On this page
Published: July 25, 2026
Key Takeaways
- Section 524B(b)(1) makes a postmarket cybersecurity plan a binding submission element for every cyber device.
- The obligation applies across 510(k), De Novo, PMA, PDP, and HDE - not only 510(k).
- IDE submissions are not enumerated in 524B(a), but the Feb 3, 2026 FDA guidance still expects postmarket thinking.
- Enforcement usually starts with a 483 or Warning Letter, not prosecution - but a submission hold is faster and more damaging commercially.
- A minimum viable postmarket program is finite, documentable, and defensible on inspection.
Yes, effectively. If your cleared submission included a Section 524B(b)(1) postmarket cybersecurity plan and you aren't executing it, you are out of compliance with the FD&C Act, exposed to a 483, a Warning Letter, and a refusal of your next submission. This applies to every 524B(a) pathway: 510(k), De Novo, PMA, PDP, and HDE.
You cleared. The submission is done. The postmarket monitoring plan you attached to satisfy Section 524B(b)(1) is now a live commitment - not a formality. If nothing behind that plan is actually running, the device as marketed no longer matches the device as cleared, and the FDA has multiple regulatory hooks to act on it.
Why this matters
Postmarket cybersecurity is where most cleared cyber devices quietly fall out of compliance. The submission gets the attention; the ongoing obligation does not. Under the FD&C Act and the FDA's February 3, 2026 final premarket cybersecurity guidance, the postmarket plan you filed is treated as an executed commitment, not a document. Missing it is not a paperwork gap - it is a mismatch between the cleared device and the marketed device, and it is the single fastest way to lose a next submission, catch a Warning Letter, or end up in a recall you cannot defend when a widely used SBOM component gets a new CVE.
What Section 524B(b)(1) Actually Requires
Section 524B(b)(1) of the FD&C Act (21 U.S.C. 360n-2) requires the sponsor of a cyber device to submit a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures.
That is not a template line. It is a description of an active program. Reviewers accept a plan on the assumption you will operate it - the same way they accept a labeling claim on the assumption you will honor it. Once cleared, the plan carries three enforceable ideas:
- You have a way to find vulnerabilities affecting your device - through SBOM monitoring, vendor advisories, ICS-CERT/CISA, NVD, and researcher intake.
- You triage and act within a defined, reasonable time - severity, exploitability, and patient impact drive cadence.
- You have a coordinated vulnerability disclosure (CVD) path - a real inbox, a public policy, and an owner.
The Feb 3, 2026 final premarket guidance ("Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions") is the operative interpretation reviewers apply when they judge whether the plan is real. It is not itself binding, but a submission that does not match its expectations gets treated the same way in practice.
Yes, It Applies to De Novo, PMA, PDP, and HDE Too
This is the piece most teams get wrong. Section 524B(a) enumerates the covered pathways explicitly. If your device is a cyber device under 524B(c), the postmarket obligation attaches regardless of pathway:
- 510(k) - 21 U.S.C. 360(k)
- De Novo - FD&C Act Section 513
- PMA - FD&C Act Section 515(c)
- PDP - FD&C Act Section 515(f)
- HDE - FD&C Act Section 520(m)
IDE submissions (Section 520(g)) are not enumerated in 524B(a), so the statute does not attach the same RTA teeth. The Feb 3, 2026 guidance still expects cybersecurity considerations - including postmarket thinking - for IDEs where they apply. So the honest framing for IDE holders is: not a 524B pathway, still a guidance expectation.
PMA and HDE holders have an additional wrinkle. PMA-approved devices carry postmarket surveillance and annual reporting obligations that already existed under Section 519 and 21 CFR 814 - postmarket cybersecurity findings that affect safety or effectiveness generally flow into those reports. HDE holders operate under the Section 520(m) profile and are similarly on the hook for postmarket surveillance of an approved device. In both cases, an unrun 524B(b)(1) plan doesn't just sit in a submission file - it also creates a gap in what you're expected to report annually.
The Legal Stack You're Touching by Not Doing Postmarket
Not running the plan is rarely a single-statute problem. It touches a stack:
| Statute or regulation | How the gap bites you |
|---|---|
| FD&C Act §524B(b)(1) | You represented that a plan exists and is being executed. Not doing it is a mismatch with the cleared/approved device. |
| FD&C Act §502 (misbranding) | Representations to the FDA and in labeling that do not match reality can render the device misbranded. |
| 21 CFR 806 | Corrections and removals for risk-to-health issues, including unpatched exploitable vulnerabilities, must be reported within 10 working days. No monitoring means you cannot comply. |
| 21 CFR 803 (MDR) | Cyber events causing or contributing to serious injury or death are reportable. Without intake, you miss MDRs. |
| 21 CFR 820 / QMSR (ISO 13485 §8.5) | CAPA requires you to detect and act on postmarket problems. No monitoring is a systemic QMS gap, and it is findable on inspection. |
| 21 CFR 814 (PMA annual reports) | For PMA and HDE, postmarket cybersecurity findings feed into annual reporting. Missing them is a reporting gap on top of the 524B gap. |
| FDA 2016 Postmarket Cybersecurity Guidance | The operative interpretation for postmarket program design. |
The QMSR final rule took effect Feb 2, 2026, replacing the Part 820 QSR with ISO 13485:2016 incorporated by reference. That is why the Feb 3, 2026 premarket guidance carries the "Quality Management System" title. The QMS hook to postmarket cybersecurity is stronger under QMSR, not weaker.
What "Breaking the Law" Actually Looks Like in Practice
The FDA rarely prosecutes solo. What actually happens, roughly in order of likelihood:
- 483 observation on your next inspection - no vulnerability intake, no SBOM monitoring, no CVD process, no CAPA linkage. This is the most common outcome.
- Warning Letter if the 483 is not addressed - public, indexed by search, and disqualifying in enterprise sales cycles.
- Recall or Safety Communication if an exploitable vulnerability surfaces in an SBOM component (Log4j, OpenSSL, curl class of events) and you had no process to detect and act on it.
- Refusal of your next submission - 510(k), Special 510(k), PMA supplement, De Novo, or HDE amendment - until postmarket evidence exists. This is often the fastest commercial pain.
- Civil penalties or consent decree in the worst case - reserved for repeat or willful conduct.
See also: Does FDA 524B Apply to Legacy Medical Devices?, FDA Section 524B Subsections Explained, and CAPA and Medical Device Cybersecurity.
There is a parallel commercial track. Hospital and IDN security questionnaires (HSCC MDS2, Mayo, Kaiser, HCA, Providence) ask directly whether you operate a postmarket cybersecurity program. "No" is disqualifying at most large health systems and increasingly at mid-market IDNs. In practice, the commercial consequence often arrives before the regulatory one.
Minimum Viable Postmarket Program to Get Compliant Fast
You do not need a full program on day one. You need a defensible one. The following is the minimum viable shape reviewers and inspectors expect to see:
- CVD intake - a monitored
security@yourdomaininbox, a public/cvdor/security.txtpage, and a named owner. - SBOM monitoring - feed the cleared SBOM into a matcher (Dependency-Track, GitHub Advanced Security, or a commercial tool) against NVD, CISA/ICS-CERT, and vendor advisories. See our SBOM vulnerability management playbook for triage wiring.
- Triage SOP - severity, exploitability, and patient-impact scoring with a documented cadence (for example, critical patched within 60 days, high within 90).
- Communication path - how you notify customers, hospitals, and the FDA when patient safety is affected.
- CAPA linkage - every triaged vulnerability enters your QMS CAPA system.
- Records - you have to be able to prove all of the above on inspection.
That is the shape of AAMI TIR97, which is the operational template FDA investigators benchmark against. Our postmarket cybersecurity monitoring guide walks through each block in the level of detail an inspector would ask for.
If you are still upstream - preparing or defending a submission - the 524B thread runs through our Section 524B requirements explainer and the 2026 FDA premarket cybersecurity guidance breakdown.
How Blue Goat approaches this
We build postmarket cybersecurity programs to the shape the FDA actually inspects: CVD intake, SBOM-driven vulnerability monitoring, triage with documented cadence, CAPA linkage, and evidence you can produce in a binder during an inspection. For teams that cleared under 510(k), De Novo, PMA, PDP, or HDE and never operationalized the plan they filed, we scope a 30-day gap-close - inventory the commitments in the submission, stand up the missing intake and monitoring, wire the triage into the QMS, and document everything against AAMI TIR97 and the Feb 3, 2026 guidance. The result is a program you can defend on inspection and cite in the next submission.
FAQ
Does Section 524B apply to my device if it was cleared before Oct 1, 2023?
Section 524B took effect March 29, 2023, and the FDA began actively enforcing RTA on that basis on October 1, 2023. Devices cleared before that are not automatically retro-scoped into 524B via the original clearance, but any subsequent submission - Special 510(k), PMA supplement, De Novo amendment - is evaluated under current 524B expectations. And the FDA's separate 2016 postmarket guidance already expected postmarket vulnerability management for connected devices long before 524B existed.
I got cleared under De Novo, not 510(k). Same rules?
Yes. Section 524B(a) enumerates De Novo alongside 510(k), PMA, PDP, and HDE. The postmarket plan requirement in 524B(b)(1) attaches identically. PMA and HDE holders also carry additional postmarket surveillance and annual reporting expectations under Section 519 and 21 CFR 814.
What about IDE - do I owe the FDA a postmarket cybersecurity plan?
IDE (Section 520(g)) is not enumerated in Section 524B(a), so 524B's RTA teeth do not attach. The FDA's Feb 3, 2026 premarket cybersecurity guidance still expects cybersecurity considerations for IDE submissions where they apply, and the investigational context itself creates postmarket-style monitoring expectations for enrolled subjects.
If my SBOM has a component with a new critical CVE, do I have to report it?
Not automatically. You have to triage it. If the vulnerability is exploitable in your device and creates a risk to health, 21 CFR 806 correction and removal reporting can apply (10 working days), and 21 CFR 803 MDR reporting attaches if the event causes or contributes to a serious injury or death. The obligation to triage - and to be able to prove you did - is the point of the postmarket plan.
Will the FDA actually inspect me on cybersecurity?
Cybersecurity is a routine element of BIMO and QSR/QMSR inspections now, not a special program. Investigators ask about vulnerability intake, SBOM monitoring, triage cadence, CAPA linkage, and complaint handling that touches security. Absence of any of these is a standard 483 category.
Does the Warning Letter or 483 become public?
483s are not automatically public but are FOIA-able and frequently posted by third-party trackers. Warning Letters are published by the FDA on issuance. Both surface in hospital and IDN security due diligence.
Where do I start if I have literally nothing running?
Stand up CVD intake (inbox plus public page) this week, get your SBOM into a monitoring tool next week, and document a triage SOP with cadence. Then wire CAPA linkage. That sequence produces a defensible program in about 30 days. Our postmarket monitoring guide is the operational playbook.
If you cleared under 524B and want a scoped assessment against the plan you filed, contact Blue Goat Cyber or explore our postmarket cybersecurity service.
Related reading
- SBOM for Medical Devices - the field guide - format, contents, and how the SBOM feeds postmarket vulnerability monitoring.
- Coordinated Vulnerability Disclosure (CVD) - our public CVD policy and the shape the FDA expects yours to take.
- FDA Section 524B Cybersecurity Requirements Explained - the full statute walkthrough, including 524B(b)(1) postmarket obligations.
- Postmarket Cybersecurity Monitoring Program - the operational template inspectors benchmark against.
- SBOM Vulnerability Management for Medical Devices - how to wire SBOM matches into triage and CAPA.
About the author
Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 250+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
