Contains Nonbinding Recommendations 
 
 
 
 6 
part of the premarket submission.16 This guidance is intended to explain how such 
documentation that may be relevant for QS regulation compliance can also be used to show how 
a sponsor or manufacturer is addressing cybersecurity considerations relevant to a device. For 
example, 21 CFR 820.30(a) requires that for all classes of devices automated with software, a 
manufacturer must establish and maintain procedures to control the design of the device in order 
to ensure that specified design requirements are met (“design controls”). As part of design 
controls, a manufacturer must “establish and maintain procedures for validating the device 
design,” which “shall include software validation and risk analysis, where appropriate” (21 CFR 
820.30(g)). As part of the software validation and risk analysis required by 21 CFR 820.30(g), 
software device manufacturers may need to establish cybersecurity risk management and 
validation processes, where appropriate. See also FDA’s guidance titled “Content of Premarket 
Submissions for Device Software Functions.”  
 
Software validation and risk management are key elements of cybersecurity analyses and 
demonstrating whether a device has a reasonable assurance of safety and effectiveness. FDA 
requires manufacturers to implement development processes that account for and address 
software risks throughout the design and development process as part of design controls, as 
discussed in FDA’s regulations regarding design control, which may include cybersecurity 
considerations.17 For example, these processes should address the identification of security risks, 
the design requirements for how the risks will be controlled, and the evidence that the controls 
function as designed and are effective in their environment of use for ensuring adequate security.  
1. 
A Secure Product Development Framework (SPDF) may be 
one way to satisfy the QS regulation 
Cybersecurity threats have the potential to exploit one or more vulnerabilities that could lead to 
patient harm. The greater the number of vulnerabilities that exist and/or are identified over time 
in a system in which a device operates, the easier a threat can compromise the safety and 
effectiveness of the medical device. An SPDF is a set of processes that help identify and reduce 
the number and severity of vulnerabilities in products. An SPDF encompasses all aspects of a 
product’s lifecycle, including design, development, release, support, and decommission. 
Additionally, using SPDF processes during device design may prevent the need to re-engineer 
the device when connectivity-based features are added after marketing and distribution, or when 
vulnerabilities resulting in uncontrolled risks are discovered. An SPDF can be integrated with 
existing processes for product and software development, risk management, and the quality 
system at large.  
 
Using an SPDF is one approach to help ensure that the QS regulation is met. Because of its 
benefits in helping comply with the QS regulation and cybersecurity, FDA encourages 
manufacturers to use an SPDF, but other approaches might also satisfy the QS regulation. 
 
16 The recommendations in this guidance are not intended to suggest that FDA will evaluate an applicant’s 
compliance with the QS regulation as part of its premarket submission under section 510(k) of the FD&C Act in our 
determination of a device’s substantial equivalence, as this is not a requirement for such decision under section 
513(i) of the FD&C Act. This guidance is intended to explain how FDA evaluates the performance of device 
cybersecurity and the cybersecurity outputs of activities that are part and parcel of QS regulation compliance, and 
explain how the QS regulation can be leveraged to demonstrate these performance outputs. 
17 See 21 CFR 820.30. 
