Cybersecurity evidence for connected medical devices

Standard & Framework · Device Cybersecurity

Section 524B of the FD&C Act (effective 2023) makes an SBOM and a vulnerability-monitoring plan statutory contents of a 510(k), De Novo, or PMA submission for a cyber device, and FDA's September 2023 final guidance expects a threat model and a patch plan as the premarket evidence of reasonable assurance.

What cybersecurity evidence does FDA require for a connected device?

Section 524B of the FD&C Act makes an SBOM and a vulnerability-monitoring plan statutory contents of a premarket submission for a cyber device. FDA's September 2023 final guidance also expects a threat model and a patch plan.

Under Section 524B (the PATCH Act, effective 2023), this is a statutory premarket requirement for cyber devices, not an optional security best practice: FDA's guidance asks for a threat model and a patch plan, not a firewall diagram.

Section 524B made this a statute, not a guidance suggestion

Since Section 524B of the FD&C Act took effect, an FDA premarket submission for a "cyber device" (one that includes software, can connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats) must include: a plan to monitor, identify, and address post-market vulnerabilities; a process for providing reasonable assurance the device is cybersecure, including patch and update mechanisms; and a Software Bill of Materials.

SBOM: the minimum elements

For a 510(k) or PMA, FDA's guidance points to the NTIA/CISA baseline for the SBOM: supplier, component name, version, dependency relationships, and a small set of other fields — generated on every build, not maintained as a document. The full checklist is downloadable below.

Threat modeling: a worked STRIDE pass

STRIDE categoryExample threat (infusion pump-class device)Mitigation evidence expected
SpoofingUnauthenticated device impersonates the infusion pump on the hospital networkMutual TLS or equivalent device authentication; verification test proving rejection of an unauthenticated peer
TamperingFirmware update accepted without signature verificationSigned firmware, verified boot chain; test proving an unsigned image is rejected
RepudiationDosage change made with no attributable audit recordTamper-evident audit log tied to an authenticated session
Information disclosurePatient data exposed via an unencrypted diagnostic portEncryption at rest/in transit; port disabled or access-controlled in production configuration
Denial of serviceMalformed network packet crashes the alarm subsystemFuzz-testing evidence; documented graceful-degradation behavior
Elevation of privilegeClinical user account can reach a service-technician configuration screenRole-based access control; test proving privilege boundaries hold

Engineering reference only. Not formal regulatory counsel. Section 524B and FDA's 2023 cybersecurity guidance should be consulted directly for a specific submission's requirements.

Artifact: sbom-minimum-elements-checklist.md

Generated client-side; no server round-trip, no account required.

# SBOM Minimum-Elements Checklist (v1.0.0)

Engineering reference checklist only, mapped to the NTIA/CISA minimum
elements referenced by FDA's 2023 cybersecurity guidance. Not a substitute
for legal/regulatory review.

## Data fields (per component)
- [ ] Supplier name
- [ ] Component name
- [ ] Component version
- [ ] Other unique identifiers (e.g. CPE, PURL, or SWID)
- [ ] Dependency relationship (what this component depends on)
- [ ] Author of the SBOM data
- [ ] Timestamp of SBOM generation

## Practices
- [ ] SBOM is regenerated on every build that changes a dependency, not
      maintained by hand
- [ ] Every component is checked against a known-vulnerability database
      (e.g. NVD) as part of the release-readiness gate
- [ ] A patchability/support-end-of-life note exists for every component,
      especially unmaintained SOUP
- [ ] SBOM format is machine-readable (SPDX or CycloneDX), not a document

## Section 524B (PATCH Act) considerations
- [ ] A plan exists to monitor, identify, and disclose post-market
      cybersecurity vulnerabilities
- [ ] A process exists to provide "reasonable assurance" the device and
      related systems are cybersecure, and to make patches/updates available

Download sbom-minimum-elements-checklist.md

Provenance & review state

Last reviewed
Sources
  • FDA Cybersecurity in Medical Devices (2023) — U.S. Food and Drug Administration
  • FD&C Act Section 524B — U.S. Food and Drug Administration
  • IEC 81001-5-1:2021 — International Electrotechnical Commission
Ingested from

Sign in or sign up

Enter your work email to receive a temporary sign-in link.

By continuing, you agree to our Terms of Service and Privacy Policy.