FDA updates its cybersecurity guidance for medical devices – What’s new for Manufacturers and Developers?

The updated guidance document, Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions, was released on 26 June to catch up with the rapidly changing MedTech landscape and the need for lifecycle management.

Scope

This guidance is applicable to devices with cybersecurity considerations, including but not limited to devices that include a device software function or that contain software (including firmware) or programmable logic. The guidance is not limited to devices that are network-enabled or contain other connected capabilities. This guidance describes recommendations regarding the cybersecurity information to be submitted for devices under the following premarket submission types:

  • Premarket Notification (510(k)) submissions
  • De Novo requests
  • Premarket Approval Applications (PMAs) and PMA supplements
  • Product Development Protocols (PDPs)
  • Investigational Device Exemption (IDE) submissions
  • Humanitarian Device Exemption (HDE) submissions
  • Biologics License Application (BLA) submissions and
  • Investigational New Drug (IND) submissions

It covers design, labelling and documentation that should be included in premarket submissions of devices with potential cybersecurity risks. It clarifies security recommendations for cyber devices under the amended Food, Drug & Cosmetic Act (FD&C Act) section 524B, including procedures, tracking software bill of materials to show the origin of components, and safely managing product updates. It references FDA’s final 21 CFR 820/ISO 13485 rule (89 FR 7496) probably to highlight and remind the obligation to adapt to the new quality management system requirements.

The definition of a cyber device

[…] 𝘢 𝘥𝘦𝘷𝘪𝘤𝘦 𝘵𝘩𝘢𝘵 (1) 𝘪𝘯𝘤𝘭𝘶𝘥𝘦𝘴 𝘴𝘰𝘧𝘵𝘸𝘢𝘳𝘦 𝘷𝘢𝘭𝘪𝘥𝘢𝘵𝘦𝘥, 𝘪𝘯𝘴𝘵𝘢𝘭𝘭𝘦𝘥, 𝘰𝘳 𝘢𝘶𝘵𝘩𝘰𝘳𝘪𝘻𝘦𝘥 𝘣𝘺 𝘵𝘩𝘦 𝘴𝘱𝘰𝘯𝘴𝘰𝘳 𝘢𝘴 𝘢 𝘥𝘦𝘷𝘪𝘤𝘦 𝘰𝘳 𝘪𝘯 𝘢 𝘥𝘦𝘷𝘪𝘤𝘦; (2) 𝘩𝘢𝘴 𝘵𝘩𝘦 𝘢𝘣𝘪𝘭𝘪𝘵𝘺 𝘵𝘰 𝘤𝘰𝘯𝘯𝘦𝘤𝘵 𝘵𝘰 𝘵𝘩𝘦 𝘪𝘯𝘵𝘦𝘳𝘯𝘦𝘵; 𝘢𝘯𝘥 (3) 𝘤𝘰𝘯𝘵𝘢𝘪𝘯𝘴 𝘢𝘯𝘺 𝘴𝘶𝘤𝘩 𝘵𝘦𝘤𝘩𝘯𝘰𝘭𝘰𝘨𝘪𝘤𝘢𝘭 𝘤𝘩𝘢𝘳𝘢𝘤𝘵𝘦𝘳𝘪𝘴𝘵𝘪𝘤𝘴 𝘷𝘢𝘭𝘪𝘥𝘢𝘵𝘦𝘥, 𝘪𝘯𝘴𝘵𝘢𝘭𝘭𝘦𝘥, 𝘰𝘳 𝘢𝘶𝘵𝘩𝘰𝘳𝘪𝘻𝘦𝘥 𝘣𝘺 𝘵𝘩𝘦 𝘴𝘱𝘰𝘯𝘴𝘰𝘳 𝘵𝘩𝘢𝘵 𝘤𝘰𝘶𝘭𝘥 𝘣𝘦 𝘷𝘶𝘭𝘯𝘦𝘳𝘢𝘣𝘭𝘦 𝘵𝘰 𝘤𝘺𝘣𝘦𝘳𝘴𝘦𝘤𝘶𝘳𝘪𝘵𝘺 𝘵𝘩𝘳𝘦𝘢𝘵𝘴. […]

Devices that include software, are internet-connected, and are potentially vulnerable to cybersecurity threats must meet new statutory requirements, including the submission of:

  • Cybersecurity risk management plans
  • Plans to monitor and address post market vulnerabilities
  • A Software Bill of Materials (SBOM)

Evnia’s tips

To get your submission accepted you need

 

How Evnia supports regulatory compliance

At Evnia, we help medical device manufacturers ensure compliance with the FDA’s latest cybersecurity expectations by offering:

  • Regulatory and Strategic Planning Services:
    We evaluate your current development and documentation practices against FDA and FDORA cybersecurity requirements
  • Comprehensive Support for the Development of Cybersecurity Documentation:
    We assist you prepare premarket submissions, such as Security Risk Management Reports, Threat Models, Cybersecurity Risk Assessments, and SBOMs
  • Consulting Services for the Implementation of Secure Product Development Frameworks (SPDF):
    We guide you on how to integrate the SPDF principles into your Quality System and Product Development Lifecycle in alignment with ISO 13485 and FDA requirements
  • FDA Audit Readiness Package

 

Contact us today for a introductory discussion!

TOP