On June 27, 2025, FDA published its final guidance, "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions," replacing the 2023 draft version and formally establishing what manufacturers must document across a device's entire lifecycle, not just at the point of clearance. Federal Register

The shift from the 2023 to 2025 version is substantive. The final guidance details expectations for managing cybersecurity risk from design through decommissioning, covering software bill of materials disclosure, labeling requirements and postmarket vulnerability management, not just premarket testing. AssurX Trade press coverage at the time described it as expanding requirements around device design, labeling and submission content specifically, giving manufacturers a much more granular checklist than the prior draft provided. HealthcareInfoSecurity

Why does this matter more in 2025 and 2026 than it did five years ago?

Connected medical devices, infusion pumps, imaging systems, patient monitors, are now standard attack surfaces in hospital ransomware incidents, not theoretical risks discussed at security conferences. A hospital network compromise increasingly starts or spreads through a device that was never designed with the same security assumptions as a laptop or server, because it was built on a longer product lifecycle, often running embedded software that predates modern security practices by a decade or more.

What does the guidance actually require of manufacturers?

A software bill of materials (SBOM). Manufacturers must document every third-party and open-source software component in a device, so a hospital security team can quickly check whether a newly disclosed vulnerability, in a widely used library for instance, affects a device on their network without waiting for the vendor to confirm it manually.

A cybersecurity management plan spanning the full lifecycle. This includes a process for identifying and disclosing vulnerabilities after the device is already sold and deployed, not just security testing performed before submission.

Design controls that assume compromise is possible. The guidance pushes manufacturers toward designing devices that can be updated and patched in the field, rather than devices that are effectively frozen at the moment of clearance and can only be secured by replacement.

What should a hospital's procurement checklist now include?

Old procurement question2026 procurement question
"Is it FDA cleared?""What is the postmarket vulnerability disclosure process?"
"Does it work on our network?""Can we get a current SBOM, and will it be updated?"
"What is the warranty period?""What is the security patch support timeline after end of sale?"
Security handled by IT after purchaseSecurity review built into the clinical procurement committee

Most hospital procurement processes were built around clinical efficacy and price, with security review handled separately, often after the purchase decision is functionally already made. The 2025 guidance gives hospital security and compliance teams a specific, citable federal standard to demand documentation against before signing, and health systems that are not updating their procurement templates to reference it directly are leaving real leverage on the table.

The takeaway

This guidance does not stop a hospital from getting compromised through a medical device. It gives purchasing teams, for the first time, a specific federal checklist to hold vendors against before the device is ever plugged into the network. The health systems that fold SBOM and lifecycle disclosure requirements into procurement now will spend a lot less time firefighting when the next widely disclosed vulnerability hits a component sitting inside their infusion pumps.