Since February 2, 2026, FDA inspects cybersecurity inside the quality system. ELTON keeps the vulnerability record ready for the visit.
The requirements stayed substantially similar. What FDA can see changed.
Part 820 now incorporates ISO 13485:2016 by reference, with risk management running through the whole system. FDA calls the requirements substantially similar to the old QS regulation, and it now enforces them.
The investigator's playbook is a total product life cycle assessment: six QMS areas, four other applicable FDA requirements, and the manufacturer's own risk management documentation read throughout. It names cyber devices and software-enabled devices.
In February 2026 FDA reissued Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions to align with QMSR. The core expectations did not change; the quality system framing did.
The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports.If your internal audits cover cybersecurity, vulnerability management, CAPA or software suppliers, an investigator can read what they found. Terminology moved more than the bar: what QMSR changed, and did not →
Sampled by risk across six QMS areas.
Part III.H tells investigators that cyber devices should be considered for review for conformity with section 524B(b)(2), on domestic and foreign inspections alike: the processes that keep the device cybersecure and make postmarket updates and patches available.
If the device is a cyber device or software enabled, the program points the investigator to CDRH's Quality Program and FDA's cybersecurity mailbox before and during the inspection, and to the Cybersecurity in Medical Devices FAQs.
FDA says investigators may review QMS records created before the effective date. A vulnerability record that stops and restarts at the rule change is a finding waiting to happen. A continuous one is evidence.
Cybersecurity moved from a submission exercise to a quality system activity.
| Dimension | Before | 2026 environment |
|---|---|---|
| Regulation | QS Regulation | QMSR, ISO 13485:2016 incorporated by reference |
| Inspection | QSIT | CP 7382.850, risk and process based, total product life cycle |
| Where cyber sits | Treated as specialized, mostly premarket | Integrated into QMS activities |
| Cyber guidance | Written against the QS regulation | Reissued in February 2026, explicitly aligned to QMSR |
| Internal audits | Generally shielded from routine inspection | FDA may inspect management review, quality audits and supplier audit reports |
| Cyber requirements | Mostly guidance driven | Section 524B statutory obligations for cyber devices, since March 29, 2023 |
As of February 2, 2026, FDA's new QMSR inspection framework allows cybersecurity to be evaluated as part of the manufacturer's overall quality management system, including design and development, risk management, verification and validation, CAPA, supplier controls and postmarket activities.QMSR contains no clause that says manufacturers shall perform penetration testing annually, and none that says FDA shall audit cybersecurity. The exposure comes from the chain, not from a new mandate.
Every finding carries its test case, verdict, rationale and version.
| QMS area (CP 7382.850) | What an investigator may ask | The ELTON record |
|---|---|---|
| Design and Development: verification, validation, software validation | Threat model coverage, and evidence that security requirements were verified on the shipped design | Digital twin and MITRE EMB3D threat model; a test case per threat, traced to components and interfaces; executed results with logs |
| Risk management, read throughout | How cybersecurity risks were identified, evaluated and controlled, and why residual risk is acceptable | Product-adjusted ratings on the qualified MDDT CVSS rubric; exploitability verified on the twin, in code and on the real device; written rationale per disposition |
| Measurement, Analysis and Improvement: complaints, feedback, CAPA, analysis of data | How a reported vulnerability was evaluated, closed and trended | Finding lifecycle with statuses, Fixed and Not Affected closures and VEX reasons; retest evidence; three clocks per view |
| Outsourcing and Purchasing | Control of software suppliers and third-party components | SBOM components matched to the twin, CVEs dispositioned per release, SOUP tracked with the product |
| Change Control | Effect of a release on security posture | Every release retested against the record; findings tracked to a version and a number |
| Management Oversight: management review, medical device file, internal audits | Metrics top management reviews; audit findings, now inspectable | Living reports with per-view metrics (MTTT, MTTV, MTTM); the same record supplies internal audits and the medical device file |
| MDR, corrections and removals | Whether a vulnerability rose to a reportable event; patch and update decisions | Incident response from the record in hours, with the evidence behind the disposition and the update decision |
Mapping is by QMS area, not a claim that each artifact is independently mandated. Which records satisfy which clause depends on the device and the quality system.
For cyber devices, the obligations are statute, not guidance.
A plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure. ELTON's postmarket record is that plan, running.
Processes that provide reasonable assurance the device and related systems are cybersecure, with updates and patches on a regular cycle and out of cycle for critical vulnerabilities. That is section 524B(b)(2), the paragraph CP 7382.850 points investigators to.
A software bill of materials covering commercial, open-source and off-the-shelf components. ELTON monitors it against the twin and dispositions every match, release by release.
Section 524B was added to the FD&C Act by the Consolidated Appropriations Act, 2023, signed December 29, 2022, and has applied to submissions since March 29, 2023.
Does QMSR require penetration testing?
No clause in QMSR says so, and this page does not claim it. What changed is that CP 7382.850 tells investigators to consider cyber devices for review against section 524B(b)(2) and to read risk management documentation throughout the inspection, so the evidence that design controls and risk management worked is what gets asked for. Executed test cases are that evidence.
Can FDA read our internal audits now?
Yes. FDA's QMSR FAQ states that the QMSR gives FDA the authority to inspect management review, quality audits and supplier audit reports; the section 820.180(c) exceptions were not carried into the QMSR. Audits that cover cybersecurity, vulnerability management, CAPA or software suppliers are in scope.
What is CP 7382.850?
FDA's compliance program Inspection of Medical Device Manufacturers, effective February 2, 2026. It replaced QSIT, supersedes CP 7382.845 and CP 7383.001, and describes a risk-based, total product life cycle inspection organized around six QMS areas and four other applicable FDA requirements.
Do records created before February 2, 2026 count?
Yes. FDA says investigators may review QMS records created before the effective date, and suggests a comparative analysis showing older records meet QMSR requirements. A continuous vulnerability record, retained by version, avoids the question.
What did the February 2026 cybersecurity guidance change?
FDA reissued Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions to align with QMSR, replacing QS regulation references with QMSR and ISO 13485 references. The core technical expectations did not change.
How does ELTON make vulnerability data inspection-ready?
Every finding is retained with its test case, product-adjusted rating, exploitability verdict and evidence, disposition and rationale, release and status history, remediation and retest, and view-relative clocks. An investigator reads the same record your reviewers did, and the record continues across releases and across the rule change.