On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- RHEL 7 Extended Life Support officially concluded on June 30, 2026.
- The FDA expects manufacturers to provide specific documentation for devices still utilizing RHEL 7.
- Postmarket files must now include either a migration plan or a formal justification for compensating controls.
- Absence of security errata for legacy systems necessitates a higher frequency of manual vulnerability monitoring.
- Regulatory reviews are increasingly focusing on the software bill of materials (SBOM) accuracy for older devices.
The primary focus for manufacturers this period is managing the end of support for legacy operating systems in their device fleets. With the expiration of Red Hat Enterprise Linux (RHEL) 7 Extended Life Support, organizations must prioritize documenting compensating controls or migration paths to maintain regulatory compliance.
While the summer months typically bring a slower pace of new regulatory releases, the last 90 days have highlighted critical maintenance milestones for medical device manufacturers. The shift away from legacy software support remains a dominant theme, requiring security leads to verify that their postmarket files accurately reflect the current risk posture of their deployed devices.
As we look across the recent regulatory landscape, the emphasis has shifted from new guidance to the execution of existing lifecycle requirements. Manufacturers are expected to demonstrate active monitoring and mitigation strategies for vulnerabilities that emerge as third party software reaches its final end of life stages.
In this brief
- RHEL 7 Extended Life Support Conclusion
- Managing Legacy Software Risks
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For device manufacturers, the end of support for a foundational operating system creates a direct compliance gap. The FDA requires active management of cybersecurity risks, and relying on an unsupported OS without documented mitigations is viewed as a failure of postmarket surveillance obligations.
RHEL 7 Extended Life Support Conclusion
Red Hat Enterprise Linux 7 Extended Life Support (ELS) reached its final end of support date on June 30, 2026.
Managing Legacy Software Risks
Managing legacy software is not just a technical hurdle but a regulatory necessity.
How Blue Goat Cyber Helps
Blue Goat Cyber assists medical device manufacturers in navigating complex regulatory requirements and securing their technology stacks. Our team provides specialized services including penetration testing and risk assessments to ensure your devices meet current security standards. For more information on our approach, visit our services page.
FAQ
Get the next issue
To stay updated on the latest medical device security requirements, subscribe to Goat's Weekly.
