Working through FDA's medical device cybersecurity requirements without the legalese. Updated guidance, RTA prevention, QMSR transitions — written for regulatory affairs leads and founders who need clarity, not page-count.
FDA's premarket cybersecurity guidance has been superseded twice since September 2023. Its own FAQ page, checked in August 2026, still names the older title — a useful illustration of why your documentation should cite a dated document rather than a page about it.
Read article →Four times, Section 524B says "the device and related systems." FDA's guidance fills that phrase with something most small manufacturers do not have in their design file: the update server they host in a cloud account — and the patch cadence obligations follow it there.
Read article →The statute contains an off-ramp: FDA may identify devices exempt from the cybersecurity requirements, and must publish the list in the Federal Register. As of August 2026 there is no public record that any list has been published — which means there is nothing to check your device against.
Read article →A CE-marked device arrives at FDA with a complete technical file and no software bill of materials. Nothing was done wrong — the European framework never asked for one. MDCG 2019-16 names it exactly once in 46 pages, and the gap that opens is not where most people expect it.
Read article →The regulation gave the Commission a deadline of 11 December 2025 for two of its own instruments. One of them belongs to Article 14 — the article whose reporting obligations start applying on 11 September 2026. As of August 2026, both are still drafts, and one member state filled the gap on its own.
Read article →Section 524B attaches to the submission, not to the device. A device cleared long before the law existed comes into scope the first time you file a change — including a Special 510(k) or a PMA supplement. And even changes unlikely to affect cybersecurity still require the postmarket plan if it was never provided.
Read article →On 11 September 2026 the Cyber Resilience Act's reporting obligations start applying. Medical devices are excluded from the regulation, and that exclusion is real. It is also narrower than most medtech companies assume — because it covers products, not companies.
Read article →A researcher emails your team about a vulnerability in a device you already sell. Half the room wants to ship a quiet patch; the other half wants to call a lawyer. The question that actually decides what you owe the FDA is narrower than either instinct — and it has a name.
Read article →On February 2, 2026, the FDA replaced the 30-year-old Quality System Regulation with the new Quality Management System Regulation, incorporating ISO 13485:2016 by reference. The cybersecurity implications aren't obvious at first glance — but they're real, and they're already affecting how submissions get reviewed.
Read article →Since October 2023, FDA can refuse to accept a 510(k) on the cybersecurity documentation alone, before substantive review even begins. Most of those rejections are preventable. Here's what an RTA actually costs — and the five evidence patterns behind almost every one.
Read article →On February 3, 2026, the FDA quietly reissued its medical device cybersecurity guidance — 8 months after publishing the previous "final" version. Most manufacturers missed it. Here's what changed, what stayed the same, and what every cyber device maker needs to do about it.
Read article →Skip the reading. Take Omakyn's free 5-minute cybersecurity gap assessment and get a prioritized list of what's missing in your current documentation. No sales call. No signup.
Start free assessment →