Device Cybersecurity Enforcement Discretion
An FDA guidance, Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices Under Section 524B of the FD&C Act, says the agency does not intend to issue “refuse to accept” decisions for premarket submissions submitted for cyber devices before 10/1 based solely on the information required by section 524B of the Federal Food, Drug, and Cosmetic Act (FFDCA). The document says that section is effective 3/29 and requires those who submit premarket submissions for cyber devices to include such information as the agency may require to ensure that the cyber device meets cybersecurity requirements in the law. The section was added to the FFDCA on 12/29/2022 by the Consolidated Appropriations Act for 2023.
The guidance says FDA “intends to work collaboratively with sponsors of such premarket submissions as part of the interactive and/or deficiency review process.” The agency expects that by 10/1, sponsors of cyber devices will have had sufficient time to prepare premarket submissions that contain the required information and thus FDA may refuse to accept those submissions that do not have the information.
The guidance is being implemented immediately because FDA determined that prior public participation is not feasible or appropriate.