Article · September 10, 2026

Which FDA cybersecurity guidance applies to my submission?

Four FDA premarket cybersecurity guidances share almost the same name. Which one is current, what each superseded, and how to tell which applies to your submission.

Four FDA premarket cybersecurity guidance documents share nearly the same name, three of them within thirty months. Teams routinely cite a superseded version in a submission, or search for a version that never existed. This page is the version record, kept current.

The three recent ones live at one address, docket FDA-2021-D-1158: Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. That page always serves the current version, which is why a link you saved two years ago now shows something different from what you read.

The version record

TitleStatusSuperseded
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket SubmissionsCurrent. FDA marks this page current as of 3 February 2026the 27 June 2025 version
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket SubmissionsSuperseded. Issued 27 June 2025the 27 September 2023 version
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket SubmissionsSuperseded. Issued 27 September 2023the 2014 premarket guidance
Content of Premarket Submissions for Management of Cybersecurity in Medical DevicesSuperseded. Issued October 2014the earliest in this line

Two things about that table are worth saying plainly.

The 2023 and 2025 documents have the identical title. Nothing in the name distinguishes them. If a submission, a supplier agreement, or an internal SOP cites “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” with no date, it is ambiguous, and a reviewer cannot tell which one you meant. Cite the date.

The February 2026 version changed the title, from “Quality System” to “Quality Management System”. That single word is the only reliable way to tell the current document from its two predecessors by name alone.

Is there a February 2026 guidance? Yes

It is a fair question to ask, because FDA’s own Cybersecurity hub page has at times still described the June 2025 document as the current final while the guidance page itself served the newer one. When two FDA pages disagree, the guidance document page is the one to trust: it carries the docket number and the supersession statement.

The postmarket guidance is separate, and it has not moved

Postmarket Management of Cybersecurity in Medical Devices was issued in December 2016 and is still the current postmarket guidance. It is a different document with a different job, and it is not superseded by any of the premarket updates above. A cybersecurity program needs both.

How to tell which one your submission was written against

Three checks, in order:

  1. Look for the word “Management” in the title you cited. Present means the current version. Absent means 2023 or 2025.
  2. Look for a Cybersecurity Management Plan requirement covering every submission, not only those that previously required one. That expectation arrived with the June 2025 update, so a document without it is the 2023 version.
  3. Look for Section VII on section 524B of the FD&C Act. The June 2025 update added it.

If your submission is in preparation now, write against the current version and say which one you used, with its date. If your submission is already with FDA under an older version, a deficiency response is the usual place the difference surfaces, and it is easier to address when you already know which document you built from.

What changed in the June 2025 update

We read the June 2025 document against the September 2023 one when it came out. The vast majority of the changes are in Section VII (pp. 30 to 36), which is entirely new. Everything else is very minor.

  • Section VII B. A “cyber device” includes any device with software and a digital hardware or radio frequency interface (including USB, NFC, Ethernet, Bluetooth), even if disabled by default or hidden behind an external enclosure. Previously stated in an interim clarification published April 2024.
  • Section VII C 1. A Cybersecurity Management Plan is to be provided for all regulatory submissions, regardless of whether they were previously required.
  • Section VII C 2. Manufacturers include related systems when taking steps to provide reasonable assurance of cybersecurity, which may include those they manage as well as those from other vendors and healthcare providers.
  • Section VII C 3. SBOMs are to be provided as part of premarket processes. Consistent with public statements, specified in the PATCH Act, and previously stated in the April 2024 interim clarification.
  • Section VII D. Clarifies what constitutes a change to a device that may affect cybersecurity, versus changes that are unlikely to.
  • Section VII D 2. Submissions describe vulnerabilities discovered since the last submission that could affect safety and effectiveness (the “uncontrolled risks”), and how they were remediated. Consistent with the existing postmarket guidance.
  • Section VII D 2, and this one is new rather than a clarification. A Cybersecurity Management Plan must account for reports from third parties such as cybersecurity researchers, with provisions to receive, assess, coordinate disclosure, and address vulnerabilities and exploits. The postmarket guidance already required manufacturers to have this capability. This is the first time documentation of it has been required during a premarket submission.
  • Section VII D 2. Cybersecurity capabilities must be updated to match current risks, including those from evolving threats, new technologies (such as adding network or radio frequency capability) and new environments (such as a hospital versus a lab), not only those assessed when the device was first approved.
  • Minor. New standards added (such as ANSI/AAMI SW96) and references to FDA documentation published since the prior final guidance (such as 89 FR 7496).

Read in one place, that list has a shape: almost all of it was already said in public, in interim clarifications, or in the postmarket guidance. One item is genuinely new, and it is the third-party reports provision. If you are budgeting time against this update, budget it there.

Our full read, clause by clause, is here: The 2025 FDA premarket cybersecurity guidance, with the original internal review attached as a document.

What changed in February 2026

A minor update, announced in advance by the 2025 version, with no surprises. It aligns the guidance with the Quality Management System Regulation (QMSR), which took effect 2 February 2026 and incorporates ISO 13485:2016. What FDA expects in a submission is unchanged: threat model, risk assessment, SBOM, architecture views, testing, labeling, management plan, and section 524B documentation.

Two things follow for manufacturers: update the terminology (QMSR and “design and development” in place of “QS regulation” and “design controls”, ISO 13485 clauses in place of 21 CFR 820.30), and treat security risk management as a lifecycle process rather than a one-time design-validation deliverable. The full note is here: What the February 2026 FDA premarket update changes.

What FDA reviewers have been asking for since, on known vulnerabilities: FDA is asking for known vulnerabilities alongside your SBOM.

Working out what a version change means for a submission in flight? Get in touch.

Get in touch

Working through the same questions on your device or program?