Omakyn Insights

Plain-English notes on FDA cybersecurity compliance.

Working through FDA's medical device cybersecurity requirements without the legalese. Updated guidance, RTA prevention, QMSR transitions — written for regulatory affairs leads and founders who need clarity, not page-count.

Cite the Guidance, Not the Page About the Guidance

FDA's premarket cybersecurity guidance has been superseded twice since September 2023. Its own FAQ page, checked in August 2026, still names the older title — a useful illustration of why your documentation should cite a dated document rather than a page about it.

Read article →

Section 524B Reaches Your Update Server

Four times, Section 524B says "the device and related systems." FDA's guidance fills that phrase with something most small manufacturers do not have in their design file: the update server they host in a cloud account — and the patch cadence obligations follow it there.

Read article →

Section 524B Has an Exemption Clause. There Is No List.

The statute contains an off-ramp: FDA may identify devices exempt from the cybersecurity requirements, and must publish the list in the Federal Register. As of August 2026 there is no public record that any list has been published — which means there is nothing to check your device against.

Read article →

Nothing in Your MDR File Required an SBOM. Section 524B Does.

A CE-marked device arrives at FDA with a complete technical file and no software bill of materials. Nothing was done wrong — the European framework never asked for one. MDCG 2019-16 names it exactly once in 46 pages, and the gap that opens is not where most people expect it.

Read article →

The Cyber Resilience Act Is Behind Schedule. Your Reporting Date Is Not.

The regulation gave the Commission a deadline of 11 December 2025 for two of its own instruments. One of them belongs to Article 14 — the article whose reporting obligations start applying on 11 September 2026. As of August 2026, both are still drafts, and one member state filled the gap on its own.

Read article →

Section 524B Reaches the Device You Cleared in 2019 — Through the Change You File Next

Section 524B attaches to the submission, not to the device. A device cleared long before the law existed comes into scope the first time you file a change — including a Special 510(k) or a PMA supplement. And even changes unlikely to affect cybersecurity still require the postmarket plan if it was never provided.

Read article →

The EU Cyber Resilience Act Does Not Apply to Your Device. It May Still Apply to You.

On 11 September 2026 the Cyber Resilience Act's reporting obligations start applying. Medical devices are excluded from the regulation, and that exclusion is real. It is also narrower than most medtech companies assume — because it covers products, not companies.

Read article →

Controlled vs Uncontrolled Risk: When a Device Vulnerability Must Be Reported to FDA

A researcher emails your team about a vulnerability in a device you already sell. Half the room wants to ship a quiet patch; the other half wants to call a lawyer. The question that actually decides what you owe the FDA is narrower than either instinct — and it has a name.

Read article →

QMSR Transition: What Changed on February 2, 2026 and What It Means for Cybersecurity Documentation

On February 2, 2026, the FDA replaced the 30-year-old Quality System Regulation with the new Quality Management System Regulation, incorporating ISO 13485:2016 by reference. The cybersecurity implications aren't obvious at first glance — but they're real, and they're already affecting how submissions get reviewed.

Read article →

FDA RTA on Cybersecurity: What It Costs and the 5 Patterns Behind It

Since October 2023, FDA can refuse to accept a 510(k) on the cybersecurity documentation alone, before substantive review even begins. Most of those rejections are preventable. Here's what an RTA actually costs — and the five evidence patterns behind almost every one.

Read article →

Understanding FDA's Feb 2026 Cybersecurity Guidance: A Plain-English Guide

On February 3, 2026, the FDA quietly reissued its medical device cybersecurity guidance — 8 months after publishing the previous "final" version. Most manufacturers missed it. Here's what changed, what stayed the same, and what every cyber device maker needs to do about it.

Read article →

Want your gaps before FDA does?

Skip the reading. Take Omakyn's free 5-minute cybersecurity gap assessment and get a prioritized list of what's missing in your current documentation. No sales call. No signup.

Start free assessment →