> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Cybersecurity Draft Guidance Clarifications Sought
- URL: https://www.fdaweb.com/cybersecurity-draft-guidance-clarifications-sought/
- Published: 2019-03-19T12:00:00.000Z
- Updated: 2026-09-15T01:13:50.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5143643

The Consumer Healthcare Products Association (CPHA) says that while it agrees with several principles underlying an FDA draft guidance on content of premarket submissions for managing medical device cybersecurity, there are several elements that should be clarified. In a comment [letter](https://www.regulations.gov/document?D=FDA-2018-D-3443-0025&ref=fdaweb.com) CPHA highlights these points: **(1)** FDA should clarify the criteria for a Tier 1 device; **(2)** low-risk devices should not be considered to be Tier 1; and **(3)** FDA should maintain a flexible approach to how manufacturers apply recommended cybersecurity controls.

AdvaMed says **(1)** FDA should eliminate the proposed two-tier risk approach; **(2)** FDA should explain its authority over the cybersecurity bill of materials and what its expectation is for how often a manufacturer would be expected to update the bill of materials; **(3)** the proposed labeling recommendations should focus on product communications; **(4)** FDA should explain its plan for implementing the draft guidance; and **(5)** the agency should address forensic design elements and account for diversity in device design.