Compliance & Regulation

Do legacy medical devices still require cybersecurity monitoring and annual testing?

Manufacturers ask me some version of this question every month: our device was cleared years before Section 524B and the 2023 premarket guidance existed, so the monitoring and annual testing expectations surely don't apply to us? They do. If the product is still commercially distributed, the obligation is live. The FDA draws the line at commercial status, not clearance date.

Obligation follows commercial status, not clearance date2016 postmarket guidance2023: 524B + new premarket guidanceDevice A · cleared 2015 · still marketedmonitoring + periodic testing still requiredDevice B · cleared 2018 · EOL 2024EOL: obligation endsDevice C · cleared 2024 under 524B2014201620182020202220242026
Two devices cleared before the 2023 guidance, one after. The obligation tracks distribution and ends only at EOL.

The 2016 postmarket guidance never went away

The FDA's 2016 Postmarket Management of Cybersecurity in Medical Devices guidance remains the foundation for every marketed device. It expects manufacturers to monitor for vulnerabilities, assess their impact on safety and essential performance, and maintain a coordinated disclosure and remediation process across the device's lifecycle. Nothing in it is scoped to devices cleared after a particular date.

That matters because teams often treat 2023 as a boundary. New rules for new submissions, silence for everything older. The postmarket side has no such boundary. A device cleared in 2014 that ships today carries the same monitoring expectation as one cleared last quarter.

What 524B changes, and what it doesn't

Section 524B attaches to new premarket submissions for cyber devices. It does not reach back and rewrite a clearance from 2016. But that's narrower comfort than it sounds. The moment a legacy product line returns to the agency for a new version or a significant change, 524B applies in full. And until then, the 2016 postmarket guidance and your quality system obligations already cover whatever you're shipping.

The 2023 premarket guidance and its 2025 update reinforce this rather than replace it. Both treat cybersecurity as a lifecycle obligation: vulnerabilities managed continuously and exploitability evaluated within each commercial release, with metrics to prove it. Neither offers an exemption for products that predate them.

The release is the unit of compliance

The practical consequence: every release still in commercial distribution needs its own monitoring record and periodic security testing, typically annual. Evidence has to line up with the specific version customers are running, not with the product family in general. Once a release reaches end of life and is no longer distributed or supported, the recurring obligation ends with it.

Monitoring, concretely, means new vulnerabilities evaluated against the composition of each supported release, an assessment of impact on safety and essential performance, and a documented disposition with rationale. Periodic testing is the check on those assumptions. It confirms whether the vulnerabilities you deferred on paper are actually unreachable on the device.

Inspections follow the same logic. The legacy findings I see come in two flavors: no evidence of recent security testing on a device that's still selling, or vulnerability records blurred across versions so nobody can say what applies to the release under audit. Both are process failures. Both are avoidable.

The clearance date tells you which premarket rules applied. The shipping date tells you which postmarket obligations apply. Only one of those ever expires.

Scope it to what still ships

None of this means testing everything forever. The scope is your active, non-EOL releases and nothing else. We built ELTON around that boundary: the platform catalogs vulnerabilities and test results per release, keeps monitoring and recurring testing running for versions still on the market, and retires coverage when a release is formally end-of-lifed. What you get is a regulator-ready record for each version you still sell, and no spend on the ones you don't.

"Legacy" describes the technology, not the obligation. If you're still selling it, you're still securing it. Manufacturers who internalize that early get to treat legacy compliance as routine maintenance. The ones who don't tend to discover it during an inspection, which is the most expensive way to learn anything.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about legacy device obligations.

Do medical devices cleared before Section 524B still need cybersecurity monitoring?

Yes. If the product is still commercially distributed, the obligation is live. The FDA draws the line at commercial status, not clearance date. A device cleared in 2014 that ships today carries the same monitoring expectation as one cleared last quarter, because the 2016 postmarket guidance was never scoped to a clearance window.

Does Section 524B apply retroactively to an older clearance?

No. Section 524B attaches to new premarket submissions for cyber devices and does not reach back to rewrite a clearance from 2016. That comfort is narrower than it sounds. The moment a legacy product line returns to the agency for a new version or a significant change, 524B applies in full.

How long does the recurring testing obligation last on a legacy device?

Every release still in commercial distribution needs its own monitoring record and periodic security testing, typically annual. Once a release reaches end of life and is no longer distributed or supported, the recurring obligation ends with it. The scope is your active, non-EOL releases and nothing else.

What does monitoring a legacy device actually involve?

Monitoring means new vulnerabilities evaluated against the composition of each supported release, an assessment of impact on safety and essential performance, and a documented disposition with rationale. Periodic testing is the check on those assumptions. It confirms whether the vulnerabilities you deferred on paper are actually unreachable on the device.

What legacy device problems show up during inspections?

Legacy findings come in two flavors: no evidence of recent security testing on a device that is still selling, or vulnerability records blurred across versions so nobody can say what applies to the release under audit. Both are process failures and both are avoidable.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON