Contains Nonbinding Recommendations 
 
 
 
 20 
Under 21 CFR 820.30(b), a manufacturer must establish and maintain plans that describe or 
reference the design and development activities and define responsibility for implementation. 
Such plans must be reviewed, updated, and approved as design and development evolves (21 
CFR 820.30(b)). Under 21 CFR 820.30(c), a manufacturer must establish and maintain 
procedures to ensure that the design requirements relating to a device are appropriate and address 
the intended use of the device, including the needs of the user and patient. Under 21 CFR 
820.30(d), a manufacturer must establish and maintain procedures for defining and documenting 
design output in terms that allow an adequate evaluation of conformance to design input 
requirements. 21 CFR 820.30(d) also states that design output procedures shall contain or make 
reference to acceptance criteria and shall ensure that those design outputs that are essential for 
the proper functioning of the device are identified.  
 
FDA recommends that these plans and procedures include design processes, design 
requirements, and acceptance criteria for the security architecture of the device such that they 
holistically address the cybersecurity considerations for the device and the system in which the 
device operates. FDA recommends that all medical devices provide and enforce the security 
objectives in Section IV, above, but recognizes that implementations to address the security 
objectives may vary. 
 
FDA recommends that premarket submissions include documentation on the security 
architecture. The objective in providing security architecture information in premarket 
submissions is to provide to FDA the security context and trust-boundaries of the medical device 
system in terms of the interfaces, interconnections, and interactions that the medical device 
system has with external entities. The details of these elements enable the identification of the 
parts of the medical device system in or through which incidents might occur. These details help 
to provide a sufficient understanding of the system such that FDA can evaluate adequacy of the 
architecture itself as it relates to safety and effectiveness. 
 
Manufacturers should analyze the entire system to understand the full environment and context 
in which the device is expected to operate. The security architecture should include a 
consideration of system-level risks, including but not limited to risks related to the supply chain 
(e.g., to ensure the device remains free of malware, or vulnerabilities inherited from upstream 
dependencies such as third-party software, among others), design, production, and deployment 
(i.e., into a connected/networked environment).  
 
FDA recommends that this architecture information take the form of “views,” and that these 
views be provided during premarket submissions to demonstrate safety and effectiveness.41 If the 
documentation identified in this section already exists in other risk management documentation, 
FDA does not expect manufacturers to separate out this information into new document(s); such 
documentation can be provided and the submission can reference the relevant sections.  
 
Below, FDA outlines the recommended security controls and ways to document the resultant 
security architecture in premarket submissions through specific Security Architecture Views.  
 
 
41 Views are discussed in more detail in the following subsections and Appendix 2. 
