Contains Nonbinding Recommendations
20
devices and/or systems that interact, and detailed information on the implementations for how 
those interactions occur and are secured. It contains information that demonstrates that the risks 
considered during the risk management process are adequately controlled, which, in turn, 
supports the demonstration of the safety and effectiveness of the medical device system.
Subclause 7.3.1 of ISO 13485 requires manufacturers to document procedures for design and 
development. Under Subclause 7.3.2, a manufacturer must establish and maintain plans that 
describe or reference the design and development activities and define responsibility for 
implementation. Such plans must be maintained and updated as design and development 
progresses (Subclause 7.3.2). Under Subclause 7.3.3, a manufacturer must determine and 
maintain inputs related to product requirements to ensure that the design requirements relating to 
a device are appropriate and address the intended use of the device. Under Subclause 7.3.4, 
design and development outputs must be in a form suitable for verification against the design and 
development inputs, and records must be maintained. Subclause 7.3.4 also states that design and 
development outputs shall contain or make reference to product acceptance criteria and shall 
ensure that those design outputs that are essential for its safe and proper use are identified. 
FDA recommends that these plans and procedures include design processes, design 
requirements, and acceptance criteria for the security architecture of the device such that they 
holistically address the cybersecurity considerations for the device and the system in which the 
device operates. FDA recommends that all medical devices provide and enforce the security 
objectives in Section IV, above, but recognizes that implementations to address the security 
objectives may vary.
FDA recommends that premarket submissions include documentation on the security 
architecture. The objective in providing security architecture information in premarket 
submissions is to provide to FDA the security context and trust-boundaries of the medical device 
system in terms of the interfaces, interconnections, and interactions that the medical device 
system has with external entities. The details of these elements enable the identification of the 
parts of the medical device system in or through which incidents might occur. These details help 
to provide a sufficient understanding of the system such that FDA can evaluate adequacy of the 
architecture itself as it relates to safety and effectiveness.
Manufacturers should analyze the entire system to understand the full environment and context 
in which the device is expected to operate. The security architecture should include a 
consideration of system-level risks, including but not limited to risks related to the supply chain 
(e.g., to ensure the device remains free of malware, or vulnerabilities inherited from upstream 
dependencies such as third-party software, among others), design, production, and deployment 
(i.e., into a connected/networked environment). 
FDA recommends that this architecture information take the form of “views,” and that these 
views be provided during premarket submissions to demonstrate safety and effectiveness.43 If the 
documentation identified in this section already exists in other risk management documentation, 
disruptions, hazards, and threats. For additional information, see NIST 800-160 vol. 1 rev. 1.
https://doi.org/10.6028/NIST.SP.800-160v1r1
43 Views are discussed in more detail in the following subsections and Appendix 2.
