Secure Product Development Framework
A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
Definition
A Secure Product Development Framework (SPDF) is a documented set of processes that integrates security activities - threat modeling, secure design, secure coding, security testing, vulnerability management, and end-of-support planning - into every phase of the medical device product lifecycle. FDA's September 2023 cybersecurity guidance positions an SPDF as the recommended foundation for meeting section 524B, and explicitly calls out IEC 81001-5-1 ("Health software - Part 5-1: Security - Activities in the product life cycle") as an acceptable industry framework.What this means in practice
An SPDF is the antidote to the 'cybersecurity is QA's job at the end' antipattern. Mature MedTech teams encode the SPDF as procedures inside the existing QMS - reusing design controls, design review checkpoints, and CAPA - rather than running cybersecurity as a parallel program. This makes audit responses and CAPA traceability dramatically easier and avoids duplicate documentation.- •Adopting an SPDF on paper but not running its activities (threat models, security reviews) at the design checkpoints.
- •Treating IEC 81001-5-1 conformance as optional after FDA's explicit endorsement in the 2023 guidance.
- •Keeping security artifacts outside the QMS, leading to versioning and traceability problems at audit.
Frequently asked questions
Cross-references
Used by
Things that build on this term.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
Lifecycle requirements for medical device software.
FDA Cybersecurity 101
· From this learning pathA machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
A globally unique identifier for a publicly disclosed cybersecurity vulnerability.
An industry-standard 0–10 score that quantifies the severity of a software vulnerability.
A lightweight, OWASP-maintained SBOM format designed for application security and supply-chain use cases.
Software Team Onboarding
· From this learning pathSoftware providing healthcare professionals with knowledge and patient-specific information.
FDA mechanism to pre-authorize specific modifications to AI/ML-enabled devices.
Software intended for medical purposes that performs without being part of a hardware device.
Software embedded in or required to operate a hardware medical device.
Primary references
3 sources- 1
FDA Cybersecurity in Medical Devices Guidance (Sept 2023)VerifiedFDAfda.gov
- 2
IEC 81001-5-1:2021VerifiedISO/IECiso.org
- 3
NIST SP 800-218 Secure Software Development Framework (SSDF)VerifiedNISTcsrc.nist.gov
Inline markers like [1] jump to the matching reference above.