Three inputs - risk class, connectivity, PHI sensitivity - return the monitoring, patching, and reporting cadence FDA postmarket reviewers expect for your device.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Device risk class
Connectivity
PHI / sensitive data on device
What you'll see after you submit
Common misconceptions
Myth: Annual pen testing is fine for any device.
Reality: FDA expects pen test cadence to scale with risk and connectivity. Internet-connected Class II/III with PHI typically warrants every release plus a yearly external test - not just annual.
Myth: FDA postmarket timelines only apply to recalls.
Reality: Uncontrolled cybersecurity risk (CVSS-style or otherwise) starts the 30-day customer communication and 60-day fix timelines, and a 21 CFR 806 report is due within 10 working days unless those timelines are met with ISAO membership. The threshold is impact, not the word 'recall.'
Myth: We monitor CVEs against our SBOM once a quarter.
Reality: Reviewer expectation is continuous monitoring with documented triage SLAs. Quarterly cadence is a deficiency for any internet-connected device.
Myth: Patch validation is the same for all devices.
Reality: Closed-loop or life-supporting devices need bench + simulated-clinical validation per patch; lower-risk SaMD can use staged rollout with telemetry. The cadence tool tells you which lane you're in.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
RHEL 7 Extended Life Support phase ends - devices on RHEL 7 need a compensating-controls memo
CISA adds use-after-free in Linux kernel netfilter to KEV (CVE-2026-0511)
BLE pairing bypass in widely embedded Bluetooth stack added to KEV
AI-letter analysis - 62% of FDA cyber deficiencies cite a missing or stale CVD URL
Monitoring, CVD, patch validation, and FDA reporting workflows.
Read Postmarket cybersecurity servicesThe plan template reviewers expect to see.
Read Postmarket readiness planContinuous CVE/KEV/VEX monitoring against your SBOM.
Read SBOM servicesPCCP, threat model starter, CVD policy generator.
Read More tools