Contains Nonbinding Recommendations
4
be capable of mitigating emerging cybersecurity risks throughout the TPLC, and to more clearly 
outline FDA’s recommendations for premarket submission information to address cybersecurity 
concerns. 
One way these TPLC considerations for devices can be achieved is through the implementation 
and adoption of a Secure Product Development Framework (SPDF).10 An SPDF, as described in 
this guidance, is a set of processes that reduces the number and severity of vulnerabilities in 
products throughout the device lifecycle. Examples of such frameworks exist in many sectors 
including the medical device sector. 
Risk management for device manufacturers is the essential systematic practice of identifying, 
analyzing, evaluating, controlling, and monitoring risk throughout the product lifecycle to ensure 
that the devices they manufacture are safe and effective. FDA issued a final rule11 amending the 
device current good manufacturing practice (cGMP) requirements of the Quality System (QS) 
Regulation under 21 CFR 820 to align more closely with the international consensus standard for 
Quality Management Systems (QMS) for medical devices used by many other regulatory 
authorities around the world. This revised Part 820 is referred to as the Quality Management 
System Regulation (QMSR). 
The QMSR incorporates by reference the 2016 edition of ISO 13485.12 By incorporating ISO 
13485 by reference, we are explicitly requiring current internationally recognized regulatory 
expectations for QMS for devices subject to FDA’s jurisdiction. Of particular note for this 
guidance, ISO 13485, incorporated into the QMSR by reference, incorporates risk management 
throughout its requirements.13
The recommendations contained in this guidance are intended to supplement FDA’s Postmarket 
Cybersecurity Guidance, and “Content of Premarket Submissions for Device Software 
Functions,” hereafter referred to as the “Premarket Software Guidance.” This guidance replaces 
the 2014 final guidance “Content of Premarket Submissions for Management of Cybersecurity in 
Medical Devices.”
The recommendations in this guidance also generally align with or expand upon the 
recommendations in the Pre-Market Considerations for Medical Device Cybersecurity section of 
the International Medical Device Regulators Forum (IMDRF) final guidance “Principles and 
Practices for Medical Device Cybersecurity,” issued in March 2020. 
10 See Appendix 5, Terminology.
11 See 89 FR 7496. This final rule took effect on February 2, 2026, and amends the majority of the requirements 
previously in 21 CFR Part 820 (Part 820) and incorporates by reference the 2016 edition of the International 
Organization for Standardization (ISO) 13485, Medical devices - Quality management systems – Requirements for 
regulatory purposes, in Part 820. As stated in the final rule, the requirements in ISO 13485 are, when taken in 
totality, substantially similar to the requirements of the previous Part 820, providing a similar level of assurance in a 
firm’s quality management system and ability to consistently manufacture devices that are safe and effective and 
otherwise in compliance with the FD&C Act.
12 All references to ISO 13485 in this guidance are to ISO 13485:2016, Medical devices — Quality management 
systems — Requirements for regulatory purposes.
13 See 89 FR 7496 at 7505. 
