Medical Device & SaMD
Premarket cybersecurity for connected devices and software-only products alike, FDA submissions, and the engineering behind a defensible security claim.
Is Your Product a "Cyber Device" Under Section 524B?
Section 524B's cyber device test has three prongs and all must be met. The connectivity prong is read far more broadly than most self-assessments assume.
The Four Security Architecture Views, and What Actually Goes in Them
FDA recommends four security architecture views. Everyone lists the names. Here is what belongs in each diagram and which question each one has to answer.
What Does FDA Actually Want in a Threat Model?
FDA expects a structured threat model that the rest of the submission derives from. Start with trust boundaries, and rank the results by patient harm.
Why Your Security Risk Assessment Cannot Live in Your 14971 File
FDA treats security risk management as a process distinct from safety risk management. They score differently, and they converge at exactly one place.
Your Security Controls Are Not Requirements Yet
FDA expects security controls written as uniquely identified, testable requirements traced to threats and tests. Most submissions contain principles instead.
Does a Security Patch Require a New 510(k)?
A change made solely to strengthen cybersecurity rarely needs a new 510(k). The word doing the work is solely, and most real patches are not solely anything.
FDA Changed Its Cybersecurity Guidance Again. What Actually Moved?
FDA reissued its premarket cybersecurity guidance to align with the QMSR. The requirements did not change. Your citations did, and so did where security lives.
One Credential, Every Device: Reading a CISA Advisory as a Design Failure
A CISA advisory describes one hard-coded credential shared across every unit of a connected therapy device. Five ordinary controls would each have caught it.
Standing Up a Coordinated Vulnerability Disclosure Program
Section 524B requires a coordinated disclosure process. The mechanics take a week. What makes it real is naming who owns the hop from inbox to the fix.
There Is Finally a Common Standard for Medical Device Penetration Testing
MDIC published a consensus penetration testing framework for medical devices. Four of its five stages sit outside the test, and that is where programs fail.
Your SBOM Lists the Framework, Not the 1,000 Packages Underneath
Most first-draft SBOMs name the framework and the major libraries and stop. The vulnerabilities are in everything those pulled in, which is where the work is.
Responding to an FDA Cybersecurity Deficiency Letter
What an FDA cybersecurity deficiency letter asks for, why the 180-day clock is shorter than it looks, and what changes when your product is software-only.
FDA Section 524B: What Premarket Cybersecurity Actually Requires
What Section 524B requires in a premarket submission for cyber devices, why software-only products are covered, and where these submissions fall short.