You are writing a threat model, or a cybersecurity management plan, or the narrative section of a 510(k). At some point you need a line that says which FDA guidance you built against.
That line is doing more work than it looks like.
Three documents, two supersessions, one title change
FDA's premarket cybersecurity guidance has been issued three times in three years:
- 27 September 2023 — Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.
- 27 June 2025 — same title, superseding the 2023 version, adding Section VII on Section 524B.
- 3 February 2026 — Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, superseding June 2025.
The third one changed the title. Not dramatically — one word — but the word is the regulatory anchor. QSR became QMSR on 2 February 2026 when the revised 21 CFR Part 820 took effect, and the guidance was reissued the following day to match.
Most of the substance carried over. The citation did not.
A small illustration, and it is not a complaint
FDA maintains a frequently asked questions page on medical device cybersecurity. It is a good page: plain language, and it answers questions the guidance itself does not address directly, including how Section 524B applies to previously authorized devices.
Checked on 12 August 2026, that page names “Quality System Considerations and Content of Premarket Submissions” seven times. It does not name “Quality Management System Considerations…” at all, and it does not mention 3 February 2026 or 27 June 2025.
This is worth being careful about. The FAQ's substance is not necessarily wrong — most of what it explains was unchanged by the reissue. What is stale is the identification of the document it points you to.
And it is not really a criticism. Any organisation that publishes a guidance document, a FAQ, a webinar recording, a transcript, a landing page and a docket entry is maintaining six surfaces that update on six different schedules. That is normal. It is also exactly why the responsibility to cite precisely sits with you rather than with the page you read.
Why it lands on your side
Two ways, and the second is worse.
The visible one. A submission that cites a guidance by a title that has been superseded twice reads as stale, regardless of whether the underlying analysis is sound. It invites a reviewer to wonder what else was built against an old version. That is an unforced impression to give.
The quiet one. If you built your documentation from a summary — a FAQ, a webinar deck, a consultant's slide, an article like this one — you inherited whatever version that summary was written against, including the parts the author did not notice had changed. The summary is not the obligation. The document is.
Webinar material deserves a specific mention here, because it circulates for years. A CDRH webinar recorded to explain a 2023 final guidance is an accurate explanation of the 2023 final guidance forever. Nothing about it announces that it has been overtaken.
The practice, which is small
- Cite title and issue date together. “FDA guidance on cybersecurity” is not a citation. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026, is.
- Anchor to the docket. This guidance lives under docket FDA-2021-D-1158. Docket numbers survive title changes and reissues; titles do not.
- Treat the guidance page as the version of record. The FDA guidance-document page carries the current PDF. FAQ pages, webinar recordings and summary articles are secondary and lag by design.
- When a guidance is reissued, re-read your own citations before you re-read the guidance. The diff in the document is usually small. The diff in what you have written about it can be a title, a date, a regulatory anchor, and a section number.
None of this makes anyone's documentation better on the merits. It removes a category of avoidable friction, which is a different and cheaper kind of win.