Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Topic hub

    Software as a Medical Device (SaMD) Cybersecurity

    SaMD - software that meets the medical-device definition without being embedded in hardware - is one of the fastest-growing FDA submission categories and one of the most cybersecurity-sensitive. Cloud backends, mobile apps, and standalone clinical software inherit all the FDA premarket requirements plus a much broader attack surface than embedded devices. This hub pulls together the services, guides, blog posts, and standards that explain what SaMD-grade cybersecurity looks like under the Feb 2026 guidance, IEC 62304, IEC 81001-5-1, and Section 524B.

    The short answer

    Software as a Medical Device is a cyber device whenever it has software and the ability to connect to the internet, which is nearly always. The cybersecurity package is the same as for hardware, with the emphasis shifted to the hosting environment: cloud architecture and tenancy, authentication and session management, API security, third-party and open-source dependency management, and update delivery. Reviewers expect the security architecture views to show the cloud and mobile components, not stop at the app boundary.

    Start here: Secure MedTech Product Design 14 resources in this hub · 5 in-depth guides · 4 FAQs

    Standards & guidance

    Defined entries from our MedTech Cybersecurity Standards Glossary.

    Topic FAQ

    Software as a Medical Device (SaMD) Cybersecurity - frequently asked questions

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.