracker will log later editions as they are checked.
- Both Class I events in this keyword result began in 2025.
How we built this
We tracked 12 FDA device cybersecurity guidance documents and drafts from FDA's site, the HHS guidance portal and Internet Archive copies of FDA's files. We retrieved 11 PDFs, read their covers and counted their pages. For the 2013 draft, we verified the issue date from the 2014 final cover and official notice; its draft PDF was not retrieved. All checks were made October 8, 2026, in America/Denver (October 9 in UTC).
The edition comparison. We turned each PDF into plain text, removed repeated page banners, and left out number-only tokens. A token is a word-shaped piece of text; the full counting rule is in the notes supplied with the download. The count includes the cover, contents, headings, footnotes, glossary and guidance history.
A word counts as "carried over" if it sits inside an exact run of words that appears anywhere in the earlier edition. Words not covered by a matching run are flagged as "new or changed." This is a text-comparison measure, not a legal redline. It can count a nearby unchanged word as part of a changed passage, miss a numbers-only edit, or match wording that moved.
We tried runs of 5, 6, 8 and 10 words, counted two ways: an earlier phrase may match repeatedly, or each earlier phrase occurrence may be used once. The latter still allows overlapping phrases; it is not a one-to-one word match. We read the PDFs with two tools, PyMuPDF 1.26.6 and Poppler 24.02.0. That gives 16 runs for each comparison. The central figure uses PyMuPDF, six-word runs and reusable matches.
| Comparison | Every run we made | Central figure (6-word runs, PyMuPDF, reusable matches) |
|---|---|---|
| Feb 2026 vs June 2025: words flagged as new or changed | 2.8% to 4.0% (715 to 1,024 words) | 3.1% (780 of 25,498 words) |
| June 2025 vs Sept 2023: words flagged as new or changed | 13.6% to 18.8% (3,470 to 4,789 words) | 14.3% (3,635 of 25,466 words) |
Source: The PenTest Index comparison of the three FDA PDFs listed below. Checked October 8, 2026.
Source: The PenTest Index comparison of the three FDA PDFs listed below. Checked October 8, 2026.
The two text reads differ because PDF text isn't clean. Footnote numbers can stick to words, and table cells can come out in different orders. The range shows how the result changes with the reading and matching rules. It is not a margin of error or an estimate of the share of rules that changed.
The topic sort uses the same 780-word central result as the headline. We assigned each of its 115 unmatched passages to its main topic and checked the quality-rule passages against the PDFs. Counts include the whole passage, including nearby unchanged words. The download gives each passage, its page number, its category and the words on either side. The math is 539 + 138 + 33 + 70 = 780; each share divides that category's words by 780.
Term counts use separate searches that keep numbers. Searches are case-insensitive except for named acronyms; the dataset gives the exact pattern, case rule and page locations for each term. Counts include the whole PDF. We checked the visible 2026 footnote 41: it says "might not be available," not "must." The correct whole-word "must" count is 19. The glossary count uses definition headings in Appendix 5.
Recalls come from the complete response to this openFDA device-enforcement query. We counted 59 distinct recall numbers and grouped them by 16 distinct event IDs. We then queried each event ID without the keyword; every full-event count matched its count in the keyword result. Years use the date the recall began, not the report date or recall-number suffix. We did not add product quantities, which have different units. openFDA data was last updated September 30, 2026. Status values are kept as listed; FDA says it does not update recall status after publication in these reports.
The safety list is the 18 entries in the named table on FDA's cybersecurity page, not a census of every FDA safety notice. The MDIC resource title and displayed date were checked on its landing page; the full paper requires a form and was not used as evidence for any finding here.
The downloads contain all 32 comparison runs, all 115 unmatched passages and a source-file manifest. The full package also includes the exact PDFs and normalized text used for the comparison. The notes give the counting recipe so someone can repeat it. For the site's general source and check-date approach, see How The PenTest Index works.
What this data does and doesn't show
- It measures wording, not workload. A 3% change could still matter for your file if one of those changes touches your device.
- These are exact counts under the published extraction method; other methods can give different counts.
- The recall count is a keyword-defined subset. It finds only recall reasons that use "cybersecurity." It does not count all vulnerabilities, attacks, affected devices, patients or injuries.
- Page counts don't measure strictness.
- We compared FDA's documents. We did not test any device, and we don't know how FDA reviewers apply the guidance case by case.
- This page is not legal or regulatory advice.
How to cite this page
Cite The PenTest Index for the comparison and counts, and FDA for the guidance itself.
The PenTest Index. "FDA Cybersecurity Guidance: What Changed in 2026 and What Is Law." Updated October 2026. https://thepentestindex.com/research/fda-cybersecurity-guidance/
Each key statistic and table has its own anchor, such as #stat-1, #table-edition-comparison or #recalls, so a citation can identify the exact finding.
You may reuse our original analysis, table arrangements and charts with credit to The PenTest Index. Underlying FDA documents and openFDA data keep their source attribution and terms (openFDA terms).
Download the data
All 17 table files below are free CSVs, with no sign-up. Every row carries its source and the date we checked it. Download the full package for the tables, charts and comparison source files.
| File | What's in it | Rows |
|---|---|---|
| fda-cybersecurity-guidance-tracker.csv | 12 identified FDA device cybersecurity guidance documents and drafts, 2005–2026 | 12 |
| fda-premarket-guidance-edition-comparison.csv | The 2023, 2025 and 2026 final editions, measured | 17 |
| fda-2026-change-breakdown.csv | What the 2026 changes are about | 5 |
| fda-2025-vs-2026-testing-section-comparison.csv | Testing section, item by item, 2025 vs 2026 | 21 |
| fda-cybersecurity-law-vs-guidance.csv | Section 524B and related law, and where the guidance covers each | 12 |
| fda-table-1-submission-documents.csv | FDA's Table 1, line by line | 14 |
| fda-security-testing-elements.csv | What Section V.C says about security testing | 24 |
| fda-guidance-term-counts.csv | 39 terms counted in each of the three editions | 39 |
| fda-postmarket-30-60-day-conditions.csv | The four conditions behind the 30- and 60-day figures | 4 |
| fda-device-cybersecurity-key-dates.csv | Timeline, with the kind of each date | 23 |
| openfda-cybersecurity-recall-events.csv | 16 recall events | 16 |
| openfda-device-recalls-citing-cybersecurity.csv | The 59 product records behind them | 59 |
| openfda-cybersecurity-recalls-by-year.csv | Events and records by year, 2012–2026 | 15 |
| fda-cybersecurity-safety-communications.csv | The 18 entries in FDA's cybersecurity safety table | 18 |
| fda-phrase-comparison-all-runs.csv | 16 runs for each of the two edition comparisons | 32 |
| fda-2026-unmatched-spans.csv | Every flagged passage in the central 2026 comparison | 115 |
| fda-audit-source-manifest.csv | The exact three PDF files used for the comparisons | 3 |
Source: The PenTest Index. Every row carries its source and the date we checked it.
Frequently asked questions
What is FDA's cybersecurity guidance for medical devices in 2026?
The current premarket guidance is "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," issued February 3, 2026. It is 64 pages. A second guidance, from December 28, 2016, covers devices already on the market.
Is the June 2025 FDA cybersecurity guidance still valid?
No. The February 3, 2026 edition says it supersedes the June 27, 2025 edition. Our comparison flags about 3% of the 2026 wording as new or changed, mostly in passages about FDA's new quality rule. Use the current edition; wording overlap does not establish that a submission is ready.
What are FDA's new rules for 2026?
The Quality Management System Regulation took effect February 2, 2026. It rewrote FDA's device quality rule, 21 CFR Part 820, to pull in ISO 13485:2016. FDA reissued its cybersecurity guidance the next day.
What happened to 21 CFR 820.30?
It was the design controls section of FDA's old quality rule. In the testing section, the June 2025 guidance cited 21 CFR 820.30(f) and (g). The February 2026 edition cites ISO 13485 Subclauses 7.3.6 and 7.3.7 instead.
Is FDA cybersecurity guidance mandatory?
The guidance is not. It is marked "Contains Nonbinding Recommendations." Section 524B of the FD&C Act is law and has applied to covered cyber-device submissions since March 29, 2023: 510(k), De Novo, PMA, PDP and HDE, including relevant supplements.
Does FDA require a penetration test?
FDA recommends penetration testing as one of four kinds of security testing and says "Penetration test reports should be provided." Section 524B does not name penetration testing.
What should an FDA penetration test report include?
Five listed elements: the independence and technical expertise of the testers, the scope, the duration, the methods, and the results, findings and observations. The same five were in the June 2025 edition. FDA also recommends the manufacturer's assessment and plans for findings left unresolved or deferred to later releases.
Does FDA require an outside firm to do the testing?
Not in every case. The guidance asks who did the testing and how independent they were, and says third parties may be necessary "in some cases."
What is a cyber device?
A device with software validated, installed or authorized by its sponsor, the ability to connect to the internet, and sponsor-validated, installed or authorized features that could be open to cyber threats. All three must be true.
What SBOM format does FDA require?
The guidance names none. It asks for a machine-readable SBOM that follows NTIA's minimum elements and says "Industry-accepted formats of SBOMs are encouraged."
How fast must a maker patch a vulnerability?
Section 524B gives no fixed number of days for those patches. It says "as soon as possible out of cycle" for critical vulnerabilities that could cause uncontrolled risks. FDA's 2016 postmarket guidance calls for action as soon as possible, with 30 days for communication and planning and 60 days for a validated, deployable fix, as two of four conditions for not enforcing Part 806 reporting. Both clocks start when the maker learns of the vulnerability.
What is in Appendix 1?
Eight categories of security controls: authentication, authorization, cryptography, code/data/execution integrity, confidentiality, event detection and logging, resiliency and recovery, and firmware and software updates.
Where is the FDA cybersecurity guidance PDF?
On FDA's site at fda.gov/media/119933/download. The cover should read "Document issued on February 3, 2026."
Sources
-
FDA. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (PDF). Issued February 3, 2026. Checked October 8, 2026.
-
FDA. Same document on the HHS guidance portal (PDF). Checked October 8, 2026.
-
FDA. June 27, 2025 edition, HHS guidance portal (PDF). Checked October 8, 2026.
-
FDA. September 27, 2023 edition, Internet Archive copy of fda.gov (PDF). Checked October 8, 2026.
-
FDA. Guidance page for the current edition. Checked October 8, 2026.
-
FDA. Cybersecurity (Digital Health Center of Excellence). Content current as of July 6, 2026. Checked October 8, 2026.
-
FDA. Cybersecurity in Medical Devices Frequently Asked Questions. Checked October 8, 2026.
-
U.S. Code. 21 U.S.C. 360n-2, Ensuring cybersecurity of devices (GovInfo). Checked October 8, 2026.
-
FDA. Postmarket Management of Cybersecurity in Medical Devices (PDF). Issued December 28, 2016. Checked October 8, 2026.
-
FDA. Quality Management System Regulation (QMSR). Checked October 8, 2026.
-
Federal Register. Notices of availability: 2013 draft, 2014 final, 2016 postmarket draft, 2016 postmarket final, 2018 draft, 2022 draft, 2023 refuse-to-accept policy, 2023 final, 2024 draft, 2025 final. Checked October 8, 2026.
-
FDA. Earlier guidance PDFs, Internet Archive copies of fda.gov files: 2005 OTS guidance, 2014 final, 2016 postmarket draft, 2018 draft, 2022 draft, 2024 draft. Checked October 8, 2026.
-
openFDA. Device enforcement reports, reason_for_recall: cybersecurity. Data updated September 30, 2026. Checked October 8, 2026.
-
FDA. Recalls Background and Definitions. Checked October 8, 2026.
-
MDIC. Validating Medical Device Cybersecurity Through Penetration Testing. Listed on FDA's Cybersecurity page June 29, 2026. Checked October 8, 2026.
-
FDA. March 29, 2023 announcement of the refuse-to-accept guidance, and the archived PDF with a March 30, 2023 cover date. The dates differ and are recorded separately. Checked October 8, 2026.
-
eCFR. 21 CFR 10.115, Good guidance practices. Checked October 8, 2026.
-
openFDA. Device enforcement reports documentation. Checked October 8, 2026.
-
FDA. Premarket Notification 510(k). Checked October 8, 2026.
The PenTest Index Research is the research and reference section of thepentestindex.com.