Frequently Asked Questions
These questions separate the most common medical-device cybersecurity confusions: FDA versus EU evidence, cyber-device status, SBOM versus threat modelling, standards, patches, and user information.
Regulatory boundaries
No. Software is central, but the file also covers device architecture, interfaces, update paths, data flows, operating environment, user information, vulnerability handling, and clinical impact.
No. FDA guidance is submission-facing and postmarket-facing for the US system. EU MDR evidence belongs in the EU conformity file, PMS, vigilance, user information, and general safety and performance requirements.
Not automatically. Section 524B has specific criteria. The dedicated cyber-device page should be used when deciding whether statutory submission content attaches to a device.
Evidence records
No. An SBOM lists software components. A threat model explains how architecture, interfaces, data flows, misuse, and attack paths can affect safety, performance, or effectiveness.
No. It is a lifecycle process standard for health software. It can support secure development and maintenance evidence, but legal obligations still come from the applicable regulator and product law.
Lifecycle and users
No single answer applies. Reporting depends on jurisdiction, device status, risk, patient-harm potential, correction or removal rules, and whether the update is routine maintenance or addresses a serious issue.
User information should support safe and secure operation. Common topics include secure configuration, accounts, backups, logs, update paths, minimum IT environment, supported versions, residual risks, and shared responsibilities.