Contains Nonbinding Recommendations 
 
 
 
 4 
outline FDA’s recommendations for premarket submission information to address cybersecurity 
concerns.  
 
One way these TPLC considerations for devices can be achieved is through the implementation 
and adoption of a Secure Product Development Framework (SPDF).10 An SPDF, as described in 
this guidance, is a set of processes that reduces the number and severity of vulnerabilities in 
products throughout the device lifecycle. Examples of such frameworks exist in many sectors, 
including the medical device sector.  
 
Risk management for device manufacturers is the essential systematic practice of identifying, 
analyzing, evaluating, controlling, and monitoring risk throughout the product lifecycle to ensure 
that the devices they manufacture are safe and effective. The Quality System (QS) regulation in 
21 CFR Part 820 explicitly addresses risk management activities in 21 CFR 820.30(g). FDA 
issued a final rule11 amending the device current good manufacturing practice (CGMP) 
requirements of the Quality System (QS) Regulation under 21 CFR 820 to align more closely 
with the international consensus standard for Quality Management Systems for medical devices 
used by many other regulatory authorities around the world, and the final rule incorporates risk 
management throughout its requirements.12 
 
The recommendations contained in this guidance are intended to supplement FDA’s Postmarket 
Cybersecurity Guidance, and “Content of Premarket Submissions for Device Software 
Functions,” hereafter referred to as the “Premarket Software Guidance.” This guidance replaces 
the 2014 final guidance “Content of Premarket Submissions for Management of Cybersecurity in 
Medical Devices.”  
 
The recommendations in this guidance also generally align with or expand upon the 
recommendations in the Pre-Market Considerations for Medical Device Cybersecurity section of 
the International Medical Device Regulators Forum (IMDRF) final guidance “Principles and 
Practices for Medical Device Cybersecurity,” issued in March 2020.  
 
Additionally, section 3305 of the Food and Drug Omnibus Reform Act of 2022 (“FDORA”), 
enacted on December 29, 2022, added section 524B “Ensuring Cybersecurity of Medical 
Devices” to the FD&C Act. Effective March 29, 2023, with respect to premarket submissions for 
“cyber devices,” section 524B(a) provides that sponsors must include information to ensure the 
 
10 See Appendix 5, Terminology.  
11 See 89 FR 7496. 
12 See 89 FR 7496 at 7505. On February 2, 2024, FDA issued a final rule amending the device Quality System 
Regulation, 21 CFR Part 820, to align more closely with international consensus standards for devices (89 FR 7496). 
This final rule will take effect on February 2, 2026. Once in effect, this rule will withdraw the majority of the current 
requirements in Part 820 and instead incorporate by reference the 2016 edition of the International Organization for 
Standardization (ISO) 13485, Medical devices - Quality management systems – Requirements for regulatory 
purposes, in Part 820. As stated in the final rule, the requirements in ISO 13485 are, when taken in totality, 
substantially similar to the requirements of the current Part 820, providing a similar level of assurance in a firm’s 
quality management system and ability to consistently manufacture devices that are safe and effective and otherwise 
in compliance with the FD&C Act. When the final rule takes effect, FDA will also update this guidance, including 
the references to provisions in Part 820 in this guidance to be consistent with the rule. 
