Section 524B Compliance
Since March 29, 2023, FDA can issue a Refuse to Accept (RTA) finding for any cyber device submission that is missing required cybersecurity documentation. The gap assessment identifies every missing or insufficient element — threat model, SBOM, security architecture, vulnerability assessment, and coordinated disclosure policy — before you submit, not after.
Statutory & Guidance Requirements
Seven distinct content requirements apply to any device that contains software and connects to a network. Missing any one of them is grounds for an RTA finding.
Design and maintain processes to confirm the device and related systems are cybersecurity-secure throughout the device lifecycle.
Provide a complete SBOM covering all commercial, open-source, and off-the-shelf software components with version information.
Monitor, identify, and address post-market cybersecurity vulnerabilities and exploits within a reasonable time.
Design and maintain processes and procedures for coordinated vulnerability disclosure to FDA and the public.
Systematically document cybersecurity threats, attack surfaces, and their potential patient safety impacts for the device's clinical environment.
Assess identified threats against the SBOM and device architecture; score vulnerabilities with clinical safety context, not raw CVSS scores alone.
Document security controls, authentication mechanisms, encryption standards, network segmentation, and audit logging capabilities.
Gap Assessment Service
The gap assessment reviews your existing documentation against FDA's 524B content expectations and delivers a written report. Remediation services are scoped separately based on what the report finds.
If the report identifies gaps, remediation work is scoped from the findings — you see exactly what needs to be built and a fair estimate before committing to anything additional.
Remediation Services — Scoped from Assessment Findings
Draft or refine your cybersecurity management plan to meet FDA's premarket content expectations for cyber devices — delivered as a structured document aligned to FDA's 2023 guidance framework.
Scoped per engagementBuild a compliant SBOM from your component list — commercial, open-source, and off-the-shelf software inventoried and versioned to FDA's expectations. Includes known-vulnerability cross-reference.
Scoped per engagementFull 524B documentation set: threat model, security architecture, vulnerability assessment, testing summary, and coordinated disclosure policy — assembled for premarket submission.
Scoped per engagementHow It Works
Structured document review against FDA's 524B content expectations — every gap identified and documented. We review whatever you have: existing SBOM drafts, design controls, threat models in any state of completion.
Written findings with a clear description of each gap, the FDA content expectation it relates to, and a realistic effort estimate for remediation. Prioritized by submission impact — RTA-blocking gaps flagged separately.
60-minute call to walk through the report, answer questions, and agree on which gaps to address before submission. If remediation work is needed, a scoped proposal follows the debrief.
Common Questions
Section 524B applies to "cyber devices" — any device that contains software (including firmware) and connects to the internet, a local area network, a wireless network, or another product. Any device with Wi-Fi, Bluetooth, USB data, or cellular connectivity likely qualifies. The definition is broad and applies regardless of device class or submission type.
FDA expects a cybersecurity management plan, threat model, SBOM, vulnerability assessment, security testing documentation, coordinated vulnerability disclosure policy, and a post-market monitoring plan. Submissions missing required elements may receive a Refuse to Accept (RTA) finding, which returns the submission without substantive review.
A Software Bill of Materials (SBOM) is a complete inventory of all software components, libraries, and dependencies in your device — including commercial, open-source, and off-the-shelf software — with version information. FDA requires it so that when new vulnerabilities are discovered, manufacturers can quickly identify affected devices and confirm patient safety impact.
FDA may issue a Refuse to Accept (RTA) finding, returning the submission without substantive review. This resets the review clock entirely and can add months to time to market. RTA resolution requires assembling the missing documentation and resubmitting. Addressing gaps before submission is significantly more efficient than responding to an RTA.
The installed base of legacy devices already on the market is not retroactively required to comply with Section 524B. However, any new premarket submission for a device that meets the cyber device definition — regardless of when first cleared — is subject to 524B requirements. A device cleared in 2019 that submits a new 510(k) for an updated indication must include the required 524B documentation.
The assessment typically completes within two weeks of kickoff. Timeline depends on the maturity of existing documentation and device complexity. A well-documented device with an existing SBOM and threat model requires less time than a device starting from scratch. The timeline is confirmed at kickoff after reviewing current documentation.
Get Started
Submit your details and we will confirm next steps within one business day. The kickoff call takes about 60 minutes — we review your current documentation and set the assessment timeline.
Sending your request…
Not Sure If 524B Applies?
If you are not certain whether your device qualifies as a cyber device or what documentation you already have that can be leveraged, a scoping call takes 30 minutes and costs nothing.