FDA Issues Updated Cybersecurity Guidance for Medical Device Premarket Submissions
核心洞察
The FDA released updated cybersecurity guidance superseding its June 2025 version, titled "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions."
The non-binding guidance formalizes the FDA's position that cybersecurity risk management is essential to ensuring medical devices remain safe and effective.
Key recommendations include secure-by-design principles, cybersecurity transparency with end users, threat modeling, and ongoing cyber risk assessments throughout the device lifecycle.
The Food and Drug Administration has released updated cybersecurity guidance for medical device manufacturers, superseding its June 2025 guidance and signaling heightened federal attention to the security of connected healthcare technologies. The new document, titled "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions," aims to supplement the FDA's postmarket cybersecurity guidance and its existing guidance on premarket submissions for device software functions.
The guidance arrives as medical devices and the broader healthcare sector remain a favored target of cyber criminals. While the recommendations are non-binding, the FDA has made clear that the guidance is intended to help companies meet their existing statutory obligations, and manufacturers should review their practices to ensure alignment with agency expectations.
Federal Cybersecurity Landscape
The FDA's guidance forms part of a broader series of federal initiatives focused on cybersecurity. The White House released its Cyber Strategy for America in March, outlining the administration's cybersecurity posture through six pillars that build on prior federal approaches. Across agencies, cyber-related rulemaking and enforcement activity have intensified, including the Justice Department's continuation of its Civil-Cyber Fraud Initiative and the Department of Defense's final rule implementing the Cybersecurity Maturity Model Certification program.
Core Elements of the FDA Guidance
The guidance formalizes the FDA's position that cybersecurity risk management is essential to ensuring devices remain safe and effective. The agency incorporates the risk management framework ISO 13485 by reference and provides specific examples of how the framework can be integrated into medical device security. Rather than mandating specific technical measures, the FDA identifies cybersecurity controls that manufacturers should generally assess as part of their premarket submissions.
Secure Design and Architecture
During the design phase, companies should assess existing systems, identify potential cybersecurity risks, and implement "secure by design" principles—such as organizational transparency and accountability—to reduce exploitable flaws before devices reach the market. The FDA recommends controls related to authentication, authorization, cryptography, confidentiality, event detection and logging, resiliency and recovery, and "updatability and patchability." Manufacturers should evaluate whether their architecture is designed to avoid deployment risks, supply chain disruptions, breaches of customer data, and the consequences of noncompliance with FDA guidance.
Cybersecurity Transparency
The guidance emphasizes that manufacturers should be transparent with device users, providing sufficient information about cybersecurity controls, potential risks to the medical device system, and other relevant information enabling users to address known or potential cybersecurity risks. Manufacturers should implement transparency policies that build trust with end users, empowering them to assess the strengths and weaknesses of security policies and make informed purchasing decisions.
Threat Modeling and Cyber Risk Assessments
The FDA suggests that manufacturers conduct threat modeling that includes identifying security objectives, risks, and vulnerabilities across the medical device system, then defining countermeasures to prevent, mitigate, monitor, or respond to threats throughout the device lifecycle. This involves analyzing systems from a bad actor's perspective and modeling how vulnerabilities could be exploited.
Additionally, the FDA calls for manufacturers to assess security risks and controls for residual risks as part of a cybersecurity risk assessment, including risks that can occur either intentionally or unintentionally. These assessments should be conducted throughout the device's lifecycle, identifying potential vulnerabilities, adopting protective measures, detecting potential attacks, and responding to and recovering from malicious incidents.
Looking Ahead
Companies across sectors should anticipate that federal agencies will continue to monitor cyber-related threats, issue guidance, engage in rulemaking, and pursue enforcement actions where companies fail to adequately address cybersecurity matters. Medical device manufacturers—and companies operating in any of the 16 critical infrastructure sectors—should monitor for updates on rulemaking initiated by the Cybersecurity and Infrastructure Security Agency under the Cyber Incident Reporting for Critical Infrastructure Act of 2022.
