Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    What FDA Expects After Clearance: Postmarket Device Cybersecurity

    The document that governs medical device cybersecurity after your product is on the market is Postmarket Management of Cybersecurity in Medical Devices, final guidance issued in December 2016 under docket FDA-2015-D-5105, and its central holding is more permissive than most manufacturers assume: the majority of actions taken to address cybersecurity vulnerabilities, which the guidance calls "cybersecurity routine updates and patches", are "generally considered to be a type of device enhancement for which the FDA does not require advance notification or reporting under 21 CFR part 806". The exception is the small subset that addresses uncontrolled risk of patient harm, and there FDA sets out four conditions under which it does not intend to enforce part 806 reporting, two of which are clocks: customer communication within 30 days of learning of the vulnerability, and a validated, distributed fix within 60 days. The contrarian observation is about the document itself. The premarket cybersecurity guidance has been rewritten twice in eight months, while this one has not moved since 2016, which means the half of the lifecycle that lasts a decade is governed by the guidance nobody in the regulatory file has reread.

    Below: the controlled versus uncontrolled decision that drives everything, the four conditions read as a checklist, what the plan you already filed obliges you to do, the reporting paths that are not part 806, and where the limits of a nonbinding guidance genuinely sit.

    Key takeaways

    • Most security patches are device enhancements and are generally not required to be reported under 21 CFR part 806. Changes made solely to strengthen cybersecurity typically fall here, including changes addressing a vulnerability that could compromise protected health information.
    • The whole decision is controlled versus uncontrolled residual risk of patient harm, assessed on exploitability and the severity of harm if exploited.
    • For uncontrolled risk the enforcement discretion has four conditions: no known serious adverse events or deaths, customer communication and interim compensating controls within 30 days, a validated deployable fix within 60 days, and active membership of an information sharing and analysis organisation.
    • Enforcement discretion is not a legal exemption. FDA's guidance says in terms that guidance documents "do not establish legally enforceable responsibilities" and that "should" means recommended, not required. Part 806 itself still says what it says.
    • An unremediated uncontrolled risk is a compliance problem, not just a security one. The guidance states that such a device may be considered to have a reasonable probability of causing serious adverse health consequences or death, and the product may be considered in violation of the FD&C Act.

    Dateline. Written August 23, 2026. Every document cited here was retrieved and read on that date, including confirming that the 2016 postmarket guidance remains listed as final and current.

    Controlled and uncontrolled, which is the whole decision

    Everything here flows from one classification, and the guidance defines both sides of it plainly.

    Controlled risk "is present when there is sufficiently low (acceptable) residual risk of patient harm due to the vulnerability." Uncontrolled risk "is present when there is unacceptable residual risk of patient harm due to insufficient risk mitigations and compensating controls." In assessing which one you have, the guidance directs manufacturers to consider the exploitability of the vulnerability and the severity of patient harm if exploited.

    Two features of that definition are where security teams and regulatory teams talk past each other.

    It is about patient harm, not about data. The guidance says device changes made solely to address a vulnerability that, if exploited, could lead to compromise of protected health information "would typically be considered a cybersecurity routine update or patch". A privacy breach is serious under other law and is not by itself what moves a vulnerability into the uncontrolled category here; if you also handle PHI, that exposure is governed elsewhere, and our HIPAA practice and the health tech compliance checklist cover it.

    It is about residual risk, after your mitigations and compensating controls. A high-severity CVE in a component is not automatically an uncontrolled risk if the affected function is unreachable or already fenced. This is the most commercially valuable thing a competent threat model does: it turns alarming component vulnerabilities into documented controlled-risk determinations instead of fire drills.

    The four conditions, read as a checklist

    Where residual risk is uncontrolled, the guidance says manufacturers "must report these vulnerabilities to the FDA according to 21 CFR part 806, unless reported under 21 CFR parts 803 or 1004", then sets out when FDA does not intend to enforce that reporting. Four conditions, cumulative.

    One: no known serious adverse events or deaths associated with the vulnerability. If there are, you are in medical device reporting territory under part 803 and this discretion is not available.

    Two: within 30 days, communicate. As soon as possible but no later than 30 days after learning of the vulnerability, the manufacturer communicates with its customers and user community, identifies interim compensating controls, and develops a remediation plan with a documented timeline rationale. The guidance sets a minimum content list for that communication: a description of the vulnerability with an impact assessment on current understanding, a statement that efforts are underway to address the risk of patient harm as expeditiously as possible, a description of any compensating controls, and a statement that the manufacturer is working to fix it or has a defense-in-depth strategy, and will communicate about a fix in future.

    Three: within 60 days, fix. As soon as possible but no later than 60 days after learning of the vulnerability, the manufacturer fixes it, validates the change and distributes the deployable fix so residual risk is acceptable. The guidance allows a compensating control to serve as a long-term solution in some circumstances, provided the risk of patient harm is brought to an acceptable level, and adds that manufacturers should follow up with end users beyond the initial 60-day period as needed.

    Four: participate in an ISAO. The manufacturer actively participates as a member of an information sharing and analysis organisation that shares vulnerabilities and threats affecting medical devices, and provides the ISAO with any customer communications upon notifying customers.

    Notice what the clocks are anchored to: learning of the vulnerability, not disclosure, not exploitation, not the release of a patch. The date you learned is a fact you have to be able to evidence, which means your vulnerability intake and your monitoring of component advisories both need timestamps that survive scrutiny. A manufacturer that cannot say when it learned cannot demonstrate it met either clock.

    Notice too that condition three is not "ship a patch". It is fix, validate and distribute, with validation inside the 60 days, which is why verification capacity rather than engineering speed usually decides whether a manufacturer can hit it at all.

    What the plan you already filed obliges you to do

    If your device went through premarket review as a cyber device, you filed something under 21 U.S.C. 360n-2, whose subsection (b)(1) requires a plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time, including coordinated vulnerability disclosure and related procedures. FDA's cybersecurity FAQ points manufacturers to the postmarket guidance as the resource for that plan and for the patching obligations in 524B(b)(2).

    That plan is a commitment, and it is the one document here that binds you specifically rather than generally. If it promises a 30-day triage your organisation does not run, the gap is a difference between a representation to FDA and your quality system. The common version is a coordinated vulnerability disclosure policy that exists as a PDF with no intake address anyone monitors, no severity rubric, and no service level a researcher could hold you to.

    Reconciling the filed plan to actual operation costs nothing in engineering, and it is what an inspection or a deficiency letter tests.

    The reporting paths that are not part 806

    Part 806 covers corrections and removals, and it is one of several routes information travels. The others are easy to miss.

    Part 803, medical device reporting. The guidance is explicit that it does not cover reporting when a device has or may have caused or contributed to a death or serious injury, which is governed by section 519 of the FD&C Act and 21 CFR part 803. A cybersecurity event that produced patient harm is an MDR question first.

    PMA periodic reports, and annual reports generally. For PMA devices with periodic reporting requirements under 21 CFR 814.84, the guidance says newly acquired information about cybersecurity vulnerabilities and the changes made as routine updates and patches should appear in the periodic (annual) report, and it repeats the point for uncontrolled-risk remediation along with the compensating controls implemented. Remediation of devices with annual reporting requirements, such as class III devices, belongs in the annual report.

    And one that is not a reporting path but is the decision people forget: the guidance says manufacturers should evaluate device changes to assess whether a premarket submission is needed, such as a PMA supplement or a new 510(k). That evaluation belongs in your change control with its reasoning written down, not in someone's judgement at release time.

    The honest limits

    The first is the one vendors elide.

    This is guidance, and guidance is not law. The document says so on its own face: FDA's guidance documents "do not establish legally enforceable responsibilities. Instead, guidances describe the Agency's current thinking on a topic and should be viewed only as recommendations, unless specific regulatory or statutory requirements are cited. The use of the word should in Agency guidance means that something is suggested or recommended, but not required." The 30 and 60-day conditions are the conditions of an enforcement discretion, not a statutory safe harbour, and part 806 is unchanged by them. Treat them as the standard you will be measured against, and your part 806 analysis as a decision you still have to make and document.

    The guidance is nearly a decade old and the ecosystem is not. A 2016 document predates the section 524B regime entirely and its own footnotes reference a premarket guidance that has since been replaced. It remains listed as final and FDA's current FAQ still points to it, so it is operative. It is also plainly the older half of the pair, and where it is silent you are reasoning from a document written before the question existed.

    We are not your regulatory affairs function. Whether a change requires a new premarket submission, and whether an event is reportable under part 803 or part 806, are determinations for your regulatory and quality leadership, informed by counsel where the stakes justify it. We build and test the technical substance underneath them. Anyone offering to make them for you is offering to take a decision they will not be accountable for.

    When you do not need us

    If your device is not a cyber device, none of the 524B machinery applies and this guidance is best practice rather than an expectation attached to your file. Read it, take the vulnerability intake process from it, and spend nothing.

    If you already run a product security incident response process with a monitored intake address, a severity rubric that maps to patient harm rather than to CVSS alone, timestamped records of when you learned of each issue, and a release process that can validate and distribute a fix inside two months, you have the programme. What may be missing is the paperwork connecting it to the plan you filed, and that is a half-day of writing rather than an engagement.

    And if you are a small manufacturer with one connected device and no security function, the first thing to buy is not consulting. It is an ISAO membership and a monitored security contact address: cheap, and the two items you cannot retrofit after an event.

    Where Top Floor fits

    Our FDA cybersecurity practice works the postmarket half: designing surveillance and triage so the 30 and 60-day clocks are achievable rather than aspirational, building a coordinated vulnerability disclosure policy with an intake path someone owns, and reconciling both against the plan filed with your submission so the two describe the same organisation.

    Whether a given vulnerability is actually reachable in your architecture, which is the determination that decides controlled versus uncontrolled, is testing work, and it runs through our penetration testing practice across firmware, wireless interfaces, APIs and the cloud backend. Where the same device also puts you inside the HIPAA regime, our HIPAA practice runs alongside it.

    How to decide this week

    First, find your filed postmarket vulnerability plan and read it as an outsider would. Every commitment your organisation does not currently perform is an item, and the list is usually short and immediately actionable.

    Second, check the two cheap conditions: ISAO membership, and a monitored address a researcher can reach you at. If either answer is no, fix that before anything else here.

    Third, take the last three vulnerabilities you handled and reconstruct the dates: when you learned, when you told customers, when a validated fix reached them. If you cannot, your evidence problem is more urgent than your process problem.

    Fourth, write the controlled versus uncontrolled determination down for each of those three, with the exploitability and patient-harm reasoning. If the reasoning has never been written for a real case, it will not be written under pressure for the case that matters.

    Frequently asked questions

    Do I have to report a cybersecurity patch to FDA?

    Usually not. FDA's postmarket cybersecurity guidance states that the majority of actions manufacturers take to address cybersecurity vulnerabilities, which it calls cybersecurity routine updates and patches, are generally considered a type of device enhancement for which FDA does not require advance notification or reporting under 21 CFR part 806. That covers changes made solely to strengthen cybersecurity, including ones addressing a vulnerability that could compromise protected health information. The reporting question arises for the smaller subset correcting vulnerabilities that present uncontrolled risk of patient harm.

    What is the difference between controlled and uncontrolled cybersecurity risk?

    Controlled risk is present when there is sufficiently low, acceptable residual risk of patient harm from the vulnerability. Uncontrolled risk is present when residual risk is unacceptable because mitigations and compensating controls are insufficient. FDA directs manufacturers to assess this on the exploitability of the vulnerability and the severity of patient harm if exploited. Because the test is residual risk rather than raw severity, a high-severity component vulnerability can be a documented controlled risk where the affected function is unreachable or already fenced.

    What are the 30 and 60 day cybersecurity timelines FDA expects?

    They are two of the four conditions under which FDA says it does not intend to enforce 21 CFR part 806 reporting for uncontrolled-risk vulnerabilities. As soon as possible but no later than 30 days after learning of the vulnerability, the manufacturer communicates with customers and users, identifies interim compensating controls and develops a documented remediation plan. As soon as possible but no later than 60 days after learning of it, the manufacturer fixes the vulnerability, validates the change and distributes the deployable fix so residual risk is acceptable. The other two conditions are no known serious adverse events or deaths associated with the vulnerability, and active membership of an information sharing and analysis organisation that receives the customer communications.

    Which FDA postmarket cybersecurity guidance is current?

    Postmarket Management of Cybersecurity in Medical Devices, final guidance issued in December 2016 under docket FDA-2015-D-5105, which FDA still lists as final and still points to from its cybersecurity FAQ page as the resource for postmarket vulnerability management and patching. It is a separate document from the premarket guidance, which was reissued on February 3, 2026 as Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions and which superseded the June 27, 2025 edition. Manufacturers frequently update their premarket citations and leave a superseded postmarket reference in place, so check both.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.