FDA Cybersecurity 2022 Guidance Explained
Attorney Brynn Stanley(Gardner Law) says medical device manufacturers should start planning and implementing the concepts found in an FDA April draft guidance on cybersecurity in both their products and within their quality management system. Writing in an online post, Stanley says that to be effective, cybersecurity needs to be “baked in” and not “bolted on.”
She says the 2022 draft guidance, which replaced a 2018 guidance, emphasizes the importance of ensuring that devices are designed securely and are capable of mitigating emerging cybersecurity risks throughout the total product lifecycle (TPLC). “This change to a TPLC approach,” Stanley writes, “will impact manufacturers as they begin to incorporate these concepts into not only their premarket submissions, as was the focus of the 2018 draft guidance, but also into their design controls processes. In fact, effects of the TPLC approach will be felt throughout a manufacturer’s quality management system. This is likely to have a big impact on manufacturers, especially for those with legacy products or for companies playing ‘catchup’ to the 2018 draft guidance.”