> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# New FDA Cybersecurity Safeguard Requirements
- URL: https://www.fdaweb.com/new-fda-cybersecurity-safeguard-requirements/
- Published: 2023-04-11T12:00:00.000Z
- Updated: 2026-09-14T18:24:52.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5154188

Attorneys **Dominick DiSabatino** and **Audrey Crowell** (Sheppard Mullin) say a recent FDA guidance and FAQ document explain new medical device cybersecurity safeguard requirements from the Consolidated Appropriations Act of 2023\. The attorneys [cover](https://www.lexology.com/library/detail.aspx?g=4a265486-492a-4b4f-9494-4a618531b0d0&ref=fdaweb.com) which submissions are subject to the new cybersecurity requirements, what the new requirements are, and how the new requirements fit into the current regulatory scheme.

Under the law, manufacturers of covered cyber devices must demonstrate compliance with each of these requirements in all pre-market applications submitted after 3/29 for products that qualify as cyber devices:

- submit a plan to monitor, identify, and address, as appropriate, in a reasonable time, post-market cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures;
- design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available post-market updates and patches to the device and related systems; and
- provide a software bill of materials, including commercial, open-source, and off-the-shelf software components.

FDA has said it will exercise enforcement discretion until 10/1, presumably to give industry time to adjust to the new requirements, the attorneys say.