FDA’s February 2026 revision is a minor update, announced in advance by the 2025 version, with no surprises. It aligns the guidance with the Quality Management System Regulation (QMSR), which took effect February 2, 2026 and incorporates ISO 13485:2016.
What FDA expects in a submission is unchanged: threat model, risk assessment, SBOM, architecture views, testing, labeling, management plan, and section 524B documentation.
Two actions follow
- FDA updated its terminology; manufacturers should do the same. Replace “QS regulation” and “design controls” with “QMSR” and “design and development” in procedures, templates, and traceability, and cite ISO 13485 clauses in place of 21 CFR 820.30.
- FDA states that risk management runs throughout ISO 13485’s requirements; security risk management should run throughout your development process. If your security risk assessment is a one-time design-validation deliverable, make it a lifecycle process.
Where this sits
This is the third revision of the premarket guidance in thirty months, and the second of them carries a title that differs from its predecessor by one word. If you are not sure which version your submission or your SOPs were written against, the version record is here: Which FDA cybersecurity guidance applies to my submission?
The substantive change was the June 2025 update, and our section-by-section read of it is here: The 2025 FDA premarket cybersecurity guidance
The second action above is the one with real work behind it. Turning a one-time security risk assessment into a lifecycle process touches your procedures, your traceability and who owns the reassessment when a threat changes. If you want a second pair of eyes on what that looks like for your device, schedule a call.