See how we map to the FDA premarket guidance.

The February 2026 final guidance defines thirty cybersecurity categories. Here is each one, the section it comes from, and what covers it.

Standards & Regulations

A mapping you can check, clause by clause.

Every category, not the convenient ones

The premarket guidance defines thirty cybersecurity categories, from quality system procedures through to firmware update signing. All thirty are mapped below to the offering that answers them, with the section reference beside each so you can check it against your own copy.

Four kinds of work, across all thirty

Some categories are answered by process and documentation, some by SBOM and vulnerability management, some by cryptography and update integrity, and some by expert review that genuinely takes a person rather than a tool. The mapping below tags each category with what it needs.

Read by people who reviewed these submissions

The mapping is informed by twelve global standards folded into one model, and by a bench that includes a former FDA reviewer and consumer safety officer alongside three HSCC JSPv2 co-authors.

FDA premarket cybersecurity guidance

Thirty categories, and what answers each.

Grouped as the guidance groups them and ordered as it orders them, so you can read this alongside your own copy. Section references point to the February 2026 final guidance.

Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions: Final, February 2026 (PDF)

15

Secure development & documentation

Process, design controls, and the records a submission needs

10

SBOM & vulnerability management

Component inventory and triage across the device lifetime

8

Cryptography & update integrity

Keys, signing, encryption, and secure updates

4

Expert review

Threat modelling and architecture review by people

All 30 categories are mapped. Some are answered by more than one kind of work, so these figures sum to more than 30.

Find your clause

Every category, its section reference, and what answers it. Select one to read the guidance’s own words and our response beside it.

Showing 30 of 30 categories

Section IV.A.1

Quality management system inclusive of cybersecurity

Development & docs

FDA guidance: Device manufacturers must establish and follow quality management systems to help ensure that their products consistently meet applicable requirements and specifications. The quality management systems requirements are found in the QMSR in 21 CFR Part 820, which incorporates by reference ISO 13485.

Medcrypt solution: Medcrypt provides a template and model implementation for folding cybersecurity procedures into an existing quality management system and its design controls.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness