Industry

Medical Device and SaMD

The only industry where a security document is read by someone who can stop you shipping.

Medical device cybersecurity is unusual in that the requirements are written down, the reviewer is specific, and the consequence of getting it wrong is a submission that does not proceed. That makes it more tractable than most compliance work and less forgiving.

It also catches more companies than expect it. Section 524B has no hardware requirement anywhere in its definition, so a connected software-only product going through a 510(k), De Novo or PMA carries the same three obligations as a device with a radio in it.

The pressure

What this sector is actually under

Section 524B, in three parts

A plan to monitor and address postmarket vulnerabilities including coordinated disclosure, processes providing a reasonable assurance that the device and related systems are cybersecure, and a software bill of materials. FDA has been able to base a refuse-to-accept decision on this content alone since 1 October 2023.

Requirements, not principles

The pattern underneath most cybersecurity deficiencies. "The product uses TLS 1.3" is a principle; a named cipher suite with a requirement ID, a test that exercises it and a traceability matrix entry is a requirement. The conversion is most of the work.

Claims nobody re-checked

An architecture document asserts a protection, goes into a submission, and is never read against the implementation again. An inaccurate security claim is worse than an absent one, because it misrepresents the product to the person deciding whether it is safe.

The postmarket plan needs an owner

You are submitting a promise about how your company will behave for years after clearance. The failure mode is not a badly written plan. It is a well-written plan describing a process that requires somebody to own it, at a company where nobody does.

Testing that has to be evidence

FDA treats penetration testing as the primary validation that controls work in the finished product. Tester independence, scope, methods and results all get scrutiny, and every finding needs a disposition you can defend.

Guidance that keeps moving

Three versions of the premarket cybersecurity guidance in under three years, the most recent aligning it to the Quality Management System Regulation. A package prepared against a superseded document is read against the current one.

Where to start

Which side of the practice you need

If a letter has arrived, or a submission is going out with a cybersecurity section nobody is confident in, that is scoped project work rather than a role.

If the deeper problem is that nobody owns security between submissions, that is the fractional CISO side. If the architecture cannot support the claims the submission needs to make, that is the CTO side, and at seed to Series B it is usually both.

The two pillars

Where this usually starts

Common questions

Questions I get asked first

We ship software only, with no hardware. Does any of this apply?

Yes. There is no hardware requirement in the cyber device definition. A connected SaMD product regulated through a 510(k), De Novo, PMA, PDP or HDE carries the same three obligations, and the deficiencies raised against it look much the same minus the ones about radios and firmware update.

How much of this is documentation versus engineering?

More documentation than teams expect, but not only documentation. Most of the effort goes into producing testable requirements and verification evidence rather than new code. Some claims cannot be documented into being true, and those need the engineering done first.

Do you replace our regulatory consultant?

No. I do the cybersecurity engineering and the documentation that has to survive a reviewer reading it. Regulatory strategy for a specific submission belongs with your regulatory lead, and this works alongside them rather than instead of them.

Related reading

Written on this

Start with a conversation

Tell me what’s going on. I will tell you which of these it actually is, and whether you need me for it.

Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.

Not ready for a call? Send a message instead.

For companies looking to engage BATO. Vendors, please email.