Contains Nonbinding Recommendations 
 
 
 
 8 
have access to information pertaining to the device’s cybersecurity controls, potential risks to the 
medical device system, and other relevant information. For example: 
 
• A failure to disclose all of the communication interfaces or third-party software could fail 
to convey potential sources of risks; 
• Insufficient information pertaining to whether a device has known but not disclosed 
cybersecurity vulnerabilities or risks may be relevant to determining whether a device’s 
safety or effectiveness could be degraded; and/or 
• Labeling that does not include sufficient information to explain how to securely configure 
or update the device may limit the ability of end users to appropriately manage and 
protect the medical device system.  
 
This information and other relevant information are important in helping users understand a 
medical device system’s resilience to cybersecurity threats, the threats that it may be exposed to, 
and how those threats may be prevented or mitigated. Without it, cybersecurity risks could be 
undisclosed, inappropriately identified, or inappropriately responded to, among other potential 
impacts, which could lead to compromises in device safety and effectiveness. 
 
FDA believes that the cybersecurity information discussed in this guidance is important for the 
safe and effective use of devices and should be included in device labeling, as discussed below in 
Section VI.  
D. 
Submission Documentation 
Device cybersecurity design and documentation are expected to scale with the cybersecurity risk 
of that device. Manufacturers should take into account the larger system in which the device may 
be used. For example, a cybersecurity risk assessment performed on a simple, non-connected 
thermometer may conclude that the risks are limited, and therefore such a device needs only a 
limited security architecture (i.e., addressing only device hardware and software) and few 
security controls based on the technical characteristics and design of the device. However, if a 
thermometer is used in a safety-critical control loop, or is connected to networks or other 
devices, then the cybersecurity risks for the device are considered to be greater and more 
substantial design controls should result. Submitters should consider including in premarket 
submissions to FDA documentation generated from those design controls used during the 
development of a device with cybersecurity risks as a way to demonstrate reasonable assurance 
of safety and effectiveness. This guidance identifies the cybersecurity information FDA 
recommends to help support a premarket submission for devices within the scope of this 
guidance, including but not limited to cyber devices.20 
 
As cybersecurity is part of device safety and effectiveness, cybersecurity controls established 
during premarket development should also take into consideration the intended and actual use 
environment (see Section IV.B). Cybersecurity risks evolve over time and as a result, the 
effectiveness of cybersecurity controls may degrade as new risks, threats, and attack methods 
emerge. In the 510(k) context, FDA evaluates the cybersecurity information submitted and the 
 
20 As previously discussed, section 524B of the FD&C Act requires the submission of certain documentation for 
cyber devices. See Section VII of this guidance for more information on cyber devices.  
