Contains Nonbinding Recommendations
5
Additionally, section 3305 of the Food and Drug Omnibus Reform Act of 2022 (“FDORA”), 
enacted on December 29, 2022, added section 524B “Ensuring Cybersecurity of Medical 
Devices” to the FD&C Act. Effective March 29, 2023, with respect to premarket submissions for 
“cyber devices,” section 524B(a) provides that sponsors must include information to ensure the 
device meets the cybersecurity requirements under section 524B(b).14 Under section 524B(a) of 
the FD&C Act, a person who submits a 510(k), PMA, PDP, De Novo, or HDE for a device that 
meets the definition of a cyber device, as defined under section 524B(c), is required to submit 
information to ensure that cyber devices meet the cybersecurity requirements under section 
524B(b).15 Section 524B(c) of the FD&C Act defines “cyber device” as a device that “(1) 
includes software validated, installed, or authorized by the sponsor as a device or in a device; (2) 
has the ability to connect to the internet; and (3) contains any such technological characteristics 
validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity 
threats” (see Section VII.B for more information on the term “cyber device”). The 
recommendations in this guidance are intended to help manufacturers meet their obligations 
under section 524B of the FD&C Act.
IV. General Principles 
This section provides general principles for device cybersecurity relevant to device 
manufacturers. The principles in this guidance are important to the improvement of device 
cybersecurity and, when followed, are expected to have a positive impact on the safety and 
effectiveness of the device. The recommendations in this guidance cover all relevant 
cybersecurity considerations that may affect device safety and effectiveness, including but not 
limited to software, hardware, and firmware. 
A.
Cybersecurity is Part of Device Safety and the Quality 
Management System Regulation (QMSR) 
Device manufacturers must establish and follow quality management systems to help ensure that 
their products consistently meet applicable requirements and specifications. The quality 
management systems requirements are found in the QMSR in 21 CFR Part 820, which 
incorporates by reference ISO 13485. Depending on the device, QMS requirements may be 
relevant at the premarket stage, postmarket stage,16 or both. 
14 While section 524B(b)(4) of the FD&C Act authorizes FDA to promulgate additional cybersecurity requirements 
via regulation, FDA is not required to promulgate a regulation to elaborate on the new requirements specified in 
section 524B of the FD&C Act.
15 In addition to the cybersecurity requirements set forth in section 524B(b) of the FD&C Act, section 524B(b)(4) of 
the FD&C Act requires cyber device manufacturers to comply with any other such requirements FDA sets forth in 
regulations “to demonstrate reasonable assurance that the device and related systems are cybersecure.”
16 In the postmarket context, design and development may also be important to ensure medical device cybersecurity 
and maintain medical device safety and effectiveness. FDA recommends that device manufacturers implement 
comprehensive cybersecurity risk management programs and documentation consistent with the QMSR, including 
but not limited to complaint handling (ISO 13485 Subclause 8.2.2 and 21 CFR 820.35(a)), quality audit (Subclause 
8.2.4), analysis of data and improvement (Subclauses 8.4 and 8.5), software validation (Subclause 7.3.7), risk 
management (Subclause 7.1), and servicing (Subclause 7.5.4 and 21 CFR 820.35(b)). 
