We use cookies and similar technologies to measure how our site and advertising perform. You can accept or decline. Declining keeps the site fully usable and only turns off measurement. See our privacy policy.

    Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    ⌘K
    Recap

    Medical Device Cybersecurity News: Recent Highlights, Week of Monday, September 7, 2026

    The recent conclusion of Extended Life Support for RHEL 7 marks a critical shift for manufacturers maintaining legacy device fleets.

    Hero image for Medical Device Cybersecurity News: Recent Highlights, Week of Monday, September 7, 2026
    Week of September 7, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    3 min read682 words

    Key Takeaways

    • Extended Life Support for RHEL 7 officially ended on June 30, 2026.
    • Security errata are no longer issued for RHEL 7, increasing vulnerability risks.
    • The FDA expects specific documentation in postmarket files for devices using retired operating systems.
    • Manufacturers must choose between active migration or formal compensating controls.
    • Legacy device inventory is now a primary focus for regulatory audit readiness.
    Direct Answer

    The recent conclusion of Extended Life Support for RHEL 7 marks a critical shift for manufacturers maintaining legacy device fleets. The FDA now expects formal documentation of migration plans or compensating controls for any devices still relying on this operating system.

    While the last few days have been relatively quiet for new regulatory filings, the past 90 days have seen significant shifts in how the industry manages legacy infrastructure and postmarket security. Manufacturers are currently transitioning away from long-standing support cycles while bracing for more stringent review of their postmarket maintenance files.

    In this brief

    Why This Matters

    For device manufacturers, the end of a major operating system support cycle is not just a technical hurdle but a regulatory compliance risk. Failure to document how a device remains secure after its underlying OS stops receiving patches can lead to delays in subsequent submissions or findings during postmarket inspections.

    Legacy Fleet Management: RHEL 7 ELS Conclusion

    High

    The period for Red Hat Enterprise Linux 7 (RHEL 7) Extended Life Support reached its final end on June 30, 2026.

    ## What to do this week * Identify every device model in your current catalog or service fleet that utilizes RHEL 7. * Draft a formal internal memo outlining the specific compensating controls used to protect these devices in the absence of OS security patches. * Schedule a review meeting with your regulatory affairs team to ensure the postmarket file for each affected device is updated to reflect the RHEL 7 ELS status.

    How Blue Goat Cyber Helps

    Blue Goat Cyber provides specialized guidance to help manufacturers navigate the complexities of legacy system security and FDA expectations. Our team, led by experts like Christian Espinosa, assists in developing the necessary documentation and technical controls to maintain compliance throughout the device lifecycle. You can learn more about our approach at Blue Goat Cyber.

    FAQ

    Get the next issue

    Subscribe to stay updated on the latest regulatory changes at Goat's Weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.