FDA Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions
FDA guidance establishing cybersecurity expectations for medical device manufacturers throughout the total product lifecycle. 42 requirements across secure product development framework (SPDF), threat modelling, security architecture, authentication and authorisation, cryptography and data protection, software bill of materials (SBOM), security testing and vulnerability management, postmarket monitoring and coordinated vulnerability disclosure, patch and update management, labelling and transparency, and interoperability security. Addresses both premarket submission requirements and postmarket management obligations. Enacted under Section 524B of the FD&C Act (Consolidated Appropriations Act 2023).
AC (8) AU (8) CA (4) CM (6) CP (6) IA (11) IR (8) MP (3) PL (4) PM (12) RA (7) SA (10) SC (10) SI (10) SR (4)
AC Access Control
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| AC-01 | Policy and Procedures | SA-1 |
| AC-02 | Account Management | SA-1 |
| AC-03 | Access Enforcement | SA-1SA-4 |
| AC-04 | Information Flow Enforcement | SA-4TM-2 |
| AC-06 | Least Privilege | SA-1SA-4 |
| AC-07 | Unsuccessful Logon Attempts | SA-1 |
| AC-14 | Permitted Actions Without Identification or Authentication | SA-1 |
| AC-24 | Access Control Decisions | SA-1 |
AU Audit and Accountability
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| AU-02 | Event Logging | SA-5 |
| AU-03 | Content of Audit Records | SA-5 |
| AU-04 | Audit Log Storage Capacity | SA-5 |
| AU-05 | Response to Audit Logging Process Failures | SA-5 |
| AU-06 | Audit Record Review, Analysis, and Reporting | SA-5 |
| AU-08 | Time Stamps | SA-5 |
| AU-09 | Protection of Audit Information | SA-5 |
| AU-12 | Audit Record Generation | SA-5 |
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| CM-02 | Baseline Configuration | PU-2SA-3 |
| CM-03 | Configuration Change Control | PU-1PU-2SA-3 |
| CM-04 | Impact Analyses | PU-1 |
| CM-05 | Access Restrictions for Change | SA-3 |
| CM-06 | Configuration Settings | PU-2SPDF-3 |
| CM-08 | System Component Inventory | 524B-1SBOM-1SBOM-2SBOM-3ST-4 |
CP Contingency Planning
IA Identification and Authentication
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| IA-01 | Policy and Procedures | SA-1 |
| IA-02 | Identification and Authentication (Organizational Users) | SA-1 |
| IA-03 | Device Identification and Authentication | SA-1 |
| IA-04 | Identifier Management | SA-1 |
| IA-05 | Authenticator Management | SA-1 |
| IA-06 | Authentication Feedback | SA-1 |
| IA-07 | Cryptographic Module Authentication | SA-1 |
| IA-08 | Identification and Authentication (Non-organizational Users) | SA-1 |
| IA-09 | Service Identification and Authentication | SA-1 |
| IA-11 | Re-authentication | SA-1 |
| IA-12 | Identity Proofing | SA-1 |
IR Incident Response
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| IR-01 | Policy and Procedures | INC-1 |
| IR-02 | Incident Response Training | INC-1 |
| IR-03 | Incident Response Testing | INC-1 |
| IR-04 | Incident Handling | INC-1INC-2VR-1 |
| IR-05 | Incident Monitoring | INC-1INC-2VR-1 |
| IR-06 | Incident Reporting | 524B-3CVD-1CVD-2INC-1INC-3 |
| IR-07 | Incident Response Assistance | 524B-3CVD-1INC-1 |
| IR-08 | Incident Response Plan | INC-1 |
MP Media Protection
PL Planning
PM Program Management
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| PM-01 | Information Security Program Plan | 524B-4SPDF-1 |
| PM-04 | Plan of Action and Milestones Process | 524B-2INC-3VR-2 |
| PM-07 | Enterprise Architecture | SPDF-1 |
| PM-09 | Risk Management Strategy | 524B-4CRA-2CRA-3SPDF-2TM-3TR-2VR-1 |
| PM-11 | Mission and Business Process Definition | CRA-2 |
| PM-12 | Insider Threat Program | TM-1 |
| PM-15 | Security and Privacy Groups and Associations | 524B-2524B-3CVD-1CVD-2MON-1MON-3 |
| PM-16 | Threat Awareness Program | MON-1MON-3TM-1 |
| PM-20 | Dissemination of Privacy Program Information | TR-1 |
| PM-21 | Accounting of Disclosures | TR-1 |
| PM-22 | Personally Identifiable Information Quality Management | CVD-1 |
| PM-28 | Risk Framing | SPDF-2 |
RA Risk Assessment
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| RA-01 | Policy and Procedures | SPDF-2 |
| RA-02 | Security Categorization | SPDF-2 |
| RA-03 | Risk Assessment | 524B-4CRA-1CRA-2CRA-3INC-2MON-2SPDF-2TM-1TM-2TM-3TR-2VR-1 |
| RA-05 | Vulnerability Monitoring and Scanning | 524B-2CRA-1MON-1MON-2SBOM-3ST-1ST-2ST-3ST-4TM-1 |
| RA-07 | Risk Response | CRA-3INC-2MON-2SPDF-2TM-3TR-2VR-1VR-2 |
| RA-09 | Criticality Analysis | CRA-2SPDF-2 |
| RA-10 | Threat Hunting | CRA-1MON-3ST-2TM-1 |
SA System and Services Acquisition
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| SA-03 | System Development Life Cycle | SPDF-1 |
| SA-04 | Acquisition Process | 524B-1SBOM-1 |
| SA-05 | System Documentation | SPDF-3TR-1TR-2TR-3 |
| SA-08 | Security and Privacy Engineering Principles | SPDF-1SPDF-3TM-2TM-3 |
| SA-09 | External System Services | TR-3 |
| SA-10 | Developer Configuration Management | 524B-1PU-1SA-3SBOM-1SBOM-2 |
| SA-11 | Developer Testing and Evaluation | 524B-4CRA-1PU-1ST-1ST-2ST-3ST-4TM-1 |
| SA-15 | Development Process, Standards, and Tools | SPDF-1ST-1 |
| SA-17 | Developer Security and Privacy Architecture and Design | SPDF-1SPDF-3TM-2 |
| SA-22 | Unsupported System Components | PU-2PU-3 |
SC System and Communications Protection
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| SC-04 | Information in Shared System Resources | SA-4 |
| SC-07 | Boundary Protection | PU-3TM-2 |
| SC-08 | Transmission Confidentiality and Integrity | SA-2SA-4 |
| SC-12 | Cryptographic Key Establishment and Management | SA-2 |
| SC-13 | Cryptographic Protection | SA-2 |
| SC-17 | Public Key Infrastructure Certificates | SA-2 |
| SC-23 | Session Authenticity | SA-2 |
| SC-24 | Fail in Known State | SA-6 |
| SC-28 | Protection of Information at Rest | SA-2SA-4 |
| SC-34 | Non-modifiable Executable Programs | SA-3 |
SI System and Information Integrity
| Control | Name | FDA Cybersecurity Guidance References |
|---|---|---|
| SI-02 | Flaw Remediation | 524B-2MON-2PU-1PU-2PU-3SBOM-2SBOM-3VR-2 |
| SI-03 | Malicious Code Protection | PU-3 |
| SI-04 | System Monitoring | MON-3PU-3SA-5 |
| SI-05 | Security Alerts, Advisories, and Directives | 524B-2524B-3CVD-1CVD-2INC-3MON-1MON-2MON-3SBOM-3 |
| SI-06 | Security and Privacy Function Verification | SA-5 |
| SI-07 | Software, Firmware, and Information Integrity | SA-3ST-1 |
| SI-10 | Information Input Validation | ST-3 |
| SI-13 | Predictable Failure Prevention | SA-6 |
| SI-16 | Memory Protection | SA-3 |
| SI-17 | Fail-safe Procedures | SA-6 |