Governance, risk & compliance
FDA Cybersecurity for Cyber Devices (Section 524B) 2026 guidance
Mandatory cybersecurity content for US premarket submissions.
Section 524B of the Federal Food, Drug, and Cosmetic Act (21 U. S.
C. 360n-2) has applied since 29 March 2023 to any "cyber device" - a device that includes software validated, installed, or authorized by the sponsor, can connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats.
Four things must be in the submission: a plan to monitor, identify, and address postmarket vulnerabilities and exploits, including coordinated vulnerability disclosure; processes providing a reasonable assurance the device and related systems are cyber secure, with updates and patches on a reasonably justified regular cycle and out-of-cycle for critical vulnerabilities; a software bill of materials covering commercial, open-source, and off-the-shelf components; and whatever else FDA requires by guidance. FDA will refuse to accept a submission for a cyber device that lacks this.
The governing guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions", was reissued 3 February 2026, superseding the 27 June 2025 and 27 September 2023 versions; the 2026 revision added no new technical requirements and re-pointed its quality-system references from the old 21 CFR 820. 30 design controls to the ISO 13485:2016 subclauses that QMSR now incorporates.
THIS IS NOT A QUALITY MANAGEMENT SYSTEM FRAMEWORK - QMSR and ISO 13485 govern your QMS and Lavawall does not replace them.
Assessment tiers & levels Lavawall supports
Lavawall assesses FDA Cybersecurity for Cyber Devices (Section 524B) at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Premarket submission | What goes in the 510(k), De Novo, PMA, or HDE: the cyber device determination, security architecture views, threat model, SBOM, testing evidence, and the security content of the labelling. Choose this if you are preparing a submission. | — |
| Postmarket lifecycle | What you must keep doing once the device is on the market: monitoring for vulnerabilities in your own code and your third-party components, coordinated vulnerability disclosure, the patch cadence you committed to, and end-of-support communication. Choose this if you have a marketed device. | — |
How Lavawall® helps you get to FDA Cybersecurity for Cyber Devices (Section 524B) compliance
Most of FDA Cybersecurity for Cyber Devices (Section 524B) comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to FDA Cybersecurity for Cyber Devices (Section 524B), and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against FDA Cybersecurity for Cyber Devices (Section 524B) in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports FDA Cybersecurity for Cyber Devices (Section 524B) as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- FDA Cybersecurity for Cyber Devices (Section 524B) 2026 guidance
- Category
- Industry
- Region
- USA
- Levels
- 2 assessment tiers
Map this framework freeTalk to our team