Does Section 524B Apply to My Auto-Injector?
Section 524B applies to a connected auto-injector when the device constituent has software and any electronic interface, regardless of whether CDER or CDRH leads review.
Read articleDeep dives on FDA expectations, threat modeling, penetration testing, SDLC, and the standards your team is being asked to meet.
Showing 12 of 274 articles · Page 1 of 23
Section 524B applies to a connected auto-injector when the device constituent has software and any electronic interface, regardless of whether CDER or CDRH leads review.
Read article
How de-identification and anonymization differ for medical device data under HIPAA Safe Harbor, Expert Determination, GDPR, and FDA AI/ML expectations — and where teams get it wrong.
Read article
How Threat Analysis and Risk Assessment (TARA) fits FDA premarket cybersecurity, AAMI TIR57, and ISO 14971 for medical device manufacturers in 2026.
Read article
How to run a design FMEA (dFMEA) for a connected medical device, link it to the ISO 14971 risk file, and hand off cyber-triggered failure modes to the threat model the FDA expects.
Read article
How to wire SAST, SBOM, secrets, container, and signature gates into a medical-device CI/CD pipeline so the SPDF produces the evidence FDA reviewers expect under the Feb 3, 2026 guidance.
Read article
What happens if you fail an FDA cybersecurity inspection: the 483-to-consent-decree enforcement ladder and the commercial fallout for device makers.
Read article
How to document update cadence for an FDA §524B submission: the regular cycle and the out-of-cycle expedited path reviewers expect under §524B(b)(2)(B).
Read article
FDA Section 524B applies to any new premarket submission for a cyber device, including legacy platforms. What attaches, what postmarket rules cover the rest.
Read article
SPDF vs SSDLC for medical devices. Why the FDA's Secure Product Development Framework demands more than a standard Secure SDLC, and what to add.
Read article
What medical device cybersecurity actually costs in 2026 - the four cost drivers, fixed-fee vs hourly pricing, premarket vs postmarket budget lines, and the cost of delay.
Read article
How SPDF activities map to IEC 62304 software lifecycle processes - the exact crosswalk FDA reviewers expect, where they overlap, and where 62304 falls short.
Read article
The threat intelligence sources medical device manufacturers should monitor to satisfy FDA Section 524B postmarket obligations: H-ISAC, CISA KEV, ICS advisories, NVD, MITRE ATT&CK for ICS, and vendor PSIRTs.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.