Medical Design and Outsourcing

  • Home
  • Medical Device Business
    • Mergers & Acquisitions
    • Financial
    • Regulatory
  • Applications
    • Cardiovascular
    • Devices
    • Imaging
    • Implantables
    • Medical Equipment
    • Orthopedic
    • Surgical
  • Technologies
    • Supplies and Components Index
    • Contract Manufacturing
    • Components
    • Electronics
    • Extrusions
    • Materials
    • Motion Control
    • Prototyping
    • Pumps
    • Tubing
  • MedTech Resources
    • Medtech Events in 2025
    • The 2024 Medtech Big 100
    • Medical Device Handbook
    • MedTech 100 Index
    • Subscribe to Print Magazine
    • DeviceTalks
    • Digital Editions
    • eBooks
    • Educational Assets
    • Manufacturer Search
    • Podcasts
    • Print Subscription
    • Webinars / Digital Events
    • Whitepapers
    • Voices
    • Video
  • 2025 Leadership
    • 2024 Winners
    • 2023 Winners
    • 2022 Winners
    • 2021 Winners
  • Women in Medtech
  • Advertise
  • Subscribe

FDA launches cybersecurity requirements for cyber device reviews

April 3, 2023 By Jim Hammerand

Cybersecurity medical deviceThe FDA’s new cybersecurity requirements for device review are now in effect, but the agency says it doesn’t plan on rejecting submissions for noncompliance until later this year.

Medical device developers must now include cybersecurity plans in their applications or submissions for regulatory review of cyber devices.

The FDA said its new powers under recent legislation “represent a significant step forward in the FDA’s role in regulating cybersecurity as part of a medical device’s safety and effectiveness.”

What are cyber devices?

The new requirements define cyber devices as any device that “includes software validated, installed, or authorized by the sponsor as a device or in a device; has the ability to connect to the internet; and contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats.”

The new rules cover cyber devices seeking approval or clearance under the 510(k), de novo, premarket approval (PMA) and humanitarian device exemption pathways.

Filings for cyber devices must now include “a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures.”

Device developers must also “design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address — on a reasonably justified regular cycle, known unacceptable vulnerabilities; and as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks.

Finally, the FDA directed developers of cyber devices filing for review to “provide a software bill of materials, including commercial, open-source, and off-the-shelf software components.”

The new rules also leave the door open for other potential regulatory requirements needed “to demonstrate reasonable assurance that the device and related systems are cybersecure.”

What led to the new cyber device regulation?

The change comes through amendments to the Federal Food, Drug, and Cosmetic Act. Federal lawmakers included those amendments in their e Consolidated Appropriations Act of 2023, which President Joe Biden signed into law on Dec. 29, 2022.

The act stipulated that the new requirements not go into effect until March 29, 2023, but the FDA said last week that it “generally intends not to issue ‘refuse to accept’ (RTA) decisions for premarket submissions submitted for cyber devices” just because they lack cybersecurity information. Instead, the agency said it will “work collaboratively” with applicants as part of the interactive and/or deficiency review process over the next six months.

“Beginning Oct. 1, 2023, FDA expects that sponsors of such cyber devices will have had sufficient time to prepare premarket submissions that contain information required by section 524B of the FD&C Act, and FDA may RTA premarket submissions that do not,” the FDA said.

The FDA has previously issued guidance on its RTA policy for 510(k)s, PMA acceptance and filing reviews, and de novo request acceptance review.

This post was originally published in April 2023 and updated in October 2023 with a link to the finalized guidance.

Related Articles Read More >

An image of an infusion pump.
Cybersecurity report flags device vulnerabilities and user needs
3 surprising cybersecurity risks in medical device software
Johnson & Johnson discloses executive pay and new security measures
A photo of CMR Surgical's Versius Surgical System being used during a simulation of a cholecystectomy.
A surgical robotics co-founder offers lessons from the de novo pathway
“mdo
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest medical device business news, application and technology trends.

DeviceTalks Weekly

See More >

MDO Digital Edition

Digital Edition

Subscribe to Medical Design & Outsourcing. Bookmark, share and interact with the leading medical design engineering magazine today.

MEDTECH 100 INDEX

Medtech 100 logo
Market Summary > Current Price
The MedTech 100 is a financial index calculated using the BIG100 companies covered in Medical Design and Outsourcing.
DeviceTalks

DeviceTalks is a conversation among medical technology leaders. It's events, podcasts, webinars and one-on-one exchanges of ideas & insights.

DeviceTalks

New MedTech Resource

Medical Tubing

MassDevice

Mass Device

The Medical Device Business Journal. MassDevice is the leading medical device news business journal telling the stories of the devices that save lives.

Visit Website
MDO ad
Medical Design and Outsourcing
  • MassDevice
  • DeviceTalks
  • MedTech100 Index
  • Medical Tubing + Extrusion
  • Medical Design Sourcing
  • Drug Delivery Business News
  • Drug Discovery & Development
  • Pharmaceutical Processing World
  • R&D World
  • About Us/Contact
  • Advertise With Us
  • Subscribe to Print Magazine
  • Subscribe to our E-Newsletter
  • Listen to our Weekly Podcasts
  • Join our DeviceTalks Tuesdays Discussion

Copyright © 2025 WTWH Media, LLC. All Rights Reserved. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of WTWH Media LLC. Site Map | Privacy Policy | RSS

Search Medical Design & Outsourcing

  • Home
  • Medical Device Business
    • Mergers & Acquisitions
    • Financial
    • Regulatory
  • Applications
    • Cardiovascular
    • Devices
    • Imaging
    • Implantables
    • Medical Equipment
    • Orthopedic
    • Surgical
  • Technologies
    • Supplies and Components Index
    • Contract Manufacturing
    • Components
    • Electronics
    • Extrusions
    • Materials
    • Motion Control
    • Prototyping
    • Pumps
    • Tubing
  • MedTech Resources
    • Medtech Events in 2025
    • The 2024 Medtech Big 100
    • Medical Device Handbook
    • MedTech 100 Index
    • Subscribe to Print Magazine
    • DeviceTalks
    • Digital Editions
    • eBooks
    • Educational Assets
    • Manufacturer Search
    • Podcasts
    • Print Subscription
    • Webinars / Digital Events
    • Whitepapers
    • Voices
    • Video
  • 2025 Leadership
    • 2024 Winners
    • 2023 Winners
    • 2022 Winners
    • 2021 Winners
  • Women in Medtech
  • Advertise
  • Subscribe