Section 524B Compliance

FDA Section 524B Cybersecurity Gap Assessment

Since March 29, 2023, FDA can issue a Refuse to Accept (RTA) finding for any cyber device submission that is missing required cybersecurity documentation. The gap assessment identifies every missing or insufficient element — threat model, SBOM, security architecture, vulnerability assessment, and coordinated disclosure policy — before you submit, not after.

Start the Gap Assessment Full Cyber Risk Assessment

Statutory & Guidance Requirements

What FDA Requires for Every Cyber Device Submission

Seven distinct content requirements apply to any device that contains software and connects to a network. Missing any one of them is grounds for an RTA finding.

FD&C §524B(b)(1)(A) Device Security Assurance

Design and maintain processes to confirm the device and related systems are cybersecurity-secure throughout the device lifecycle.

FD&C §524B(b)(3) Software Bill of Materials

Provide a complete SBOM covering all commercial, open-source, and off-the-shelf software components with version information.

FD&C §524B(b)(4) Post-Market Monitoring Plan

Monitor, identify, and address post-market cybersecurity vulnerabilities and exploits within a reasonable time.

FD&C §524B(b)(1)(B) Coordinated Disclosure Policy

Design and maintain processes and procedures for coordinated vulnerability disclosure to FDA and the public.

FDA Guidance (2023) Threat Model Documentation

Systematically document cybersecurity threats, attack surfaces, and their potential patient safety impacts for the device's clinical environment.

FDA Guidance (2023) Vulnerability Assessment

Assess identified threats against the SBOM and device architecture; score vulnerabilities with clinical safety context, not raw CVSS scores alone.

FDA Guidance (2023) Security Architecture

Document security controls, authentication mechanisms, encryption standards, network segmentation, and audit logging capabilities.

Gap Assessment Service

One Flat Fee. Every Gap Identified Before Submission.

The gap assessment reviews your existing documentation against FDA's 524B content expectations and delivers a written report. Remediation services are scoped separately based on what the report finds.

Flat Fee
Section 524B Gap Assessment
$3,495
Invoice — no card required. Andre sends a QBO invoice; work begins on cleared funds.
  • Review against FDA's 524B content expectations
  • Threat model gap analysis
  • SBOM completeness assessment
  • Security architecture review
  • Vulnerability assessment methodology review
  • Written gap report — every finding documented
  • Prioritized remediation items with effort estimates
  • 60-minute findings debrief call

If the report identifies gaps, remediation work is scoped from the findings — you see exactly what needs to be built and a fair estimate before committing to anything additional.

Remediation Services — Scoped from Assessment Findings

Cybersecurity Management Plan

Draft or refine your cybersecurity management plan to meet FDA's premarket content expectations for cyber devices — delivered as a structured document aligned to FDA's 2023 guidance framework.

Scoped per engagement

SBOM Construction & Review

Build a compliant SBOM from your component list — commercial, open-source, and off-the-shelf software inventoried and versioned to FDA's expectations. Includes known-vulnerability cross-reference.

Scoped per engagement

Premarket Documentation Package

Full 524B documentation set: threat model, security architecture, vulnerability assessment, testing summary, and coordinated disclosure policy — assembled for premarket submission.

Scoped per engagement

How It Works

From Kickoff to Written Report in Two Weeks

Step 1

Baseline Review

Days 1–3

Structured document review against FDA's 524B content expectations — every gap identified and documented. We review whatever you have: existing SBOM drafts, design controls, threat models in any state of completion.

Step 2

Gap Report

Days 4–10

Written findings with a clear description of each gap, the FDA content expectation it relates to, and a realistic effort estimate for remediation. Prioritized by submission impact — RTA-blocking gaps flagged separately.

Step 3

Debrief & Path Forward

Week 2

60-minute call to walk through the report, answer questions, and agree on which gaps to address before submission. If remediation work is needed, a scoped proposal follows the debrief.

Common Questions

Frequently Asked Questions

Which devices are subject to Section 524B?

Section 524B applies to "cyber devices" — any device that contains software (including firmware) and connects to the internet, a local area network, a wireless network, or another product. Any device with Wi-Fi, Bluetooth, USB data, or cellular connectivity likely qualifies. The definition is broad and applies regardless of device class or submission type.

What does FDA require in the premarket submission for a cyber device?

FDA expects a cybersecurity management plan, threat model, SBOM, vulnerability assessment, security testing documentation, coordinated vulnerability disclosure policy, and a post-market monitoring plan. Submissions missing required elements may receive a Refuse to Accept (RTA) finding, which returns the submission without substantive review.

What is an SBOM and why does FDA require it?

A Software Bill of Materials (SBOM) is a complete inventory of all software components, libraries, and dependencies in your device — including commercial, open-source, and off-the-shelf software — with version information. FDA requires it so that when new vulnerabilities are discovered, manufacturers can quickly identify affected devices and confirm patient safety impact.

What happens if a submission is missing required 524B elements?

FDA may issue a Refuse to Accept (RTA) finding, returning the submission without substantive review. This resets the review clock entirely and can add months to time to market. RTA resolution requires assembling the missing documentation and resubmitting. Addressing gaps before submission is significantly more efficient than responding to an RTA.

Does Section 524B apply to devices cleared before March 2023?

The installed base of legacy devices already on the market is not retroactively required to comply with Section 524B. However, any new premarket submission for a device that meets the cyber device definition — regardless of when first cleared — is subject to 524B requirements. A device cleared in 2019 that submits a new 510(k) for an updated indication must include the required 524B documentation.

How long does the Section 524B gap assessment take?

The assessment typically completes within two weeks of kickoff. Timeline depends on the maturity of existing documentation and device complexity. A well-documented device with an existing SBOM and threat model requires less time than a device starting from scratch. The timeline is confirmed at kickoff after reviewing current documentation.

Get Started

Tell Us About Your Device

Submit your details and we will confirm next steps within one business day. The kickoff call takes about 60 minutes — we review your current documentation and set the assessment timeline.

Not Sure If 524B Applies?

Free 30-Minute Scope Call

If you are not certain whether your device qualifies as a cyber device or what documentation you already have that can be leveraged, a scoping call takes 30 minutes and costs nothing.