top of page

2025 Cyber Updates: FDA 2025 Cybersecurity Update for Medical Device Manufacturers

  • Writer: Rajesh Kanungo
    Rajesh Kanungo
  • 2 days ago
  • 1 min read

The FDA released a revised guidance titled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.” Key updates include:


  • Alignment with FD&C Act Section 524B: Applies to all “cyber devices” (including SaMD), making it binding legally.

  • Added Section VII to consolidate premarket cybersecurity recommendations for “cyber devices” under FD&C Act 524B

  • Clearer expectations for labeling, software updates, SBOM tracking, third-party software management, and vulnerability management.

  • Supersedes the 2023 guidance of the same title.

  • Secure Product Development Framework (SPDF) is now the central strategy.

  • Risk-based documentation requirements: Went from being High-level suggestions to requiring detailed scaling & architecture flow.

  • Structured premarket documentation to streamline FDA review and improve device resilience.

  • Appendices: expanded with templates and technical content.

  • Explicitly aligns with ISO 13485 and IMDRF Cybersecurity principles.


In short, the FDA has made its cybersecurity guidelines stricter. Link


To modernize internal operations, the FDA launched Elsa, a generative AI tool supporting staff across reviews, inspections, and compliance workflows, signaling growing FDA interest in leveraging AI responsibly. Link.


In a June whitepaper, the FDA urged manufacturers to strengthen OT security in medical product manufacturing, citing increasing vulnerabilities in industrial control systems. Link


Cyberattack Hits Device Manufacturer

On June 5, Minnesota-based Surmodics suffered a cybersecurity breach, disrupting its IT systems. The incident underscores the urgency of strong postmarket surveillance and response capabilities. Link



 
 
 

Recent Posts

See All

Comments


bottom of page