Contains Nonbinding Recommendations
30
A revision-controlled, Manufacturer Disclosure Statement for Medical Device Security (MDS2)
and Customer Security Documentation as outlined in the Medical Device and Health IT Joint 
Security Plan version 2 (JSP2) may address a number of the above recommendations.
B.
Cybersecurity Management Plans 
Recognizing that cybersecurity risks evolve as technology evolves throughout a device’s TPLC, 
FDA recommends that manufacturers establish a plan for how they will identify and 
communicate to the relevant parties the vulnerabilities that are identified after releasing the 
device in accordance with Subclause 8.4 and Subclause 8.5 of ISO 13485, and 21 CFR Part 806, 
as appropriate. This plan can also support security risk management processes that are described 
throughout the QMSR and ISO 13485, as incorporated by reference in the QMSR.
FDA recommends that manufacturers submit their cybersecurity management plans as part of 
their premarket submissions so that FDA can assess whether the manufacturer has sufficiently 
addressed how to maintain the safety and effectiveness of the device after marketing 
authorization is achieved. For cyber devices, “a plan to monitor, identify, and address, as 
appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, 
including coordinated vulnerability disclosure and related procedures” is required (see section 
524B(b)(1) of the FD&C Act and Section VII.C.1 of this guidance). 
Cybersecurity management plans should include the following elements:
·
Personnel responsible;
·
Sources, methods, and frequency for monitoring and identifying vulnerabilities (e.g., 
researchers, NIST national vulnerability database (NIST NVD), third-party software 
manufacturers);
·
Identify and address vulnerabilities identified in CISA’s Known Exploited Vulnerabilities 
Catalog;
·
Periodic security testing;
·
Timeline to develop and release patches; 
·
Update processes;
·
Patching capability (i.e., rate at which update can be delivered to devices); 
·
Description of their coordinated vulnerability disclosure process; and
·
Description of how the manufacturer intends to communicate forthcoming remediations, 
patches, and updates to customers. 
Additional recommendations on coordinated vulnerability disclosure plans may be found in 
FDA’s Postmarket Cybersecurity Guidance.
VII. Cyber Devices 
This section identifies the cybersecurity information FDA considers to generally be necessary to 
support obligations under section 524B of the FD&C Act for cyber devices. This section 
provides recommendations specifically for cyber devices. Manufacturers of cyber devices should 
also consider the recommendations throughout this guidance to help meet their obligations under 
section 524B.   
