Article · June 27, 2025

The 2025 FDA premarket cybersecurity guidance: an evolution, not a revolution

FDA's June 2025 update to the premarket cybersecurity guidance is an evolution, not a revolution. Five expectations and clarifications to fold into your cybersecurity program.

This piece was first published as a LinkedIn post when the June 2025 update was released. FDA has since superseded that version, in February 2026; see what that update changes and the full version record.

The newly released FDA premarket guidance for medical device cybersecurity is an evolution (not a revolution), building off lessons learned through collaboration with medical device makers and members of the cybersecurity research community (including myself and many others). As you might expect, it falls in line with the updated messaging the Agency has published and what some of us in the industry and community have been discussing for the past several years.

If you’ve been staying current on trends a lot of this will look familiar; if not you’ll want to take a close look. In either case, it’s worth a read to understand the latest thinking.

Five things to watch for

While you’re reviewing and processing the updated document, keep your eyes out for these expectations and clarifications so you can incorporate them into your cybersecurity program:

  • A more explicit definition of a “cyber device”, to include pretty much anything with software and a digital hardware or radio frequency interface (including USB, NFC, Ethernet, Bluetooth), even if disabled by default or hidden behind an external enclosure.
  • The Cybersecurity Management Plan accounts for reports from third parties (such as cybersecurity researchers), with provisions to receive, assess, coordinate disclosure, and address vulnerabilities and exploits. This aligns with the existing postmarket guidance.
  • Cybersecurity Management Plans are to be provided for all regulatory submissions, regardless of whether they were previously required.
  • Submissions describe vulnerabilities discovered since the last submission that could affect safety and effectiveness (aka “uncontrolled risks”), as well as how they were remediated.
  • Cybersecurity capabilities must be updated to match current risks, not just those assessed when the device was first approved.

The guidance itself is on FDA’s site: Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (docket FDA-2021-D-1158). That address now serves the current version, which supersedes the June 2025 document this piece was written about.

The full section-by-section review

We wrote up the whole thing internally at the time, clause by clause, with a note on which changes were clarifications of something already said in public and which were genuinely new. That document is published as-is:

Internal Review of Updated Pre-Market Guidance, July 2025 (PDF)

Reading the list in one place makes a point worth making. Almost every change restates something already in an interim clarification, a public statement, or the postmarket guidance. One is genuinely new: the Section VII D 2 requirement that a Cybersecurity Management Plan account for reports from third parties, with provisions to receive, assess, coordinate disclosure, and address vulnerabilities. The postmarket guidance already required manufacturers to have that capability. This is the first time documentation of it has been required in a premarket submission. If you are budgeting time against the update, budget it there.

Looking to see how this update might affect your medical device? Get in touch and we can talk it through.

Get in touch

Working through the same questions on your device or program?