Most conversations about Section 524B start with new products. A connected device in development, a first submission, a team deciding how much cybersecurity documentation to build. That framing is where the attention has gone since the requirement became effective in March 2023.
It is also why the more expensive version of the problem tends to be discovered late, and by companies who were not worried about 524B at all.
The law attaches to the submission, not to the device
Section 524B(a) applies to a person who submits an application or submission for a device meeting the definition of a cyber device. The obligation is triggered by the act of filing, not by the age of the product.
FDA states the consequence directly:
“If a cyber device was previously authorized, and the manufacturer is making a change to the device that requires premarket review by the agency, the law applies to the new premarket submission.”
And on which pathways count, the agency is equally explicit. The requirement reaches 510(k), PMA, PDP, De Novo and HDE submissions — and it “includes Special and Abbreviated 510(k) applications as well as PMA and HDE supplements.”
The Special 510(k) is the detail worth pausing on. That pathway exists precisely so a manufacturer can push through a well-understood change to its own device quickly, on a design-control basis. It is the lightweight route. It is now also a route into 524B.
Where the line falls
There is a cutoff, and it is clean: the cybersecurity requirements do not apply to an application or submission filed with FDA before 29 March 2023. If your device was cleared before then and you have not filed since, nothing has changed for you yet.
“Yet” is doing the work in that sentence. The obligation is not waiting for a deadline. It is waiting for your next submission.
The graduated part — which is genuinely reasonable
FDA does not treat every modification the same way. Applying its least burdensome principles, the guidance says the information it recommends “will generally differ based on the type of change and whether such change impacts the cybersecurity of the device,” and it splits modifications into two groups.
Changes that may impact cybersecurity — the guidance names changes to authentication or encryption algorithms, new connectivity features, and changes to the software update process or mechanism. These carry the full documentation set.
Changes unlikely to impact cybersecurity — the guidance names changes in materials, sterilization method changes, and a change to an algorithm without a change to architecture, software structure or connectivity.
If you stopped reading there, you would conclude that a materials change is not a cybersecurity event. That is where the surprise lives.
The floor that applies even to the changes that do not matter
For changes in the second group — the ones unlikely to impact cybersecurity at all — the guidance still says this:
“If not previously provided, manufacturers must provide a plan as described in section 524B(b)(1) of the FD&C Act… If a plan … was previously provided, the manufacturer should provide a reference to the prior submission and a summary of any changes to the plan.”
Read the conditional. The relief is for manufacturers who already provided the plan. Those manufacturers reference the earlier submission and summarise what changed — a genuinely light obligation.
Manufacturers who never provided it get no such relief, because the condition does not apply to them. And a device cleared before March 2023 has, by definition, never provided it.
So the sentence resolves to something that sounds wrong the first time you read it: a sterilization method change on a legacy connected device can require you to file a postmarket cybersecurity vulnerability plan. Not because sterilization has anything to do with cybersecurity. Because the plan was owed and never delivered, and the modification is the moment the account comes due.
Why that is more expensive than it sounds
The instinct at this point is to treat the plan as a writing task. Two pages, submitted with the supplement, move on.
Look at what 524B(b)(1) actually requires the plan to describe: a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures.
That is not a description of a document. It is a description of a capability. Monitoring implies somebody is watching a vulnerability feed against your bill of materials. Addressing in a reasonable time implies a patch path exists for a device already in the field. Coordinated vulnerability disclosure implies a published intake route and a process for handling what arrives through it.
For a device designed before any of this was required, none of those things exist as a matter of course. The plan cannot be written from an existing record, because there is no existing record — which means it has to be built. That work is entirely doable. It is not doable in the two weeks between deciding to change a supplier and filing the supplement.
Three questions worth answering before the next filing
- Which of your marketed devices meet the cyber device definition? Section 524B(c) sets three conditions and they are cumulative: software validated, installed or authorized by the sponsor; the ability to connect to the internet; and technological characteristics that could be vulnerable to cybersecurity threats. Note that the second condition is capability, not use. A port nobody connects and a radio disabled in the field still count.
- Has any submission for those devices ever included a 524B(b)(1) plan? If the answer is no, you know exactly what your next modification will cost you, and you know it before the clock starts.
- What is the next change you are likely to file? Supplier changes, sterilization changes and materials changes are ordinary lifecycle events. They are also, now, the trigger.
None of this is an argument for filing less. It is an argument for knowing which of your legacy devices is one supplement away from owing a capability you have not built.