← Standards library

FDA 524B Clause Premarket cybersecurity guidance — security architecture

Security architecture views expected in a premarket submission

FDA Cybersecurity Premarket Guidance

FDA's premarket cybersecurity guidance expects a cyber-device submission to include security architecture views — diagrams and descriptions of the device's security design from several angles. The guidance describes a global system view, a multi-patient harm view, an updateability and patchability view, and a security use-case view. Together they show a reviewer how the device is defended, how it is patched, and how a compromise could propagate. Cite the current version: the guidance was reissued on 3 February 2026 as 'Quality Management System Considerations and Content of Premarket Submissions', superseding the June 2025 final guidance of nearly the same name. The architecture expectations carry over; the revision re-anchored the document on the QMSR and ISO 13485:2016.

Where Forge applies this

Verified against the primary source. Standards are periodically revised — always confirm the current text.