Contains Nonbinding Recommendations 
 
 
 
 5 
device meets the cybersecurity requirements under section 524B(b).13 Under section 524B(a) of 
the FD&C Act, a person who submits a 510(k), PMA, PDP, De Novo, or HDE for a device that 
meets the definition of a cyber device, as defined under section 524B(c), is required to submit 
information to ensure that cyber devices meet the cybersecurity requirements under section 
524B(b).14 Section 524B(c) of the FD&C Act defines “cyber device” as a device that “(1) 
includes software validated, installed, or authorized by the sponsor as a device or in a device; (2) 
has the ability to connect to the internet; and (3) contains any such technological characteristics 
validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity 
threats” (see Section VII.B for more information on the term “cyber device”). The 
recommendations in this guidance are intended to help manufacturers meet their obligations 
under section 524B of the FD&C Act. 
 
IV. General Principles 
This section provides general principles for device cybersecurity relevant to device 
manufacturers. The principles in this guidance are important to the improvement of device 
cybersecurity and, when followed, are expected to have a positive impact on the safety and 
effectiveness of the device. The recommendations in this guidance cover all relevant 
cybersecurity considerations that may affect device safety and effectiveness, including but not 
limited to software, hardware, and firmware.  
A. 
Cybersecurity is Part of Device Safety and the Quality 
System Regulation 
Device manufacturers must establish and follow quality systems to help ensure that their 
products consistently meet applicable requirements and specifications. The quality systems 
requirements are found in the QS regulation in 21 CFR Part 820. Depending on the device, QS 
requirements may be relevant at the premarket stage, postmarket stage,15 or both.  
 
In the premarket context, in order to demonstrate a reasonable assurance of safety and 
effectiveness for certain devices with cybersecurity risks, documentation outputs related to the 
ongoing requirements of the QS regulation may be one source of documentation to include as 
 
13 While section 524B(b)(4) of the FD&C Act authorizes FDA to promulgate additional cybersecurity requirements 
via regulation, FDA is not required to promulgate a regulation to elaborate on the new requirements specified in 
section 524B of the FD&C Act. 
14 In addition to the cybersecurity requirements set forth in section 524B(b) of the FD&C Act, section 524B(b)(4) of 
the FD&C Act requires cyber device manufacturers to comply with any other such requirements FDA sets forth in 
regulations “to demonstrate reasonable assurance that the device and related systems are cybersecure.” 
15 In the postmarket context, design controls may also be important to ensure medical device cybersecurity and 
maintain medical device safety and effectiveness. FDA recommends that device manufacturers implement 
comprehensive cybersecurity risk management programs and documentation consistent with the QS regulation, 
including but not limited to complaint handling (21 CFR 820.198), quality audit (21 CFR 820.22), corrective and 
preventive action (21 CFR 820.100), software validation and risk analysis (21 CFR 820.30(g)), and servicing (21 
CFR 820.200).  
