On February 3, 2026, FDA reissued Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, superseding the June 2025 version. Unlike that release — a full Level 1 final guidance that substantially updated FDA’s premarket cybersecurity recommendations, including recommendations addressing Section 524B cyber-device obligations and SBOMs — this update was issued under Level 2 procedures (21 CFR 10.115(g)(4)): a narrower revision aligning the guidance with the amendments to 21 CFR Part 820 under the QMSR.

Those amendments stem from FDA’s Quality Management System Regulation (QMSR). FDA’s amended 21 CFR Part 820, which incorporates ISO 13485:2016 by reference, was finalized in early 2024 with a two-year transition period. That transition period ended when QMSR became effective on February 2, 2026 — one day before this guidance was reissued. The QMSR is no longer a forthcoming framework; effective February 2, 2026, it is the applicable FDA quality-system regulation for manufacturers within its scope.

The more useful way to read this revision is not as a new cybersecurity bar but as a clearer regulatory integration: FDA is now explicitly connecting cybersecurity activities and their outputs to the QMSR processes manufacturers must already operate and maintain.

A coordinated rollout, not an isolated update

This guidance reissue was one piece of a longer sequence FDA had been staging since the QMSR final rule published February 2, 2024. On December 4, 2025, FDA issued a batch of technical amendments updating QSR references to QMSR across 179 sections in 18 parts of Title 21 — non-substantive, editorial changes, illustrating how broadly the QSR-to-QMSR terminology changes extend beyond Part 820 itself. FDA implemented Compliance Program 7382.850, “Inspection of Medical Device Manufacturers,” on February 2, 2026, retiring the Quality System Inspection Technique (QSIT) guide (CP 7382.845) and the separate PMA inspection program (CP 7383.001) that investigators had used. The cybersecurity guidance reissue on February 3 was part of that process, not isolated.

What actually changed

The February 2026 text more explicitly maps cybersecurity activities and documentation to specific ISO 13485 subclauses rather than legacy Part 820 language: design and development controls (7.3, including validation under 7.3.7 and design files under 7.3.10), risk management (7.1), supplier controls (7.4), production (7.5), and postmarket activities including complaint handling (8.2.2), quality audits (8.2.4), analysis of data (8.4), and improvement/CAPA activities (8.5). It also sharpens the framing of a Secure Product Development Framework (SPDF) as “one way to satisfy the QMSR” — positioning secure-by-design practices explicitly within QMS compliance rather than alongside it.

Why it matters for cybersecurity programs

For manufacturers already operating an ISO 13485-based QMS for MDR or other regulatory purposes, this creates a more direct crosswalk: design and development records, risk-management documentation, and CAPA records built for QMS compliance can now be traced clause-by-clause to FDA’s cybersecurity documentation expectations, potentially reducing duplication between QMS records and premarket cybersecurity documentation. FDA is explicit that it still won’t evaluate QMSR compliance as part of a 510(k) substantial equivalence determination — but QMSR-related outputs — such as threat models, cybersecurity risk assessments, and architecture documentation — can nevertheless provide important evidence for demonstrating that the device’s cybersecurity supports safety and effectiveness. In short: the compliance target didn’t move, but the map to it just got a lot more specific.

The new inspection program raises the stakes on that documentation. CP 7382.850 structures inspections around six QMS areas within a total-product-lifecycle, risk-based approach — including design/development and risk management — using the manufacturer’s risk-management information to help determine which QMS elements warrant deeper examination, and it authorizes investigators to pull internal audit reports, management review records, and supplier audit reports that were largely out of scope under QSIT. Cybersecurity risk documentation maintained as part of the QMS is therefore no longer merely premarket submission support; depending on the inspection scope, it can become part of the records FDA investigators examine directly.

Sources: FDA, “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions,” issued February 3, 2026 (supersedes June 27, 2025 guidance); 89 FR 7496 (QMSR final rule); Federal Register, “Medical Devices; Quality Management System Regulation Technical Amendments,” published December 4, 2025 (2025-21955); FDA Compliance Program 7382.850, “Inspection of Medical Device Manufacturers,” implementation date February 2, 2026.