Contains Nonbinding Recommendations
8
device system is more likely to be secure by design, such that the device is designed from the 
outset to be secure within its system and/or network of use throughout the device lifecycle.
C.
Transparency 
A lack of cybersecurity information, such as information necessary to integrate the device into 
the use environment, as well as information needed by users to maintain the medical device 
system’s cybersecurity over the device lifecycle, has the potential to affect the safety and 
effectiveness of a device. In order to address these concerns, it is important for device users to 
have access to information pertaining to the device’s cybersecurity controls, potential risks to the 
medical device system, and other relevant information. For example:
·
A failure to disclose all of the communication interfaces or third-party software could fail 
to convey potential sources of risks;
·
Insufficient information pertaining to whether a device has known but not disclosed 
cybersecurity vulnerabilities or risks may be relevant to determining whether a device’s 
safety or effectiveness could be degraded; and/or
·
Labeling that does not include sufficient information to explain how to securely configure 
or update the device may limit the ability of end users to appropriately manage and 
protect the medical device system.
This information and other relevant information are important in helping users understand a 
medical device system’s resilience to cybersecurity threats, the threats that it may be exposed to, 
and how those threats may be prevented or mitigated. Without it, cybersecurity risks could be 
undisclosed, inappropriately identified, or inappropriately responded to, among other potential 
impacts, which could lead to compromises in device safety and effectiveness.
FDA believes that the cybersecurity information discussed in this guidance is important for the 
safe and effective use of devices and should be included in device labeling, as discussed below in 
Section VI. 
D.
Submission Documentation 
Device cybersecurity design and documentation are expected to scale with the cybersecurity risk 
of that device. Manufacturers should take into account the larger system in which the device may 
be used. For example, a cybersecurity risk assessment performed on a simple, non-connected 
thermometer may conclude that the risks are limited, and therefore such a device needs only a 
limited security architecture (i.e., addressing only device hardware and software) and few 
security controls based on the technical characteristics and design of the device. However, if a 
thermometer is used in a safety-critical control loop, or is connected to networks or other 
devices, then the cybersecurity risks for the device are considered to be greater and more 
substantial design and development activities should result. Submitters should consider including 
in premarket submissions to FDA documentation generated from those design and development 
activities used during the development of a device with cybersecurity risks as a way to 
demonstrate reasonable assurance of safety and effectiveness. This guidance identifies the 
