
On this page
Published:
Key Takeaways
- Start with the pathway the device was cleared or approved under: 510(k) and PMA have different change rules.
- For 510(k) devices, the question is whether the change could significantly affect safety or effectiveness (21 CFR 807.81(a)(3)).
- A letter to file still needs real evidence: an updated threat model, SBOM and testing for the changed parts.
- A Special 510(k) fits changes to your own cleared device when the supporting testing can be reviewed in summary form.
- For PMA devices, 21 CFR 814.39 requires a supplement before changes that affect safety or effectiveness, and the PMA holder decides first.
- When the call is close, a Pre-Sub with the FDA is cheaper than guessing wrong.
Does a cybersecurity change to my medical device need a new FDA submission?
A cybersecurity change to a 510(k) device needs a new 510(k) only if it could significantly affect safety or effectiveness; otherwise it is documented in a letter to file. A Special 510(k) often fits changes to your own device. For a PMA device, 21 CFR 814.39 requires a PMA supplement before any change that affects safety or effectiveness. In every case, the threat model, SBOM and testing must be updated and kept on file.
Clients ask us this question more than almost any other after clearance: "We changed the firmware, the cloud service or the encryption. Do we need to file something?" This page is the short version. Each step links to a full post that covers the details.
Last reviewed: October 2026 against 21 CFR 807.81(a)(3), 21 CFR 814.39, the FDA's guidance "Deciding When to Submit a 510(k) for a Change to an Existing Device," the FDA's Special 510(k) Program guidance and the FDA's February 3, 2026 final premarket cybersecurity guidance.
Why this matters
Security changes happen constantly after launch: patched libraries, new cloud services, updated encryption, added connectivity. Each one is also a device change. Filing too little risks an inspection finding or a forced submission later. Filing too much costs months. For devices that meet the Section 524B definition of a cyber device, a new submission also has to carry the full cybersecurity package the FDA expects under the February 2026 guidance.
The decision at a glance
| Your device | Change could affect safety or effectiveness? | Usual path | Full post |
|---|---|---|---|
| 510(k) cleared | No | Letter to file, kept in your quality system | Letter to File vs New 510(k) |
| 510(k) cleared | Yes, change to your own device, testing can be summarized | Special 510(k) | Special vs Traditional 510(k) |
| 510(k) cleared | Yes, new intended use, new technology or complex testing | Traditional 510(k) | Special vs Traditional 510(k) |
| PMA approved | Yes | PMA supplement (180-day, Real-Time or Special, depending on the change) | PMA Supplement Cybersecurity Changes |
| PMA approved | No | Periodic (annual) report, if the approval order allows | PMA Supplement Cybersecurity Changes |
Step 1: How did the device reach the market?
Look at the marketing authorization, not the device class. A Class II device cleared through 510(k) follows the 510(k) change rules. A Class III device approved through PMA follows 21 CFR 814.39. If you are planning repeated changes, such as regular model updates, a Predetermined Change Control Plan can authorize them in advance. Adding software or connectivity to a Class I device can also remove its 510(k) exemption; see Does Device Class Decide FDA Cybersecurity Scope?.
Step 2 (510(k) devices): Could the change significantly affect safety or effectiveness?
Under 21 CFR 807.81(a)(3), a new 510(k) is required when a change could significantly affect safety or effectiveness, or when the intended use changes in a major way. The FDA's change guidance walks through that question. For cybersecurity, routine patches that do not change the attack surface or risk controls usually stay in a letter to file. New interfaces, new connectivity, changes to authentication or encryption, and changes to risk controls tied to patient harm often do not.
A letter to file is not a shortcut. It is a record that you assessed the change, and an inspector can ask for it. Read Letter to File vs New 510(k) for the examples and what to put in the file.
Step 3 (510(k) devices): Special or Traditional?
If a new 510(k) is needed, the Special 510(k) Program is often faster. It fits changes to your own legally marketed device where the testing methods are well established and the results can be reviewed in summary or risk analysis form. A new intended use, or testing the FDA would need to review in full, points to a Traditional 510(k). See Special vs Traditional 510(k) for the decision tree.
Step 4 (PMA devices): What 21 CFR 814.39 says
A PMA holder must submit a PMA supplement for FDA review and approval before making a change that affects safety or effectiveness. The regulation says the burden of deciding this falls primarily on the PMA holder. Changes in performance or design specifications, circuits, components or principles of operation are listed examples. Some changes can go through other routes the regulation and the FDA allow, such as a 30-day notice for certain manufacturing changes or a periodic report when the approval order permits it. PMA Supplement Cybersecurity Changes compares the five paths.
Step 5: Not sure? Ask the FDA
A Pre-Submission (Q-Sub) lets you describe the change and your proposed path and get the FDA's feedback before you commit. For borderline security changes, that is usually cheaper than a wrong call.
What every path needs from cybersecurity
Whatever you file, or don't, the evidence is the same kind of work, scaled to the change:
- An updated threat model for the changed parts
- A regenerated SBOM and a review of new known vulnerabilities
- Penetration testing of the changed attack surface
- Updated risk and traceability records so the decision is defensible at inspection
How Blue Goat Cyber approaches this
We start with a scoping call about the change itself: what moved, what it connects to and which risk controls it touches. From there we update the threat model, SBOM and testing for the changed parts and write the cybersecurity documentation for whichever path you choose, whether that is a letter to file, a 510(k) or a PMA supplement. Your regulatory team owns the filing decision; we make sure the security evidence behind it holds up. Our team has supported 275+ devices.
FAQ
Does a software patch need a new 510(k)?
Usually not, if it fixes a vulnerability without changing the attack surface, intended use or risk controls. Document the assessment and evidence in a letter to file. A patch that adds features or changes how the device communicates may need a new 510(k).
What is a letter to file?
It is an internal record that you assessed a change to a 510(k) device and concluded a new submission was not needed. It stays in your quality system, and the FDA can review it during an inspection.
When is a Special 510(k) the right choice?
When the change is to your own cleared device and the supporting testing can be reviewed in summary form. The FDA's goal for Special 510(k) reviews is 30 days, shorter than a Traditional 510(k).
Who decides whether a PMA change needs a supplement?
The PMA holder. 21 CFR 814.39 places the burden of that decision primarily on the manufacturer, so document your reasoning.
Can I avoid repeated filings for planned changes?
Possibly. A Predetermined Change Control Plan, authorized as part of a submission, can cover specific future changes so each one does not need its own filing.
Planning a change to a cleared or approved device?
Book a discovery session and we will scope the cybersecurity work for your change.




