New FDA Cybersecurity Safeguard Requirements

Share

Attorneys Dominick DiSabatino and Audrey Crowell (Sheppard Mullin) say a recent FDA guidance and FAQ document explain new medical device cybersecurity safeguard requirements from the Consolidated Appropriations Act of 2023. The attorneys cover which submissions are subject to the new cybersecurity requirements, what the new requirements are, and how the new requirements fit into the current regulatory scheme.

Under the law, manufacturers of covered cyber devices must demonstrate compliance with each of these requirements in all pre-market applications submitted after 3/29 for products that qualify as cyber devices:

  • submit a plan to monitor, identify, and address, as appropriate, in a reasonable time, post-market cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures;
  • design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available post-market updates and patches to the device and related systems; and
  • provide a software bill of materials, including commercial, open-source, and off-the-shelf software components.

FDA has said it will exercise enforcement discretion until 10/1, presumably to give industry time to adjust to the new requirements, the attorneys say.

Read more