The guidance document titled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” released on June 27, 2025, replaces the previous guidance issued on September 27, 2023. This updated version integrates content from the draft select update published on March 13, 2024, along with additional new material not included in the draft.
Key distinction: the fundamental and most significant difference between the 2023 and 2025 guidance documents is the inclusion of detailed information and requirements to help manufacturers comply with Section 524B, “Ensuring Cybersecurity of Medical Devices,” of the FD&C Act. This section was added by Section 3305 of the Food and Drug Omnibus Reform Act of 2022 (FDORA) and became effective March 29, 2023, requiring sponsors to include specific information in premarket submissions for “cyber devices.”
New statutory requirements for “cyber devices”
The 2025 guidance introduces an entirely new Section VII, Cyber Devices, which details the specific information manufacturers must now include in premarket submissions for devices meeting the “cyber device” definition. The 2023 guidance mentioned Section 524B but did not include this dedicated, comprehensive section.
For “cyber devices,” the 2025 guidance mandates submission of:
- A plan to monitor, identify, and address postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure (CVD) procedures. The plan must outline timelines for developing and releasing updates and patches — addressing “known unacceptable vulnerabilities” on a reasonably justified regular cycle, and “critical vulnerabilities that could cause uncontrolled risks” as soon as possible, out of cycle.
- Processes and procedures providing reasonable assurance that the device and related systems are cybersecure — where “related systems” includes manufacturer-controlled elements like other devices, software update servers, and connections to healthcare facility networks.
- A Software Bill of Materials (SBOM) covering commercial, open-source, and off-the-shelf components. The 2025 guidance further recommends the SBOM be machine-readable and consistent with the minimum elements identified by NTIA, including each component’s level of support and end-of-support date.
Clarifications and expanded recommendations
Beyond the new statutory requirements, the 2025 guidance provides significant elaborations and clarifications to recommendations already present in the 2023 version:
- Definition and scope of “cyber devices” — a more detailed explanation of what “ability to connect to the internet” includes under Section 524B(c): network, server, and cloud connections, various radio-frequency and magnetic inductive communications, and hardware connectors like USB, Ethernet, and serial port.
- Quality System (QS) regulation alignment — updated to reflect the final rule issued February 2, 2024, aligning the QS regulation (21 CFR Part 820) more closely with international consensus standards like ISO 13485. The 2023 guidance had referred to a proposed rule for this amendment.
- Risk management standards — adds ANSI/AAMI SW96 as an additional standard alongside AAMI TIR57, for detailing how security and safety risk management processes should interface and for content in security risk management plans and reports. The 2023 guidance primarily referenced only AAMI TIR57.
- Documentation for modifications — a new Section VII.D provides specific recommendations for documenting device modifications under Section 524B, differentiating changes likely to affect cybersecurity (e.g., changes to authentication, new connectivity) from those unlikely to (e.g., material changes, sterilization method changes).
- Reasonable assurance of cybersecurity — a new Section VII.E explains that “reasonable assurance of cybersecurity” can be part of FDA’s determination of a device’s safety and effectiveness across premarket pathways.
- SBOM as a statutory requirement — while both guidance versions recommend providing an SBOM, the 2025 guidance explicitly states that for “cyber devices,” an SBOM is required by Section 524B(b)(3) of the FD&C Act.
- Appendix 4 documentation table — the table summarizing recommended documentation elements now explicitly notes which items are required for “Cyber Devices (Sec. 524B),” a linkage the 2023 table didn’t make.
- Cybersecurity Transparency — manufacturers of cyber devices should consider the Section VI Cybersecurity Transparency recommendations as they design, develop, and maintain processes providing reasonable assurance that the device and related systems are cybersecure.
The guidance also adds a definition for “Controlled Risk” in Appendix 5, consistent with the 2016 postmarket cybersecurity guidance: “Controlled Risk” occurs “when there is sufficiently low (acceptable) residual risk of patient harm due to a device’s particular cybersecurity vulnerability.” It clarifies the distinction between a “known unacceptable vulnerability” that could still present controlled risk — where updates are aimed at maintaining software supportability on a reasonably justified regular cycle, rather than correcting a violation of the FD&C Act — and a “critical vulnerability that could cause uncontrolled risk,” which calls for an out-of-cycle update.
In summary, the 2025 guidance significantly reinforces and formalizes FDA’s expectations for medical device cybersecurity, driven primarily by the new statutory requirements for “cyber devices” under Section 524B of the FD&C Act. It provides more explicit, detailed, and legally backed requirements for that subset of devices, alongside expanded recommendations and updated references reflecting the evolving cybersecurity landscape and regulatory framework.