---
title: "Cybersecurity - MedTech Roadmap | MedTech Launch Guide"
description: "FD&amp;C Act Section 524B - premarket package + lifelong postmarket plan. Any device that includes software, connects to the internet, and has features vulnerable"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@type": "Article",
    "headline": "Cybersecurity - MedTech Roadmap",
    "description": "Any device that includes software, connects to the internet, and has features vulnerable to cyber threats is a 'cyber device' under FD&C Act Section 524B. FDA will refuse to accept a 510(k), De Novo, or PMA that does not include the required cybersecurity content - regardless of clinical merit.",
    "url": "https://medtechlaunchguide.com/roadmap/cybersecurity",
    "mainEntityOfPage": "https://medtechlaunchguide.com/roadmap/cybersecurity",
    "articleSection": "Cybersecurity",
    "isPartOf": {
      "@type": "CollectionPage",
      "name": "MedTech Founder Roadmap",
      "url": "https://medtechlaunchguide.com/roadmap"
    },
    "publisher": {
      "@type": "Organization",
      "name": "MedTech Launch Guide",
      "url": "https://medtechlaunchguide.com"
    }
  }
---

[Skip to content](#main)

[

MedTech Launch Guide

Education Hub for Founders



](/)

[Roadmap](/roadmap)

[Topics](/topics)

Tools

[Pulse](/pulse)Search ⌘K[Start Here](/start)

Search ⌘K

[Roadmap](/roadmap)/ [01 · IP Protection](/roadmap/ip-protection)[02 · Regulatory Pathway](/roadmap/regulatory-pathway)[03 · Clinical Evidence](/roadmap/clinical-evidence)[04 · Reimbursement](/roadmap/reimbursement)[05 · Cybersecurity](/roadmap/cybersecurity)[06 · Business Model](/roadmap/business-model)[07 · Go-To-Market](/roadmap/go-to-market)

Step 05 of 7 · Roadmap

# Cybersecurity

FD&C Act Section 524B - premarket package + lifelong postmarket plan

When to start 

Architecture phase - before software is written. Retrofits are 5–10× more expensive.

Duration 

Ongoing - premarket package builds over 6–12 months; postmarket monitoring is continuous

Indicative cost 

USD 50K–250K premarket · 75K–300K/year postmarket

Any device that includes software, connects to the internet, and has features vulnerable to cyber threats is a 'cyber device' under FD&C Act Section 524B. FDA will refuse to accept a 510(k), De Novo, or PMA that does not include the required cybersecurity content - regardless of clinical merit.

## What FDA requires in the submission

Per the Feb 2026 cybersecurity guidance and Section 524B, premarket submissions must include a Secure Product Development Framework, threat model, cybersecurity risk assessment, SBOM, vulnerability assessment, and a postmarket monitoring plan with a coordinated vulnerability disclosure process.

## SBOM is not optional

Software Bill of Materials in a machine-readable format (CycloneDX or SPDX) is required content. Generate it from your CI pipeline; do not assemble it by hand. Update it for every release.

## Postmarket is the long tail

Cybersecurity is not a launch milestone - it's a 10-year operational commitment. CISA medical advisories, vulnerability disclosures, patch deployment, and updated threat models continue for the life of the device.

Artifacts to ship

-   Threat model (STRIDE or attack tree) 
-   Cybersecurity risk assessment (mapped to ISO 14971) 
-   Software Bill of Materials in CycloneDX or SPDX 
-   Penetration test report from independent assessor 
-   Coordinated vulnerability disclosure policy + intake process 
-   Postmarket monitoring + patch management plan 

Common pitfalls

-   Treating cyber as a checkbox at submission - FDA reviewers ask follow-ups for months 
-   Hand-assembled SBOM that drifts from the actual build 
-   No vulnerability disclosure process (now an explicit Section 524B requirement) 
-   Underbudgeting postmarket monitoring - recalls cost 10–100× the prevention 

Primary sources

-   [FDA Cybersecurity in Medical Devices: QMS Considerations (3 Feb 2026) Premarket guidance ](https://www.fda.gov/media/119933/download)
-   [FD&C Act Section 524B Statute ](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity)
-   [CycloneDX SBOM Standard Format ](https://cyclonedx.org/)
-   [CISA Medical Advisories Postmarket signal ](https://www.cisa.gov/news-events/ics-advisories)

[

Previous

Reimbursement

Step 04 · Coding, coverage, payment - the three legs every payer requires

](/roadmap/reimbursement)[

Next

Business Model

Step 06 · Capital equipment, consumables, SaaS, or service - pick on purpose

](/roadmap/business-model)

MedTech Launch Guide

The independent education hub for medtech innovators bringing devices to the US market - paired with a live pulse of what FDA, CMS, CISA and investors are doing right now.

Sponsored by Blue Goat Cyber 

Pulse

-   [Live Pulse](/pulse)
-   [Funding Tape](/pulse#funding)
-   [Pitch Decks](/pulse#pitch)
-   [Cybersecurity](/pulse#cyber)
-   [Post-mortems](/pulse#failure)

Learn

-   [Founder Roadmap](/roadmap)
-   [Start here: build my plan](/start)
-   [Regulatory & Quality](/roadmap/regulatory-pathway)
-   [Funding & Grants](/pulse#funding)
-   [Clinical evidence](/roadmap/clinical-evidence)
-   [Reimbursement](/roadmap/reimbursement)
-   [Topics & tools](/topics)
-   [Funding quiz](/quiz)
-   [Investor Directory](/investors)
-   [FDA user fees & calculator](/mdufa-fees)
-   [Cyber budget worksheet](/worksheets/cyber-budget)
-   [Glossary](/glossary)
-   [Weekly Brief](/#newsletter)

Company

-   [About](/about)
-   [Editorial policy](/editorial)
-   [Tip line · Contact](/contact)
-   [Privacy](/privacy)
-   [Terms](/terms)

Sister sites

[MedTech Terms ↗](https://medtechterms.com)

medtechterms.com

The full MedTech dictionary. Sourced definitions with a page per term, A-Z and category indexes, learning paths, and side-by-side comparisons.

[A-Z index →](https://medtechterms.com/a-z)[Categories →](https://medtechterms.com/categories)[Learning paths →](https://medtechterms.com/paths)[Compare terms →](https://medtechterms.com/compare)

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

bluegoatcyber.com

Medical device cybersecurity practice. Threat modeling, SBOMs, penetration testing, and FDA premarket and postmarket submission support.

[FDA premarket cyber →](https://bluegoatcyber.com/services/medical-device-cybersecurity/fda-premarket-cybersecurity/)[Penetration testing →](https://bluegoatcyber.com/services/medical-device-cybersecurity/penetration-testing/)[Threat modeling →](https://bluegoatcyber.com/services/medical-device-cybersecurity/threat-modeling/)[Site index →](https://bluegoatcyber.com/site-index)

© 2026 MedTech Launch Guide. Editorial independence is non-negotiable.

Sponsored content is clearly labelled.