Section 524B Cyber Device
FD&C Act section 524B is the FDA statutory rule for cyber-device premarket submissions. It is narrower than FDA's whole cybersecurity guidance, but it adds specific submission content when a device meets the cyber-device criteria.
Cyber-device criteria
A cyber device is a medical device that meets all three statutory criteria. The device must include sponsor-validated, sponsor-installed or sponsor-authorised software as a device or in a device. It must have the ability to connect to the internet. It must also contain sponsor-validated, sponsor-installed or sponsor-authorised technological characteristics that could be vulnerable to cybersecurity threats.
Section 524B(c) of the FD&C Act defines "cyber device" as a device that (1) includes software validated, installed, or authorized by the sponsor as a device or in a device, (2) has the ability to connect to the internet, and (3) contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to the cybersecurity threats.
FDA FAQ on section 524B, quoting FD&C Act section 524B(c)
FDA reads the connection element broadly. Firmware and programmable logic count as software for this purpose. Internet capability can be direct or indirect, intended or unintended, and can arise through the device threat surface and environment of use.
Software element
The criterion is about software in or as the device, including firmware and programmable logic, when the sponsor validates, installs or authorises it.
Connection element
FDA examples include network, server, cloud, Wi-Fi, cellular, Bluetooth, magnetic inductive communication, USB, Ethernet and serial-port paths.
Threat element
The technological characteristics must be capable of being vulnerable to cybersecurity threats. The question is not limited to whether the product is marketed as connected.
Submission pathways
Section 524B applies to the person who submits a covered FDA premarket application or submission for a cyber device. FDA identifies 510(k), PMA, product development protocol, De Novo and HDE pathways, including relevant supplements and Special or Abbreviated 510(k) submissions.
The statutory requirements do not apply to applications or submissions sent to FDA before 29 March 2023. FDA's FAQ states that, beginning 1 October 2023, FDA expected sponsors to have had enough time to prepare cyber-device submissions with the required section 524B information. If a previously authorised cyber device later needs new premarket review for a change, the new submission can bring section 524B into scope.
Obligations that attach
Section 524B does not ask for a single cybersecurity certificate. It requires submission information showing that the cyber device meets the cybersecurity requirements in section 524B(b). FDA's current final premarket guidance explains how the broader guidance evidence can support those statutory requirements.
The submission must include a plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time. FDA connects that plan to coordinated vulnerability disclosure, monitoring sources, patch timelines, customer communication and lifecycle updates to threat modelling and risk assessment records.
The sponsor must design, develop and maintain processes and procedures that provide reasonable assurance that the cyber device and related systems are cybersecure. FDA treats related systems as including manufacturer-controlled elements such as update servers, other device functions, software or firmware services, and connections to healthcare facility networks when those systems affect the cyber device.
Section 524B distinguishes regular updates for known unacceptable vulnerabilities from out-of-cycle updates for critical vulnerabilities that could cause uncontrolled risk. The plan should account for fielded versions, supported configurations and whether an update reaches all devices automatically.
A cyber-device submission must provide an SBOM covering commercial, open-source and off-the-shelf software components. FDA still expects the SBOM to work with risk management, vulnerability assessment and component-support information. It is not a replacement for those records.
Boundary with FDA guidance
The cyber-device definition is not the boundary of all FDA cybersecurity expectations. FDA's February 2026 final guidance addresses premarket cybersecurity design, labelling and documentation for devices with cybersecurity risk, and says section 524B cyber devices are a subset of devices within the guidance scope.
- A device can need FDA cybersecurity risk management evidence even if the sponsor concludes that section 524B does not apply.
- A non-internet-connected device can still raise cybersecurity issues through software, local ports, removable media, update mechanisms or its operating environment.
- A cyber-device conclusion does not by itself prove reasonable assurance of safety, effectiveness or cybersecurity.
- FDA guidance is non-binding guidance, while section 524B is statutory law for qualifying submissions.
Modifications and fielded versions
Section 524B information may differ by change type. FDA's least burdensome framing means a cyber-device modification submission should focus on the cybersecurity impact of the change, the current device architecture, the affected fielded versions and the required statutory elements. A change that does not affect cybersecurity will not need the same depth as a change to connectivity, update infrastructure, authentication, encryption, cloud services or third-party software.
Fielded configurations
If not every device receives an update automatically, the risk file should recognise different software configurations in the field.
Related systems
The analysis should include related systems when their security affects the cyber device, especially update servers, connected services and manufacturer-controlled software functions.