
On this page
Published:
Key Takeaways
- A cyber device must meet all three parts of the Section 524B(c) test: sponsor software, ability to connect to the internet, and characteristics that could be vulnerable.
- The FDA reads "ability to connect to the internet" broadly, so Bluetooth, Wi-Fi, cellular, USB and network ports usually count.
- A device does not need to connect to the internet directly. A path through a phone, gateway or hospital network is enough.
- Section 524B applies to premarket submissions sent on or after March 29, 2023, including 510(k), De Novo, PMA and some other submission types.
- Purely mechanical devices with no software are not cyber devices.
Under Section 524B(c) of the FD&C Act, a cyber device is a device that includes software validated, installed or authorized by the sponsor, has the ability to connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats. The FDA reads "ability to connect" broadly. Bluetooth, Wi-Fi, cellular, USB and similar interfaces usually qualify, even without a direct internet link.
"Is my device a cyber device?" is the first question every medical device team asks about Section 524B. The answer decides whether your premarket submission must include an SBOM, a vulnerability monitoring plan and evidence of secure design.
Many teams assume their device is out of scope because it never touches the public internet. That assumption causes trouble late in the project.
The FDA's February 3, 2026 final guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," explains how the agency reads the definition. This post walks through the three-part test, how each part is interpreted, and a quick check you can run on your own device.
Why This Matters
Section 524B was added to the FD&C Act by the Consolidated Appropriations Act, 2023, and it applies to premarket submissions for cyber devices sent on or after March 29, 2023. If your device is a cyber device, the law requires three things in the submission: a plan to monitor, identify and address postmarket vulnerabilities, processes that provide reasonable assurance the device and related systems are cybersecure, and a software bill of materials.
The FDA's February 3, 2026 guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," describes the evidence behind those requirements in detail. The agency's premarket cybersecurity content set now spans 18 deliverables, which our FDA premarket cybersecurity deliverables and eSTAR map lists line by line.
Getting the applicability question wrong is costly. A team that decides too late that its device is in scope has to build a threat model, SBOM and testing evidence under deadline pressure. The standards behind that evidence are AAMI TIR57 and ANSI/AAMI SW96 for security risk management, IEC 81001-5-1 for secure development, and ISO 14971 for safety risk.
What are the three parts of the cyber device test?
A device is a cyber device only if it meets all three parts of Section 524B(c).
Section 524B(c) defines a cyber device as a device that "(1) includes software validated, installed, or authorized by the sponsor as a device or in a device; (2) has the ability to connect to the internet; and (3) contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats."
| Part | What it means in practice | Typical example |
|---|---|---|
| 1. Sponsor software | The device has firmware, software or programmable logic you validated, installed or authorized | Embedded firmware, SaMD, companion app |
| 2. Ability to connect | The device can connect to the internet, directly or indirectly | Wi-Fi, Bluetooth, cellular, USB, Ethernet |
| 3. Vulnerable characteristics | Some part of that software or connectivity could be attacked | Pairing, update path, data interfaces |
Part 3 is met by almost any device that meets parts 1 and 2. In practice, the decision usually turns on part 2.
How does the FDA read "ability to connect to the internet"?
The FDA reads "ability to connect to the internet" broadly. A device does not have to be online all the time, or connect directly, to meet this part of the test.
The 2026 guidance describes devices with features such as Wi-Fi, cellular, Bluetooth, radio frequency, inductive communication, network ports, USB and serial ports as generally having this ability. The reasoning is that each of these interfaces can create a path from the internet to the device, often through a phone, laptop, gateway or hospital network.
This is why a Bluetooth device that pairs with a phone app is usually in scope. So is a device that only connects to a laptop by USB during servicing. For a worked example, see does Section 524B apply to my connected auto-injector.
How can you check whether your device is a cyber device?
You can run a fast first check with three questions. If the answer to the first two is yes, assume the device is a cyber device and plan accordingly.
- Does the device contain software, firmware or programmable logic that you validated, installed or authorized?
- Does it have any electronic interface, including Bluetooth, Wi-Fi, cellular, USB, Ethernet, serial, NFC or other radio?
- Could that software or interface be attacked, for example through pairing, updates or data exchange?
If you are unsure, document your reasoning. Reviewers respond better to a clear applicability rationale than to silence. Our Section 524B requirements guide covers the full set of obligations.
See also: Does FDA 524B Apply to Auto-Injectors?, Ransomware and Medical Devices: What the FDA Expects, and SBOM for SaMD and Cloud Components: FDA Guide.
Not sure where your device lands? We can review your design and give you a written applicability rationale. Ask our team.
What changes if your device is a cyber device?
If your device is a cyber device, your premarket submission must meet Section 524B and the FDA's 2026 guidance. That means more evidence and earlier planning.
- SBOM. A software bill of materials covering commercial, open-source and off-the-shelf components.
- Postmarket plan. A plan to monitor, identify and address vulnerabilities, including coordinated vulnerability disclosure.
- Secure design evidence. Threat model, security risk assessment, architecture views and security testing, including penetration testing.
- Updates and patches. Processes to deliver updates and patches on a reasonable schedule, and sooner for critical issues.
- Labeling. Cybersecurity information customers need to use and maintain the device safely.
Devices already on the market before March 29, 2023 are not retroactively covered, but any new submission for a change to that device is. See does Section 524B apply to legacy devices.
How Blue Goat Cyber Approaches This
We start with applicability. Before any deliverable is built, we map every interface on the device, from Bluetooth pairing to service ports, and document whether and how each one creates a path to the internet. That rationale goes into the submission so the reviewer sees the reasoning, not just the conclusion.
If the device is a cyber device, our US-based engineers build the full premarket package: SBOM, threat model, security risk assessment, architecture views and mostly manual, expert-led penetration testing with AI-driven tools in support. We have supported more than 275 device submissions across implantables, wearables, imaging, diagnostics and SaMD.
See our FDA premarket cybersecurity services for how an engagement runs. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
Frequently Asked Questions
What is a cyber device under FDA Section 524B?
A cyber device is a medical device that includes software validated, installed or authorized by the sponsor, has the ability to connect to the internet, and has characteristics that could be vulnerable to cybersecurity threats. All three parts must apply. Because the FDA reads internet connection broadly, most devices with software and any electronic interface meet the definition.
Is a Bluetooth-only device a cyber device?
Usually, yes. The FDA treats Bluetooth as an interface that gives a device the ability to connect to the internet, because a paired phone or gateway can create a path from the internet to the device. A Bluetooth device with sponsor firmware will almost always meet the definition and should plan for the full Section 524B evidence set.
My device never connects to the internet. Is it out of scope?
Not necessarily, and this is a common misconception. The test is the ability to connect, not whether the device is online in normal use. A USB service port, serial interface or network jack can be enough. Only devices with no software, or no electronic interface at all, are clearly out of scope.
Does Section 524B apply to software as a medical device?
Yes, when the software meets the three-part test. Most SaMD runs on phones, computers or cloud platforms that connect to the internet, so it usually qualifies. The SBOM and threat model should cover the software itself and the platforms and cloud services it depends on.
When did the cyber device definition take effect?
Section 524B applies to premarket submissions for cyber devices sent on or after March 29, 2023. The FDA began refusing to accept submissions that lacked the required cybersecurity content from October 1, 2023. The February 3, 2026 final guidance is the current explanation of what the FDA expects.
CTA
If you are not sure whether your device is a cyber device, we can tell you. Send us a short description of the device and its interfaces, and we will explain where it lands under Section 524B and what that means for your submission. Ask for an applicability review.
About the author. Christian Espinosa, MBA, is the founder and CEO of Blue Goat Cyber and a graduate of the US Air Force Academy. He leads a team focused only on medical device cybersecurity and has advised device makers on Section 524B applicability since the law took effect. Read more about Christian.
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
