> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CDRH Endorses Device Cybersecurity Standard
- URL: https://www.fdaweb.com/cdrh-endorses-device-cybersecurity-standard/
- Published: 2023-11-06T12:00:00.000Z
- Updated: 2026-09-14T14:15:18.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5155727

CDRH says it has recognized and supports industry’s use of a key consensus standard to support device sponsors in their cybersecurity efforts. The standard in entitled “ANSI/AAMI SW96:2023 Standard for medical device security —- Security risk management for device manufacturers.” The Center says it “aligns with existing international safety risk management standards and quality systems expectations, and provides direction to sponsors on how to consider and address cybersecurity risks in device design and development.”

The [standard](https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDIsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3LmFjY2Vzc2RhdGEuZmRhLmdvdi9zY3JpcHRzL2NkcmgvY2Zkb2NzL2NmU3RhbmRhcmRzL3Jlc3VsdHMuY2ZtP1BBR0VOVU09NTAwJmFzY2FwaWxvdHluPW9mZiZjYXRlZ29yeT0mZWZmZWN0aXZlZGF0ZWZyb209JmVmZmVjdGl2ZWRhdGV0bz0mb3JnYW5pemF0aW9uPSZwcm9kdWN0Y29kZT0mcmVjb2duaXRpb25udW1iZXI9JnJlZmVyZW5jZW51bWJlcj0mcmVndWxhdGlvbm51bWJlcj0mc29ydGNvbHVtbj1wZGQmc3RhcnRfc2VhcmNoPTEmc3VwcG9ydGluZ2RvY3N5bj1vZmYmdGl0bGU9JnV0bV9tZWRpdW09ZW1haWwmdXRtX3NvdXJjZT1nb3ZkZWxpdmVyeSIsImJ1bGxldGluX2lkIjoiMjAyMzExMDYuODUyMzA1MDEifQ.PdhJ7w2d0UYACs7v5sYf9N7PfhhxV4WYWnkwpX1Dp-M/s/1255931999/br/230097649021-l?ref=fdaweb.com) is intended to provide requirements and guidance when addressing design, production and post-production security risk management for devices within the risk management framework defined by ISO 14971, according to the agency. It assists manufacturers with identifying threats, vulnerabilities, and assets associated with medical devices and their components and supply chain vendors. It also helps firms determine appropriate security risk controls to reduce security risks, and then verify and monitor the effectiveness of the security risk controls.