FDA 524B Clause Premarket cybersecurity guidance — security architecture
Security architecture views expected in a premarket submission
FDA Cybersecurity Premarket Guidance
FDA's premarket cybersecurity guidance expects a cyber-device submission to include security architecture views — diagrams and descriptions of the device's security design from several angles. The guidance describes a global system view, a multi-patient harm view, an updateability and patchability view, and a security use-case view. Together they show a reviewer how the device is defended, how it is patched, and how a compromise could propagate. Cite the current version: the guidance was reissued on 3 February 2026 as 'Quality Management System Considerations and Content of Premarket Submissions', superseding the June 2025 final guidance of nearly the same name. The architecture expectations carry over; the revision re-anchored the document on the QMSR and ISO 13485:2016.
Where Forge applies this
Verified against the primary source. Standards are periodically revised — always confirm the current text.