Cybersecurity evidence for connected medical devices
Standard & Framework · Device Cybersecurity
Section 524B of the FD&C Act (effective 2023) makes an SBOM and a vulnerability-monitoring plan statutory contents of a 510(k), De Novo, or PMA submission for a cyber device, and FDA's September 2023 final guidance expects a threat model and a patch plan as the premarket evidence of reasonable assurance.
What cybersecurity evidence does FDA require for a connected device?
Section 524B of the FD&C Act makes an SBOM and a vulnerability-monitoring plan statutory contents of a premarket submission for a cyber device. FDA's September 2023 final guidance also expects a threat model and a patch plan.
Under Section 524B (the PATCH Act, effective 2023), this is a statutory premarket requirement for cyber devices, not an optional security best practice: FDA's guidance asks for a threat model and a patch plan, not a firewall diagram.
Section 524B made this a statute, not a guidance suggestion
Since Section 524B of the FD&C Act took effect, an FDA premarket submission for a "cyber device" (one that includes software, can connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats) must include: a plan to monitor, identify, and address post-market vulnerabilities; a process for providing reasonable assurance the device is cybersecure, including patch and update mechanisms; and a Software Bill of Materials.
SBOM: the minimum elements
For a 510(k) or PMA, FDA's guidance points to the NTIA/CISA baseline for the SBOM: supplier, component name, version, dependency relationships, and a small set of other fields — generated on every build, not maintained as a document. The full checklist is downloadable below.
Threat modeling: a worked STRIDE pass
| STRIDE category | Example threat (infusion pump-class device) | Mitigation evidence expected |
|---|---|---|
| Spoofing | Unauthenticated device impersonates the infusion pump on the hospital network | Mutual TLS or equivalent device authentication; verification test proving rejection of an unauthenticated peer |
| Tampering | Firmware update accepted without signature verification | Signed firmware, verified boot chain; test proving an unsigned image is rejected |
| Repudiation | Dosage change made with no attributable audit record | Tamper-evident audit log tied to an authenticated session |
| Information disclosure | Patient data exposed via an unencrypted diagnostic port | Encryption at rest/in transit; port disabled or access-controlled in production configuration |
| Denial of service | Malformed network packet crashes the alarm subsystem | Fuzz-testing evidence; documented graceful-degradation behavior |
| Elevation of privilege | Clinical user account can reach a service-technician configuration screen | Role-based access control; test proving privilege boundaries hold |
Engineering reference only. Not formal regulatory counsel. Section 524B and FDA's 2023 cybersecurity guidance should be consulted directly for a specific submission's requirements.
Artifact: sbom-minimum-elements-checklist.md
Generated client-side; no server round-trip, no account required.
# SBOM Minimum-Elements Checklist (v1.0.0)
Engineering reference checklist only, mapped to the NTIA/CISA minimum
elements referenced by FDA's 2023 cybersecurity guidance. Not a substitute
for legal/regulatory review.
## Data fields (per component)
- [ ] Supplier name
- [ ] Component name
- [ ] Component version
- [ ] Other unique identifiers (e.g. CPE, PURL, or SWID)
- [ ] Dependency relationship (what this component depends on)
- [ ] Author of the SBOM data
- [ ] Timestamp of SBOM generation
## Practices
- [ ] SBOM is regenerated on every build that changes a dependency, not
maintained by hand
- [ ] Every component is checked against a known-vulnerability database
(e.g. NVD) as part of the release-readiness gate
- [ ] A patchability/support-end-of-life note exists for every component,
especially unmaintained SOUP
- [ ] SBOM format is machine-readable (SPDX or CycloneDX), not a document
## Section 524B (PATCH Act) considerations
- [ ] A plan exists to monitor, identify, and disclose post-market
cybersecurity vulnerabilities
- [ ] A process exists to provide "reasonable assurance" the device and
related systems are cybersecure, and to make patches/updates available
Useful next step
Provenance & review state
- Last reviewed
- Sources
-
- FDA Cybersecurity in Medical Devices (2023) — U.S. Food and Drug Administration
- FD&C Act Section 524B — U.S. Food and Drug Administration
- IEC 81001-5-1:2021 — International Electrotechnical Commission
- Ingested from
-