Skip to main content
USFD&C Act §524B (21 U.S.C. §360n-2) · FDA premarket cybersecurity guidance, February 2026

Cybersecurity is submission content.
We get the evidence ready.

Since March 2023, a US premarket submission for a device with software and connectivity carries statutory cybersecurity obligations — a postmarket vulnerability plan, update and patch processes, and a software bill of materials. FDA’s guidance sets out the evidence it expects alongside them. We prepare that evidence; FDA reviews the submission.

How it works

01

Kaitara Security prepares the cybersecurity evidence

Threat model and security risk file, the four architecture views, SBOM, testing strategy and VAPT, disclosure and postmarket plans — the cybersecurity content a reviewer expects to find in the submission.

02

Your team implements fixes with our guidance

We specify what needs to change — credentials, secure update, logging, cryptography, session handling — review the fixes, then retest to confirm the critical and high findings are closed.

03

Your regulatory advisor makes the submission

The submission, the quality management system and the FDA relationship stay with your regulatory advisor. We hand back the cybersecurity section for them to integrate.

Collaborative and hands-on — delivered remotely, working directly with your engineering team.

29 Mar 2023

§524B has applied to premarket submissions since this date

Four views

The security architecture views FDA recommends as a minimum

eSTAR

An incomplete cybersecurity section means a Technical Screening hold

Phase 1

Gap assessment

Start here. It stands on its own.

A short, scoped first step: we walk the applicability test with you, review what you already hold, and give you a gap report per assessment area with a prioritised action plan. If you go no further, you keep a defensible assessment you can share with your regulatory advisor.

Fixed-fee, scoped to you — no hourly billing.

Full programme

Phases 2–4

Evidence, testing, readiness

Quoted firm once the assessment is done.

Threat model and security risk file linked to your ISO 14971 process, the architecture views, SBOM, security testing with a clean retest, disclosure and postmarket plans, and the cybersecurity section assembled for the submission. Sized to your device’s connectivity and risk — documentation scales, and FDA says so itself.

Fixed-fee, scoped to you — no hourly billing.

What we deliver

Threat model and security risk assessment, with the rationale for the methodology used
Security risk management file (AAMI TIR57) linked into your ISO 14971 risk file
Global system view — the device and every internal and external connection
Multi-patient harm view — how a compromise reaching many devices is defended against
Updateability and patchability view — the end-to-end software update path
Security use case views for functionality where a compromise affects safety or effectiveness
Security controls across the eight categories, shown to be implemented and tested
Software Bill of Materials (CycloneDX) and a vulnerability management process
Coordinated vulnerability disclosure policy (ISO/IEC 29147 and 30111)
Security testing strategy — requirements, threat mitigation, vulnerability and penetration testing
VAPT findings report with severity ratings, then a clean retest after remediation
Security information for the labelling — what the device needs from the network it sits on
Postmarket vulnerability monitoring and patch plan, on the statutory cadences
The cybersecurity section assembled so a reviewer can trace each claim to its evidence

What §524B and the guidance require

§524B(b)(1)

A postmarket vulnerability plan

A plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits — including coordinated vulnerability disclosure and related procedures. Disclosure is statutory here, not merely good practice.

§524B(b)(2)

Processes, updates and patches

Processes providing reasonable assurance the device and related systems are cybersecure, with updates made available: known unacceptable vulnerabilities on a reasonably justified regular cycle, and critical vulnerabilities that could cause uncontrolled risks as soon as possible, out of cycle.

§524B(b)(3)

A software bill of materials

Including commercial, open-source and off-the-shelf components. The statute specifies no format. FDA's guidance separately recommends a machine-readable SBOM against NTIA's October 2021 minimum elements — one is law, the other is an expectation, and they are worth keeping apart.

§524B(c)

What makes a device a “cyber device”

Three limbs, joined by “and”: it includes software validated, installed or authorised by the sponsor; it has the ability to connect to the internet; and it contains technological characteristics that could be vulnerable to cybersecurity threats.

Guidance §V.B

Security architecture views

Four views are recommended as a minimum — global system, multi-patient harm, updateability and patchability, and security use cases — as diagrams with explanatory text covering communication paths, protocols, credential handling and session management.

Guidance Appendix 4

Documentation scales with risk

FDA states this expressly, and its worked example places a device with a single hardware connection at the lighter end of the range. The volume of evidence follows the device's connectivity and risk, not a fixed checklist.

How an engagement runs

Scoping

Understand the device

Interfaces and connectivity, whose instrument and whose software, submission pathway, and where you are in the timeline.

Assess

Applicability & gap assessment

The three-limb test walked with you, then posture measured against FDA's premarket cybersecurity guidance and EN IEC 81001-5-1.

Build

Threat model, views, SBOM & testing

Security risk file linked to ISO 14971; the architecture views; SBOM and vulnerability management; security testing strategy and VAPT.

Remediate

Fix and retest

Your team closes critical and high findings with our guidance; we retest to a clean result.

Ready

Submission section & readiness sign-off

The cybersecurity section assembled, and a readiness assessment issued before your advisor files.

Common questions

Does §524B apply to our device?

That determination is yours and your regulatory advisor's — we will not give you a verdict on it. What we can do is walk the test with you. All three limbs must hold, and the one companies assume rules them out is the internet limb. FDA reads it broadly: connectivity counts whether intentional or not, its illustrative list includes USB, ethernet and serial ports, and it states that a brief USB service connection is enough. The test is ability, not practice.

What happens if the cybersecurity section is incomplete?

Since October 2023 every 510(k) is submitted through eSTAR, and FDA places a submission on Technical Screening hold where the cybersecurity section does not contain accurate responses and the relevant attachments. Separately, FDA may refuse to accept a submission that does not contain the information §524B requires. Neither is a rejection on the merits — both cost calendar time, and both are avoided by preparing the content before submission rather than in response to a hold.

Is a machine-readable SBOM required?

An SBOM is required by the statute, and the statute specifies no format. A machine-readable SBOM against NTIA's minimum elements is what FDA's guidance recommends. We produce CycloneDX, which meets those elements — but the distinction between what the law requires and what the guidance recommends is one we keep explicit, because it changes what you must argue in a submission.

Which submissions does it reach?

510(k), De Novo, PMA, PDP and HDE. An Investigational Device Exemption is not a §524B submission — though the guidance's recommendations still reach it, and FDA asks for a reduced set for IDEs: cybersecurity risks in the informed consent form, three of the four architecture views, an SBOM, and connectivity labelling.

Do you make the submission?

No. Your regulatory advisor owns the submission itself, the quality management system and the FDA relationship. We prepare the cybersecurity evidence that sits inside it. The two do not overlap, and they run in parallel so the evidence is ready when the submission is.

We are CE marking as well — is this separate work?

Largely the same evidence core, presented for a different reviewer. The threat model, security risk management file, SBOM and testing serve both; what differs is the framing and the architecture-view documentation FDA asks for specifically. If both markets are in scope, it is cheaper to scope them together than to run them a year apart.

Which edition of the FDA guidance do you work to?

The February 2026 edition of the premarket cybersecurity guidance, which supersedes the June 2025 one. Worth knowing: FDA replaces the file at a stable download link while some of its own pages lag, so the June 2025 edition is still described in places on fda.gov. If your consultant cites it, they are reading FDA's website correctly — we will simply share the current download.

Preparing a US submission?

30-minute scoping call. We walk the applicability test with you, look at your device and timeline, and give you a right-sized, fixed-fee proposal for the cybersecurity evidence.

Book a free scoping call →

Further reading: FDA §524B in plain English