Device Cybersecurity Guide Coming by 9/30: FDA
FDA is planning to finalize by 9/30 its draft guidance entitled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” which replaced a 2018 draft guidance on content of premarket submissions for management of cybersecurity in medical devices. If all goes as planned, the guidance will be available 10/1, which is the effective date when CDRH says it will begin issuing refuse-to-accept letters for device submissions missing required cybersecurity information that was mandated at the end of last year in the omnibus spending bill, according to CDRH Office of Strategic Partnerships and Technology Innovation director Suzanne Schwartz. “We are working very diligently in trying to get that finalized,” she said during an online govinfosecurity.com interview.
FDA said the new draft guidance was intended to “further emphasize the importance of ensuring that devices are designed securely, enabling emerging cybersecurity risks to be mitigated throughout the total product lifecycle and to outline FDA’s recommendations more clearly for premarket submission content to address cybersecurity concerns.”
According to the refuse-to-accept policy, CDRH says device submissions should include:
- a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits,
- a software bill of materials, including commercial, open-source, and off-the-shelf software components