Q-Sub vs Pre-Sub: FDA Cybersecurity Guide
Q-Sub vs Pre-Sub for FDA cybersecurity: what they are, how they differ, and when to use a Pre-Submission to de-risk Section 524B threat models, SBOMs, and pen tests.
Read articleEvery article in our archive tagged Section 524B.
Showing 12 of 32 articles tagged Section 524B · Page 1 of 3
Q-Sub vs Pre-Sub for FDA cybersecurity: what they are, how they differ, and when to use a Pre-Submission to de-risk Section 524B threat models, SBOMs, and pen tests.
Read article
AAMI SW96 didn't formally replace TIR57, but SW96 is now the FDA-recognized normative standard. Here's what changed and what the FDA expects in 2026.
Read article
FDA Submission Issue Request (SIR) response strategy for cybersecurity: eSTAR prep checklist, common 524B gaps, and how to answer without restarting review.
Read article
Medical device pen testing under FDA vs EU MDR: the 5 FDA report elements, MDR Annex I §17.2/17.4, and how one report serves both submissions.
Read article
A five-source workflow (510(k), De Novo, PMA, MAUDE, FOIA) for mining FDA cybersecurity precedent by product code before a Section 524B filing.
Read article
The FDA PCCP guidance isn't AI-only. Use a predetermined change control plan for cybersecurity patches, firmware updates, and SBOM component swaps.
Read article
The FDA's Feb 3, 2026 guidance names 7 AI cyber threats, data poisoning, model inversion, evasion, leakage, overfitting, bias, drift, as 524B obligations.
Read article
FDA Section 524B applies to connected auto-injectors when the device constituent has software and any electronic interface, whether CDER or CDRH leads review.
Read article
How to document update cadence for an FDA §524B submission: the regular cycle and the out-of-cycle expedited path reviewers expect under §524B(b)(2)(B).
Read article
FDA Section 524B applies to any new premarket submission for a cyber device, including legacy platforms.
Read article
How SPDF activities map to IEC 62304 software lifecycle processes - the exact crosswalk FDA reviewers expect, where they overlap, and where 62304 falls.
Read article
The threat intelligence sources medical device manufacturers should monitor to satisfy FDA Section 524B postmarket obligations: H-ISAC, CISA KEV, ICS.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.