---
title: "524B, Section 524B of the FD&amp;C Act | MedTech Terms"
description: "The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices. Plain-English Cybersecurity definition for MedTech teams,"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/section-524b#term",
        "name": "Section 524B of the FD&C Act",
        "alternateName": [
          "524B",
          "524B",
          "Cyber device authority"
        ],
        "description": "Section 524B of the Federal Food, Drug, and Cosmetic Act, added by section 3305 of the Consolidated Appropriations Act of 2023, requires sponsors of \"cyber devices\" to submit a cybersecurity package as part of any premarket submission (510(k), De Novo, PMA, HDE). A cyber device is defined as one that (1) includes software validated, installed, or authorized by the sponsor; (2) has the ability to connect to the internet; and (3) contains technological characteristics that could be vulnerable to cybersecurity threats. 524B took effect for submissions on or after March 29, 2023, and FDA began Refuse-to-Accept (RTA) enforcement on October 1, 2023.",
        "url": "https://medtechterms.com/terms/section-524b",
        "termCode": "section-524b",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/section-524b#article",
        "headline": "524B, Section 524B of the FD&C Act",
        "description": "The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.",
        "url": "https://medtechterms.com/terms/section-524b",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/section-524b"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/section-524b#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Section 524B of the FD&C Act, 524B, 524B, Cyber device authority, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Section 524B of the FD&C Act - FDA overview",
            "url": "https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions (Sept 2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Consolidated Appropriations Act of 2023, Section 3305",
            "url": "https://www.congress.gov/bill/117th-congress/house-bill/2617",
            "publisher": {
              "@type": "Organization",
              "name": "U.S. Congress"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/sbom#term",
            "name": "Software Bill of Materials",
            "alternateName": "SBOM",
            "url": "https://medtechterms.com/terms/sbom"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/spdf#term",
            "name": "Secure Product Development Framework",
            "alternateName": "SPDF",
            "url": "https://medtechterms.com/terms/spdf"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/threat-modeling#term",
            "name": "Threat Modeling",
            "url": "https://medtechterms.com/terms/threat-modeling"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/rta-cyber#term",
            "name": "Refuse to Accept (Cybersecurity)",
            "alternateName": "RTA (cyber)",
            "url": "https://medtechterms.com/terms/rta-cyber"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/cvd#term",
            "name": "Coordinated Vulnerability Disclosure",
            "alternateName": "CVD",
            "url": "https://medtechterms.com/terms/cvd"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Section 524B of the FD&C Act",
            "item": "https://medtechterms.com/terms/section-524b"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/section-524b#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "What is a 'cyber device' under 524B?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "A device that (1) contains software validated, installed, or authorized by the sponsor, (2) has the ability to connect to the internet, and (3) contains technological characteristics vulnerable to cybersecurity threats. The 'ability to connect' is interpreted broadly - Wi-Fi, Bluetooth, cellular, even USB pathways into clinical networks can qualify."
            }
          },
          {
            "@type": "Question",
            "name": "Does 524B apply to 510(k) submissions only?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "No. 524B applies to all premarket submission types - 510(k), De Novo, PMA, HDE, and PMA supplements - for any device that meets the cyber-device definition."
            }
          },
          {
            "@type": "Question",
            "name": "What happens if our 524B content is incomplete?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "FDA will issue a Refuse-to-Accept (RTA) decision and the submission clock never starts. RTA is faster and less forgiving than a Major Deficiency letter, so 524B content needs to be complete on Day 1."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Section 524B of the FD&C Act

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)[Global Markets](/ecosystems/global-markets)524B 

# Section 524B of the FD&C Act

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

Section 524B of the Federal Food, Drug, and Cosmetic Act, added by section 3305 of the Consolidated Appropriations Act of 2023, requires sponsors of "cyber devices" to submit a cybersecurity package as part of any premarket submission (510(k),  [De Novo](/terms/de-novo),  [PMA](/terms/pma),  [HDE](/terms/hde)). A cyber device is defined as one that (1) includes software validated, installed, or authorized by the sponsor; (2) has the ability to connect to the internet; and (3) contains technological characteristics that could be vulnerable to cybersecurity threats. 524B took effect for submissions on or after March 29, 2023, and FDA began Refuse-to-Accept ( [RTA](/terms/rta)) enforcement on October 1, 2023. 

What the regulation says

524B requires four things in a cyber-device submission: (1) a plan to monitor, identify, and address postmarket cybersecurity vulnerabilities and exploits; (2) processes and procedures providing reasonable assurance that the device and connected systems are cybersecure, including  [coordinated vulnerability disclosure](/terms/cvd) and timely patch release; (3) a  [Software Bill of Materials](/terms/sbom) including commercial, open-source, and off-the-shelf components; and (4) any other information FDA may require to demonstrate reasonable assurance of safety and effectiveness. FDA's September 2023 final guidance translates these statutory requirements into reviewable artifacts - threat model, risk assessment, security architecture views, SBOM, vulnerability management plan, and end-user  [labeling](/terms/labeling). 

## What this means in practice

Before 524B, cybersecurity expectations were guidance-level and inconsistently enforced. Today, missing 524B content is a Refuse-to-Accept basis - the submission never reaches substantive review. Most MedTech teams now treat 524B as the  [spine](/terms/spine) of their premarket cybersecurity package and align internal  [design controls](/terms/design-controls) ( [ISO 13485](/terms/iso-13485) / 21 CFR 820.30) and risk management ( [ISO 14971](/terms/iso-14971),  [AAMI TIR57](/terms/aami-tir57)) to produce the required artifacts as a natural output of the development lifecycle. 

Common pitfalls

-   • Assuming legacy 510(k) predicates exempt the new submission from 524B - they do not. 
-   • Submitting a generic 'cybersecurity plan' without the underlying threat model, SBOM, and architecture views. 
-   • Treating the postmarket vulnerability monitoring plan as boilerplate; FDA expects a real, resourced process. 
-   • Ignoring labeling - 524B requires end-user-facing security information (e.g., MDS2-style disclosures). 

## Frequently asked questions

What is a 'cyber device' under 524B? 

A device that (1) contains software validated, installed, or authorized by the sponsor, (2) has the ability to connect to the internet, and (3) contains technological characteristics vulnerable to cybersecurity threats. The 'ability to connect' is interpreted broadly - Wi-Fi, Bluetooth, cellular, even USB pathways into clinical networks can qualify. 

Does 524B apply to 510(k) submissions only? 

What happens if our 524B content is incomplete? 

## Cross-references

### Uses

Concepts or artefacts this term builds on.

-   [
    
    Software Bill of Materials(SBOM) 
    
    
    
    ](/terms/sbom)
-   [
    
    Coordinated Vulnerability Disclosure(CVD) 
    
    
    
    ](/terms/cvd)
-   [
    
    Premarket Cybersecurity Submission
    
    
    
    ](/terms/premarket-cybersecurity)

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Secure Product Development Framework(SPDF) 

A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.





](/terms/spdf)[

Cybersecurity

Software Bill of Materials(SBOM) 

A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.





](/terms/sbom)[

Cybersecurity

Threat Modeling

A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.





](/terms/threat-modeling)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)

### FDA Cybersecurity 101

· From this learning path 

[

Cybersecurity

Common Vulnerabilities and Exposures(CVE) 

A globally unique identifier for a publicly disclosed cybersecurity vulnerability.





](/terms/cve?from=fda-cybersecurity-101)[

Cybersecurity

Common Vulnerability Scoring System(CVSS) 

An industry-standard 0–10 score that quantifies the severity of a software vulnerability.





](/terms/cvss?from=fda-cybersecurity-101)[

Cybersecurity

CycloneDX

A lightweight, OWASP-maintained SBOM format designed for application security and supply-chain use cases.





](/terms/cyclonedx?from=fda-cybersecurity-101)[

Cybersecurity

STRIDE Threat Model(STRIDE) 

A six-category framework for enumerating threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.





](/terms/stride?from=fda-cybersecurity-101)

### Software Team Onboarding

· From this learning path 

[

Software & AI

Clinical Decision Support(CDS) 

Software providing healthcare professionals with knowledge and patient-specific information.

Adjacent lesson 

](/terms/cds?from=software-team-onboarding)[

Standards

IEC 62304

Lifecycle requirements for medical device software.





](/terms/iec-62304?from=software-team-onboarding)[

Software & AI

Predetermined Change Control Plan(PCCP) 

FDA mechanism to pre-authorize specific modifications to AI/ML-enabled devices.





](/terms/ai-ml-pccp?from=software-team-onboarding)[

Software & AI

Software as a Medical Device(SaMD) 

Software intended for medical purposes that performs without being part of a hardware device.





](/terms/samd?from=software-team-onboarding)

Cited by

Where this term appears across MedTech Terms.

Learning paths (2)

-   [FDA Cybersecurity 101](/paths/fda-cybersecurity-101)Lesson 1 of 11 
-   [Software Team Onboarding](/paths/software-team-onboarding)Lesson 8 of 12 

Ecosystems (2)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)
-   [Global Markets](/ecosystems/global-markets)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

FDA· 2 U.S. Congress· 1 

1.  [1 
    
    Section 524B of the FD&C Act - FDA overview
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity)
2.  [2 
    
    Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions (Sept 2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)
3.  [3 
    
    Consolidated Appropriations Act of 2023, Section 3305
    
    Verified 
    
    U.S. Congress · congress.gov 
    
    
    
    ](https://www.congress.gov/bill/117th-congress/house-bill/2617)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Preparing a 524B cyber submission?

We've supported dozens of premarket cybersecurity packages - threat modeling, SBOMs, and the supporting documentation FDA expects.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

524B

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=section-524b)

Learn in 60 seconds

Card Lesson Quiz

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.

-   · Before 524B, cybersecurity expectations were guidance-level and inconsistently enforced. 
-   · Today, missing 524B content is a Refuse-to-Accept basis - the submission never reaches substantive review. 
-   · 524B took effect for submissions on or after March 29, 2023, and FDA began Refuse-to-Accept (RTA) enforcement on October 1, 2023. 

Remember this

Watch out: Assuming legacy 510(k) predicates exempt the new submission from 524B - they do not.

Related terms

-   [Software Bill of Materials(SBOM) ](/terms/sbom)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Threat Modeling ](/terms/threat-modeling)
-   [Refuse to Accept (Cybersecurity)(RTA (cyber)) ](/terms/rta-cyber)
-   [Coordinated Vulnerability Disclosure(CVD) ](/terms/cvd)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [Section 522 Postmarket Surveillance(Section 522) ](/terms/section-522)
-   [Emergency Use Authorization(EUA) ](/terms/eua)
-   [CISA Known Exploited Vulnerabilities Catalog(KEV) ](/terms/kev)
-   [FedRAMP(FedRAMP) ](/terms/fedramp)
-   [Legacy Device Cybersecurity ](/terms/legacy-device-cyber)
-   [Zero Trust Architecture(ZTA) ](/terms/zero-trust)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)