Medical Devices & FDA Requirements: What It Means to Stay Ahead of Cyberattacks

Medical Devices & FDA Requirements: What It Means to Stay Ahead of Cyberattacks

For decades, safety conversations in the medical device industry mostly focused on physical risk — would a device malfunction, deliver an incorrect dose, or fail at a critical moment? Those concerns are still relevant, but cybersecurity is increasingly part of the critical discussions. The FDA has issued cybersecurity guidance for medical devices, and unprepared manufacturers risk regulatory and patient safety consequences. 

As devices have become networked, connecting to hospital systems, cloud platforms, and patient monitoring apps, they’ve also become targets. Questions have extended beyond whether a connected device could be attacked, to include whether manufacturers have done what is required to help prevent it. For organizations navigating this landscape, the IEEE Medical Device Cybersecurity Certification Program offers a structured, standards-based path to demonstrating that readiness — one grounded in internationally recognized technical criteria rather than self-assessment alone.

How the FDA Changed Its Approach to Device Security

A regulatory turning point came with the Consolidated Appropriations Act of 2023, which amended Section 524B of the Federal Food, Drug, and Cosmetic Act. Under this legislation, manufacturers submitting premarket applications for “cyber devices” — broadly defined as any device that connects to the internet, a network, or another device — must now meet specific cybersecurity requirements as a condition of FDA clearance or approval. The FDA published its final guidance on these requirements in September 2023, and the agency has made clear it will refuse to accept submissions that do not address cybersecurity adequately.

This was a meaningful departure from prior guidance, which treated cybersecurity as a best practice rather than a legal obligation. The FDA had issued voluntary guidance documents going back to 2014, but compliance was inconsistent across the industry. The 2023 legislation gave the agency real enforcement authority, and manufacturers took notice. The shift also reflected a broader recognition within the federal government that healthcare infrastructure is a high-value target. The Cybersecurity and Infrastructure Security Agency (CISA) designates healthcare and public health as one of 16 critical infrastructure sectors, underscoring why device-level security has become a national priority.

The FDA’s requirements under Section 524B include submitting a software bill of materials (SBOM), establishing a plan to monitor and address post-market vulnerabilities, and providing reasonable assurance that the device and related systems are protected against unauthorized access. These are not one-time compliance tasks. They demand ongoing processes, documentation, and organizational commitment that extend well beyond the initial product launch.

What "Secured Against Cyberattacks" Actually Means

The phrase appears straightforward, but its implementation requires sustained technical and organizational rigor. Being secured against cyberattacks means demonstrating — to the FDA, to hospital procurement teams, and to the public — that a device has been designed with security as a foundational principle, not as an afterthought.

In practice, this involves several interconnected disciplines that must be addressed at different stages of the product lifecycle. Threat modeling must happen early in the design process, identifying how an attacker might interact with the device and what the consequences of a successful attack would be. Secure coding practices must be applied throughout development. Authentication and encryption must be implemented appropriately for the device’s use case and risk profile, and the FDA expects manufacturers to understand and document those decisions clearly.

Security responsibilities do not end at product launch. Even years after a device has shipped, any newly-discovered vulnerability remains the manufacturer’s responsibility. The FDA expects manufacturers to have processes in place to detect those vulnerabilities, assess their severity, and push updates or patches in a timely manner. For many organizations, building that infrastructure is as challenging as the initial design work. It requires dedicated personnel, monitoring systems, and a coordinated disclosure process for when vulnerabilities are reported by external researchers and for managing timely remediation and transparent communication with affected stakeholders.

The scale of the threat environment makes this work urgent. According to the IBM Cost of a Data Breach Report 2025, the healthcare industry has reported the highest average data breach cost of any sector for 14 consecutive years, reaching $9.77 million per incident in 2024. Medical devices that are compromised don’t just expose patient data — they can become entry points into broader hospital networks, amplifying the damage far beyond the device itself.

The Role of Standards in Meeting FDA Expectations

The FDA doesn’t prescribe a single technical standard that manufacturers must follow. Instead, it references a “recognized standard” framework and expects manufacturers to demonstrate alignment with established cybersecurity principles. This is where global standards — including those developed by IEEE and other bodies — become essential tools for manufacturers trying to build a defensible compliance posture.

Standards help provide a common language for security requirements, a benchmark against which designs can be evaluated, and a documented record of due diligence. When a manufacturer can point to specific standards conformance in a premarket submission, it strengthens the regulatory case considerably. It also signals to hospital systems and healthcare networks that the device has been evaluated against criteria that go beyond the manufacturer’s own internal testing — criteria developed through a rigorous, consensus-based process involving engineers, regulators, and security researchers from around the world.

The connection between FDA expectations and established standards isn’t coincidental. Regulatory agencies participate in standards development, helping the resulting standards reflect both technical rigor and real-world regulatory context. For manufacturers, working within a recognized standards framework from the beginning of a project is more efficient than retrofitting compliance after the fact, and contributes to credibility.

As the threat landscape evolves and new attack techniques emerge, standards are updated to reflect current best practices. Manufacturers who build ongoing standards engagement into their development processes are better positioned to stay ahead of both regulatory changes and emerging vulnerabilities.

How Certification Supports Compliance and Market Confidence

Regulatory compliance and market differentiation are often treated as separate goals, however in medical device cybersecurity, they reinforce each other in important ways. A device that meets FDA cybersecurity requirements is also a device that hospital procurement teams can justify purchasing. A device that carries third-party certification is one that stands out in an increasingly crowded and scrutinized market, particularly as healthcare systems face growing pressure from their own insurers and regulators to demonstrate supply chain security.

The IEEE 2621 Product Certification Program provides independent validation that a connected medical device meets defined cybersecurity criteria, and that independence matters more than it might initially appear. Self-attestation has its place in the regulatory process, but when a hospital system is evaluating devices for a large-scale deployment, third-party evidence carries significantly more weight. It reduces the due diligence burden on the buyer, provides a clear basis for comparison across competing products, and shifts accountability appropriately to the manufacturer.

The financial case for proactive certification is also compelling. A cybersecurity incident involving a medical device doesn’t just create immediate financial exposure — it can trigger FDA enforcement action, product recalls, civil litigation, and lasting reputational damage that affects future sales cycles. The cost of a serious incident almost always exceeds the cost of the security investment that could have prevented it. Certification is, in part, a risk management strategy, and one that increasingly sophisticated hospital procurement processes are beginning to require rather than to simply prefer.

Preparing for a Regulatory Environment That Will Only Intensify

The FDA’s current cybersecurity requirements are not the endpoint of this regulatory evolution, they’re a foundation. The agency has signaled its intent to continue strengthening its oversight of connected medical devices, and international regulatory bodies are moving in the same direction. The European Union’s Medical Device Regulation (MDR) and the forthcoming EU Cyber Resilience Act both impose cybersecurity obligations on device manufacturers operating in European markets, and the trend toward harmonized international requirements is accelerating.

Manufacturers who treat today’s FDA requirements as the ceiling of their cybersecurity obligations may struggle as standards continue to rise. Those who treat them as a foundation for building durable security programs will be better positioned to adapt. That requires investing in training, engaging with the standards community, and establishing post-market surveillance infrastructure capable of responding to emerging threats.

It also means thinking carefully about how cybersecurity is communicated to customers. Hospital procurement teams are becoming more sophisticated in their security evaluations, and the ability to clearly articulate a device’s security posture, in terms that align with recognized standards and regulatory expectations, is increasingly a competitive differentiator. Manufacturers who can tell a coherent, evidence-based security story will have an advantage over those who can only offer assurances.

Looking Ahead

The FDA’s requirement that medical devices provide a Secure Product Development Framework (SPDF) against cyberattacks represents a permanent shift in how the industry operates. Manufacturers who treat these requirements as a compliance hurdle to clear once will find themselves unprepared for the ongoing obligations that follow — vulnerability monitoring, patch management, and evolving regulatory expectations as the threat landscape changes.

The organizations that will fare best are those that build cybersecurity into their culture and processes from the ground up, not just into their documentation. That means adopting recognized standards, seeking independent validation of their security posture, and engaging with the broader cybersecurity community as a long-term practice rather than a project with a defined end date.

If your organization is working to meet FDA cybersecurity requirements and demonstrate credible, standards-based security to regulators and customers alike, the IEEE Medical Device Cybersecurity Certification Program is designed to support exactly that work.

Share this Article