Cybersecurity

FDA Section 524B Cybersecurity Requirements: What Medical Device Companies Must Know in 2025

By Andre Butler  ·  June 25, 2026  ·  ← All Insights

Medical device cybersecurity: Section 524B requirements

Photo by FlyD on Unsplash

The Cybersecurity Enforcement Era Is Here

If you are submitting a premarket application for any device that contains software or connects to a network, the regulatory landscape changed fundamentally on March 29, 2023. That is when Section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act), enacted under the Consolidated Appropriations Act of 2023, became effective. FDA is no longer treating cybersecurity as a supplementary concern or a post-market afterthought. It is now a condition of market entry.

For startup founders, VP-level quality and regulatory leaders, and regulatory affairs professionals, understanding exactly what Section 524B demands—and how FDA is interpreting it—is not optional. Submissions that fall short are being placed on Refuse to Accept (RTA) hold. The clock is ticking from the moment your 510(k), PMA, or De Novo lands in FDA's queue.

What Section 524B Actually Requires

Section 524B, codified in the FD&C Act, applies to what FDA calls cyber devices—defined as devices that include software validated, installed, or authorized by the sponsor, are capable of connecting to the internet, and contain technological characteristics that could be vulnerable to cybersecurity threats. This definition is intentionally broad. If your device has Bluetooth, Wi-Fi, USB, or any external interface, assume it qualifies.

Under Section 524B, manufacturers of cyber devices must include the following in any premarket submission:

  • A plan to monitor, identify, and address postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure (CVD) processes
  • Procedures and processes for providing reasonable assurance that the device and related systems are cybersecure
  • A software bill of materials (SBOM), including commercial, open-source, and off-the-shelf software components
  • Evidence that the device meets FDA cybersecurity performance criteria under section 524B(b)

FDA's primary guidance document for premarket submissions is the 2023 Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions guidance, finalized in September 2023. This document supersedes earlier 2014 and 2018 guidance and should be your primary technical reference for any current submission.

The SBOM Requirement: More Complex Than It Sounds

The software bill of materials requirement deserves special attention because it catches many sponsors off guard. An SBOM is not simply a list of libraries. FDA expects a machine-readable inventory of all software components, including version information, supplier names, and known vulnerabilities mapped against those versions. Common formats FDA references include CycloneDX and SPDX.

More importantly, your SBOM must be paired with a vulnerability management plan that demonstrates you have processes to monitor sources like the National Vulnerability Database (NVD) and CISA advisories, assess the clinical impact of identified vulnerabilities, and communicate with customers when patches or mitigations are necessary. This is a living document expectation, not a one-time deliverable.

The Secure Product Development Framework (SPDF)

FDA's 2023 guidance heavily references the Secure Product Development Framework (SPDF) as the organizing structure for your cybersecurity program. The SPDF is not a single standard but a concept that encompasses security risk management throughout the total product lifecycle (TPLC). FDA points to recognized standards including AAMI TIR57, NIST SP 800-30, IEC 62443, and the MITRE ATT&CK for ICS framework as acceptable inputs to an SPDF implementation.

Your design history file (DHF) and 21 CFR Part 820 quality system documentation must now reflect cybersecurity risk management as an integrated discipline alongside your traditional safety risk management under ISO 14971. These are not parallel tracks—they must be reconciled. A threat model that identifies a high-likelihood cyberattack must feed back into your safety risk analysis if that attack could cause patient harm.

Common Submission Deficiencies That Will Get You an RTA

Based on FDA's enforcement posture since late 2023, the following gaps consistently trigger RTA decisions or major deficiencies:

  • Submitting an SBOM that is incomplete, outdated, or not in a machine-readable format
  • Providing a cybersecurity risk assessment that does not address the STRIDE or equivalent threat modeling methodology
  • Failing to describe a coordinated vulnerability disclosure policy or providing one that lacks clear timelines and communication procedures
  • Treating cybersecurity testing as a one-time penetration test rather than a systematic, risk-based testing program
  • Not addressing authentication, encryption, and audit log requirements for network-connected devices
  • Omitting cybersecurity considerations from the device's Instructions for Use (IFU)

What This Means for Your Regulatory Strategy

Section 524B compliance is not a documentation exercise you add at the end of development. The threat modeling, architecture security review, and vulnerability assessment activities that feed your premarket submission must begin during design inputs—before your design freeze. Retrofitting cybersecurity into a mature design is expensive, time-consuming, and often results in architectural compromises that FDA reviewers can identify immediately.

For early-stage companies, the most practical approach is to establish your SPDF framework concurrently with your design controls under 21 CFR Part 820 or ISO 13485. Document your threat modeling assumptions, track your SBOM from the first sprint, and build your CVD policy before you have your first commercial customer. These are not burdensome additions—they are the foundation of a defensible premarket submission and a sustainable postmarket posture.

Work with Experts Who Know FDA's Cybersecurity Expectations

Section 524B raised the bar significantly, and FDA has made clear that cybersecurity deficiencies will not be resolved through informal feedback cycles. Getting this right in your initial submission—whether that is a 510(k), PMA, or De Novo—requires someone who understands both the regulatory framework and the technical depth FDA reviewers now expect.

At ADB Consulting & CRO Inc., we help medical device companies build cybersecurity programs that satisfy Section 524B from the ground up. From SBOM architecture and threat modeling to premarket submission strategy and postmarket vulnerability management, we provide the regulatory expertise your team needs to move efficiently and confidently through FDA review.

Book a free discovery call with Andre Butler today at adbccro.com and find out exactly what your submission needs to clear FDA's cybersecurity bar on the first review cycle.

Andre Butler

Principal Consultant — ADB Consulting & CRO Inc.

Andre Butler has 20+ years of hands-on FDA regulatory experience guiding medical device companies through 510(k), PMA, De Novo, AI/ML SaMD, and FDA 483 response engagements. He specialises in Section 524B cybersecurity compliance and ISO 13485 quality management systems, with a track record across cardiovascular, orthopedic, diagnostic, and software-as-a-medical-device categories.

Ready to Navigate the FDA Process with Confidence?

Book a free 30-minute discovery call with Andre Butler. No sales pitch -- just expert regulatory guidance on your specific device and situation.

Schedule Free Discovery Call

Or call directly: (888) 450-8607