" " indicates required fields
The FDA’s Final Cybersecurity Guidance of June 2025 introduces significant new requirements under the FD&C Act, making cybersecurity a lifecycle obligation. Section 7 provides the most detailed interpretation to date.
The update consolidates all previous cybersecurity guidance documents and specifies how medical device manufacturers (MDMs) must address both premarket and postmarket risks, including the systems surrounding the device.
For your convenience, we summarized the new requirements of the cybersecurity mandate for MDMs to move forward proactively.

Section 524B of the FD&C Act requires MDMs to include cybersecurity information in their premarket approval applications to demonstrate that their devices meet security requirements.
A study showed that 53% of connected medical and healthcare IoT devices have at least one unpatched critical vulnerability.
MDMs must show that their products are designed with security top of mind, from initial development through deployment, to protect patient safety. Section 524B has become the new roadmap for cybersecurity compliance in medical devices.
The table below illustrates the full timeline of Section 524B:

What Qualifies as a Cyber Device?
Section 7 further expands the scope to include:
Expanded View: Securing the Healthcare Ecosystem
Compliance now includes related systems, such as:
Manufacturers must “establish and maintain procedures for validating the device design.” MDMs should design devices to limit the potential impact of vulnerabilities by enforcing a secure default configuration and notifying users when anomalous device behavior is detected.
There are other security barriers for MDMs, such as changes to authentication or encryption algorithms, which may delay product development or trigger additional regulatory review late in the product lifecycle, ultimately impacting device time-to-market and key stakeholders. A thorough risk assessment should document any risk mitigations to prevent device hazards in a premarket submission.
Security Updates to Existing Devices
Controlling user access is essential in preventing cyber risks. The section highlighted security control categories, such as authentication and authorization, among other areas.
Authentication best practices:
Authorization best practices:
Section 7 mandates that premarket submissions must include:
Section 524B requires manufacturers of cyber devices to provide an SBOM, which enables manufacturers to track all software components, dependencies, and potential vulnerabilities within the device, ensuring full transparency throughout the product lifecycle. Every component listed in the SBOM should include metadata such as version, supplier, and license type for accurate tracking, vulnerability assessment, and compliance.
The FDA now classifies security risks as either:
C2A Security’s EVSec platform supports medical device companies in meeting the FDA’s latest cybersecurity requirements by:
Schedule a demo to learn how C2A Security can help you stay ahead of the FDA’s latest regulatory requirements for medical devices.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data