Back to Field Notes
Compliance & Regulation/Field Note

Medical Device Cybersecurity — The 2023 FDA Cyber Mandate

Section 524B of the FD&C Act made cybersecurity submission requirements binding. The SBOM requirement alone changes the supplier conversation.

Author

Mark Velasquez

Principal Standards Architect

Published

April 23, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Section 524B of the FD&C Act, in force since March 2023, imposed cybersecurity requirements on submissions for 'cyber devices.' The FDA refused-to-accept policy gave the requirements teeth. The SBOM mandate alone has reshaped how manufacturers manage their software supply chain.
  • 02What must be in the submission: plan to monitor/identify/address postmarket cybersecurity vulnerabilities, procedures and processes that provide reasonable assurance of cybersecurity, Software Bill of Materials (commercial, open-source, off-the-shelf components), and any other information FDA may require.
  • 03Postmarket obligations: vulnerability monitoring across the SBOM, coordinated disclosure procedures, patch and update mechanisms, communication to clinicians and patients. The submission is the start; postmarket discipline is the ongoing commitment.
  • 04What this means for suppliers: manufacturers will demand SBOMs and security attestations from every software component supplier. If you sell a software library to a medical device manufacturer, you are now part of their FDA submission. The bar for what 'security' means in your dependencies has risen accordingly.

Section 524B of the Federal Food, Drug, and Cosmetic Act, in force since March 2023, imposed cybersecurity requirements on submissions for 'cyber devices.' The FDA refused-to-accept-policy gave the requirements teeth. The SBOM mandate alone has reshaped how manufacturers manage their software supply chain.

What must be in the submission

  • 01Plan to monitor, identify, and address postmarket cybersecurity vulnerabilities
  • 02Procedures and processes that provide reasonable assurance of cybersecurity
  • 03Software Bill of Materials, including commercial, open-source, and off-the-shelf components
  • 04Other information FDA may require to demonstrate reasonable assurance

Postmarket obligations

Vulnerability monitoring across the SBOM. Coordinated disclosure procedures. Patch and update mechanisms. Communication to clinicians and patients. The submission is the start; the postmarket discipline is the ongoing commitment.

What this means for suppliers

Manufacturers will demand SBOMs and security attestations from every software component supplier. If you sell a software library to a medical device manufacturer, you are now part of their FDA submission. The bar for what 'security' means in your dependencies has risen accordingly.

#FDA#Medical Device#Healthcare

/WRITTEN_BY

Mark Velasquez

Principal Standards Architect · Alexa Cybersecurity