The RND Group, a Gener8 company
Menu
Cybersecurity

Medical Device Cybersecurity and FDA Section 524B

Updated September 30, 2026 · Originally published March 11, 2019

Connected medical devices, from blood pressure monitors to hospital-networked instruments, carry cybersecurity risks that cannot be fully eliminated, only managed. The FDA addresses this through two connected expectations: security built in at premarket submission, and a cybersecurity risk management program that continues for the life of the device.

Cybersecurity Became a Statutory Requirement in 2023

This article was first published in 2019, when FDA cybersecurity expectations were set out in guidance rather than law. That changed with the December 2022 Consolidated Appropriations Act (the omnibus spending bill), which added Section 524B to the Federal Food, Drug, and Cosmetic Act. FDA has enforced it since 2023. Manufacturers of qualifying “cyber devices,” devices with internet connectivity and manufacturer-controlled software that could be vulnerable to cybersecurity threats, must now submit cybersecurity information with every premarket submission, including a software bill of materials (SBOM). RND’s FDA premarket cybersecurity services help manufacturers meet this requirement as part of their submission strategy.

Premarket and Postmarket Cybersecurity Risk Management

Today’s medical devices are interconnected with the internet, hospital networks, and other medical devices to improve care and give providers better tools to treat patients. Those same connections widen the attack surface for outside threat actors. Such devices are vulnerable to security breaches that can affect the safety and effectiveness of the device. These threats cannot be eliminated entirely, which is why reducing cybersecurity risk is an ongoing challenge rather than a one-time fix.

FDA’s cybersecurity expectations take a holistic approach, split into two parts: premarket submission and postmarket management. The premarket portion applies during device design and includes provisions for building in security from the start. Postmarket management addresses the device’s full lifecycle, monitoring and updating the product to keep pace with an evolving threat environment.

The premarket expectations cover limiting access to trusted users, recommending individual user accounts, strong passwords, a layered access approach, and physical access controls. Beyond access control, secure data transfer into and out of the application is a necessity, along with a means to verify the authenticity of patches and upgrades.

Prevention alone is not enough. The system should be designed to allow detection, response, and recovery from threats and intrusions.

View the FDA Fact Sheet here.

As part of a premarket submission, FDA looks for a clear indication that cybersecurity was addressed through security-related requirements and features documented in key submission artifacts. The keystone is the device’s hazard analysis, which should include all cybersecurity risks, justifications, and controls. Those risks should also appear in a traceability matrix demonstrating implementation, along with a summary describing the cybersecurity controls in place. Cybersecurity also belongs in the maintenance plan, or in a dedicated cybersecurity plan within the premarket submission package.

Cybersecurity is not a one-time effort. It is a continuous process, and postmarket expectations address the evolving threat environment by defining business processes rather than device-specific detail.

Postmarket expectations call for a cybersecurity risk management program operated by the manufacturer, aimed at identifying, protecting against, detecting, responding to, and recovering from cybersecurity threats. That program draws input from sources such as quality audits, corrective and preventive actions, customer complaints, and an Information Sharing and Analysis Organization, a nonprofit structure that gathers information on cyber threats to critical infrastructure and shares it between the private and public sectors. Those inputs then feed a formal risk analysis process focused on patient safety impact.

FDA recognizes that cybersecurity is a shared responsibility among device designers, manufacturers, healthcare facilities, and end users. RND Group has worked alongside clients to address FDA cybersecurity expectations as part of their device submissions. For more than 25 years, The RND Group has applied the rigor required to design, develop, document, and test products in the evolving FDA regulated environment.

Standards referenced

Have a device that has to hold up in an FDA submission?

Bring us your device and where it sits in its lifecycle. We will help you plan the clearest path forward with a senior medical device software expert.

Talk to an expert
Talk to a medical device software expert