On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- RHEL 7 Extended Life Support officially ended on June 30, 2026.
- The FDA expects documented migration plans for devices using unsupported operating systems.
- Compensating controls must be justified in postmarket files if updates are not feasible.
- Inventory management is the first step in addressing legacy OS vulnerabilities.
- Security errata are no longer issued for RHEL 7, increasing the risk of unpatched vulnerabilities.
The end of Extended Life Support for RHEL 7 marks a critical milestone for manufacturers maintaining legacy device fleets. Regulatory bodies now expect formal documentation regarding compensating controls or migration paths for any devices still utilizing this operating system.
While this week has been relatively quiet for new regulatory filings, the recent sunsetting of major legacy software support continues to impact postmarket compliance. Manufacturers must shift focus from active development to ensuring their legacy portfolios meet current cybersecurity expectations.
In this brief
- Legacy Fleet Management: The RHEL 7 ELS Cut-off
- Why This Matters
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For medical device manufacturers, the end of life for an operating system is not just a technical hurdle but a regulatory one. Failure to account for the lack of security patches in a legacy environment can lead to non-compliance during postmarket reviews and increase the attack surface of the healthcare provider's network.
Legacy Fleet Management: The RHEL 7 ELS Cut-off
Red Hat Enterprise Linux (RHEL) 7 reached the end of its Extended Life Support (ELS) phase on June 30, 2026.
How Blue Goat Cyber Helps
Blue Goat Cyber assists manufacturers in navigating complex regulatory requirements through specialized services. Our team, led by experts like Christian Espinosa, provides guidance on documenting compensating controls and performing risk assessments for legacy systems. You can learn more about our approach at our services page.
FAQ
Get the next issue
To stay updated on medical device cybersecurity trends, subscribe to Goat's Weekly.
