Why ELTON · FDA-Compliant

Cybersecurity is now
inspection evidence.

Since February 2, 2026, FDA inspects cybersecurity inside the quality system. ELTON keeps the vulnerability record ready for the visit.

THE CHAIN AN INVESTIGATOR CAN FOLLOW · QMSR CLAUSE TO CVECP 7382.8501QMSR, ISO 13485Part 820 with ISO 13485:20162Design, developmentcontrols, inputs and outputs3Risk managementread throughout the inspection4Cyber risk managementthreats, controls, acceptance5Security requirementsand architecture6Security verificationand validation7Vulnerability testingidentification and testing8CAPA, complaintspostmarket surveillance9Monitor and remediatepostmarket vulnerabilitiesWHERE ELTON'S RECORD LIVESquality system clauses the investigator starts fromcybersecurity records ELTON produces on every releaseCybersecurity records sit on the path FDA uses to test whether the quality system works.Evaluation of one requirement may necessitate evaluation of others, in the compliance program's own words.TOTAL PRODUCT LIFE CYCLETHE CHAIN AN INVESTIGATOR CAN FOLLOW1QMSR, ISO 13485Part 820 with ISO 13485:20162Design, developmentcontrols, inputs and outputs3Risk managementread throughout the inspection4Cyber risk managementthreats, controls, acceptance5Security requirementsand architecture6Security verificationand validation7Vulnerability testingidentification and testing8CAPA, complaintspostmarket surveillance9Monitor and remediatepostmarket vulnerabilitiesCybersecurity records sit on the pathFDA uses to test the quality system.Green: the records ELTON produces on every release.TOTAL PRODUCT LIFE CYCLE
In the compliance program's own words, evaluation of one requirement may necessitate the evaluation of requirements in other areas of the QMS.
February 2, 2026

The bar did not move.
The inspection did.

The requirements stayed substantially similar. What FDA can see changed.

QMSR replaced the QS regulation

Part 820 now incorporates ISO 13485:2016 by reference, with risk management running through the whole system. FDA calls the requirements substantially similar to the old QS regulation, and it now enforces them.

CP 7382.850 replaced QSIT

The investigator's playbook is a total product life cycle assessment: six QMS areas, four other applicable FDA requirements, and the manufacturer's own risk management documentation read throughout. It names cyber devices and software-enabled devices.

The cybersecurity guidance was reissued

In February 2026 FDA reissued Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions to align with QMSR. The core expectations did not change; the quality system framing did.

The inspection shield is gone. Under the old QS regulation, section 820.180(c) kept management reviews, quality audits and supplier audit reports out of routine inspection. FDA's QMSR FAQ now says: The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. If your internal audits cover cybersecurity, vulnerability management, CAPA or software suppliers, an investigator can read what they found. Terminology moved more than the bar: what QMSR changed, and did not →
CP 7382.850

The playbook
names cyber devices.

Sampled by risk across six QMS areas.

CP 7382.850 · SIX QMS AREASRISK MANAGEMENT READ THROUGHOUTDesign and Developmentinputs, outputs, review, verification,validation, software validation, transferMeasurement, Analysis, Improvementcomplaint handling, feedback, analysis ofdata, internal audits, corrective, preventiveManagement Oversightmanagement review, medical device file,planning of product realizationOutsourcing and Purchasingoutsourcing, purchasing controls,supplier evaluation and monitoringChange Controlproduct and process changes,effect on risk and on the designProduction and Service Provisionprocess validation, identificationand traceability, servicingFOUR OTHER APPLICABLE FDA REQUIREMENTSMedical Device ReportingReports of Corrections and RemovalsMedical Device TrackingUnique Device IdentificationSIGNALS READ BEFORE AND DURINGBEFOREMedical Device Reports (MDRs)Reports of Corrections and RemovalsComplaints and trade complaintsTotal Product Lifecycle reportDURINGComplaints and customer feedbackPostmarket surveillanceRisk management documentationMonitoring, trends, servicing dataCyber devices are considered for review against FD&C Act section 524B(b)(2), at home and abroad.Software-enabled devices route the investigator to CDRH's Quality Program and the cybermed mailbox before and during the visit.PART III · H · CYBERSECURITYCP 7382.850 · SIX QMS AREASDesign and Developmentinputs, outputs, review, verification,validation, software validation, transferMeasurement, Analysis, Improvementcomplaint handling, feedback, analysis ofdata, internal audits, corrective, preventiveManagement Oversightmanagement review, medical device file,planning of product realizationOutsourcing and Purchasingoutsourcing, purchasing controls,supplier evaluation and monitoringChange Controlproduct and process changes,effect on risk and on the designProduction and Service Provisionprocess validation, identificationand traceability, servicingFOUR OTHER APPLICABLE FDA REQUIREMENTSMedical Device ReportingReports of Corrections and RemovalsMedical Device TrackingUnique Device IdentificationSIGNALS READ BEFORE AND DURINGBEFOREMedical Device Reports (MDRs)Reports of Corrections and RemovalsComplaints and trade complaintsTotal Product Lifecycle reportDURINGComplaints and customer feedbackPostmarket surveillanceRisk management documentationMonitoring, trends, servicing dataCyber devices are considered for reviewagainst section 524B(b)(2).Domestic and foreign inspections alike. Software-enableddevices route the investigator to CDRH's Quality Program.PART III · H
Before the visit: MDRs, complaints, corrections and removals, the TPLC report. During it: postmarket surveillance, risk management documentation, monitoring and trends.

Cyber devices, section 524B(b)(2)

Part III.H tells investigators that cyber devices should be considered for review for conformity with section 524B(b)(2), on domestic and foreign inspections alike: the processes that keep the device cybersecure and make postmarket updates and patches available.

Software-enabled devices get specialist support

If the device is a cyber device or software enabled, the program points the investigator to CDRH's Quality Program and FDA's cybersecurity mailbox before and during the inspection, and to the Cybersecurity in Medical Devices FAQs.

Records from before February 2, 2026 count

FDA says investigators may review QMS records created before the effective date. A vulnerability record that stops and restarts at the rule change is a finding waiting to happen. A continuous one is evidence.

What converged in 2026

Six changes,
one exposure.

Cybersecurity moved from a submission exercise to a quality system activity.

DimensionBefore2026 environment
RegulationQS RegulationQMSR, ISO 13485:2016 incorporated by reference
InspectionQSITCP 7382.850, risk and process based, total product life cycle
Where cyber sitsTreated as specialized, mostly premarketIntegrated into QMS activities
Cyber guidanceWritten against the QS regulationReissued in February 2026, explicitly aligned to QMSR
Internal auditsGenerally shielded from routine inspectionFDA may inspect management review, quality audits and supplier audit reports
Cyber requirementsMostly guidance drivenSection 524B statutory obligations for cyber devices, since March 29, 2023
The accurate statement. As of February 2, 2026, FDA's new QMSR inspection framework allows cybersecurity to be evaluated as part of the manufacturer's overall quality management system, including design and development, risk management, verification and validation, CAPA, supplier controls and postmarket activities. QMSR contains no clause that says manufacturers shall perform penetration testing annually, and none that says FDA shall audit cybersecurity. The exposure comes from the chain, not from a new mandate.
How ELTON keeps the record

Vulnerability data
FDA can inspect.

Every finding carries its test case, verdict, rationale and version.

ONE FINDING IN THE ELTON RECORDRETAINED PER VERSIONFinding and test casecomponent, interface, threat (EMB3D), test case identifierProduct-adjusted ratingqualified MDDT CVSS rubric, base score kept alongsideExploitability verdictL1 twin, L2 code, L3 real device; test case, log, resultDisposition and rationaleFixed or Not Affected, VEX reason, written justificationRelease and statusversion, view (Draft, Release, Archived), status historyRemediation and retestfix, release it shipped in, retest that proved itClocksMTTT, MTTV, MTTM per view, for management reviewWHERE IT LANDS IN THE QMS · CP 7382.850 AREASINSPECTABLEDesign and Developmentverification, validation, software validationRisk management filecybersecurity risks, controls, acceptabilityMeasurement, Analysis, Improvementcomplaints, CAPA, analysis of data, internal auditsOutsourcing and PurchasingSBOM components, SOUP, supplier controlsChange Controleffect of each release on postureManagement Oversightmanagement review, medical device fileMDR, Corrections and Removalsreportability, patch and update decisionsRetained with a version and a number, so an investigator reads the same record your reviewers did.Records created before February 2, 2026 are in scope too, in FDA's words, so the record has to be continuous, not rebuilt for the visit.AUDIT-READYONE FINDING IN THE ELTON RECORDFinding and test casecomponent, interface, threat (EMB3D), test case identifierProduct-adjusted ratingqualified MDDT CVSS rubric, base score kept alongsideExploitability verdictL1 twin, L2 code, L3 real device; test case, log, resultDisposition and rationaleFixed or Not Affected, VEX reason, written justificationRelease and statusversion, view (Draft, Release, Archived), status historyRemediation and retestfix, release it shipped in, retest that proved itClocksMTTT, MTTV, MTTM per view, for management reviewLANDS INWHERE IT LANDS · CP 7382.850 AREASDesign and Developmentverification, validation, software validationRisk management filecybersecurity risks, controls, acceptabilityMeasurement, Analysis, Improvementcomplaints, CAPA, analysis of data, internal auditsOutsourcing and PurchasingSBOM components, SOUP, supplier controlsChange Controleffect of each release on postureManagement Oversightmanagement review, medical device fileMDR, Corrections and Removalsreportability, patch and update decisionsRetained with a version and a number,the record your reviewers already read.Records from before February 2, 2026 are in scope too.AUDIT-READY
One record feeds design verification, the risk file, CAPA, supplier controls and management review, without a second spreadsheet.
QMS area (CP 7382.850)What an investigator may askThe ELTON record
Design and Development: verification, validation, software validationThreat model coverage, and evidence that security requirements were verified on the shipped designDigital twin and MITRE EMB3D threat model; a test case per threat, traced to components and interfaces; executed results with logs
Risk management, read throughoutHow cybersecurity risks were identified, evaluated and controlled, and why residual risk is acceptableProduct-adjusted ratings on the qualified MDDT CVSS rubric; exploitability verified on the twin, in code and on the real device; written rationale per disposition
Measurement, Analysis and Improvement: complaints, feedback, CAPA, analysis of dataHow a reported vulnerability was evaluated, closed and trendedFinding lifecycle with statuses, Fixed and Not Affected closures and VEX reasons; retest evidence; three clocks per view
Outsourcing and PurchasingControl of software suppliers and third-party componentsSBOM components matched to the twin, CVEs dispositioned per release, SOUP tracked with the product
Change ControlEffect of a release on security postureEvery release retested against the record; findings tracked to a version and a number
Management Oversight: management review, medical device file, internal auditsMetrics top management reviews; audit findings, now inspectableLiving reports with per-view metrics (MTTT, MTTV, MTTM); the same record supplies internal audits and the medical device file
MDR, corrections and removalsWhether a vulnerability rose to a reportable event; patch and update decisionsIncident response from the record in hours, with the evidence behind the disposition and the update decision

Mapping is by QMS area, not a claim that each artifact is independently mandated. Which records satisfy which clause depends on the device and the quality system.

The statutory layer

Section 524B
runs underneath.

For cyber devices, the obligations are statute, not guidance.

Monitor, identify, address

A plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure. ELTON's postmarket record is that plan, running.

Cybersecure by process, patched on a cycle

Processes that provide reasonable assurance the device and related systems are cybersecure, with updates and patches on a regular cycle and out of cycle for critical vulnerabilities. That is section 524B(b)(2), the paragraph CP 7382.850 points investigators to.

SBOM

A software bill of materials covering commercial, open-source and off-the-shelf components. ELTON monitors it against the twin and dispositions every match, release by release.

Section 524B was added to the FD&C Act by the Consolidated Appropriations Act, 2023, signed December 29, 2022, and has applied to submissions since March 29, 2023.

Questions

Questions about
QMSR inspections.

Does QMSR require penetration testing?

No clause in QMSR says so, and this page does not claim it. What changed is that CP 7382.850 tells investigators to consider cyber devices for review against section 524B(b)(2) and to read risk management documentation throughout the inspection, so the evidence that design controls and risk management worked is what gets asked for. Executed test cases are that evidence.

Can FDA read our internal audits now?

Yes. FDA's QMSR FAQ states that the QMSR gives FDA the authority to inspect management review, quality audits and supplier audit reports; the section 820.180(c) exceptions were not carried into the QMSR. Audits that cover cybersecurity, vulnerability management, CAPA or software suppliers are in scope.

What is CP 7382.850?

FDA's compliance program Inspection of Medical Device Manufacturers, effective February 2, 2026. It replaced QSIT, supersedes CP 7382.845 and CP 7383.001, and describes a risk-based, total product life cycle inspection organized around six QMS areas and four other applicable FDA requirements.

Do records created before February 2, 2026 count?

Yes. FDA says investigators may review QMS records created before the effective date, and suggests a comparative analysis showing older records meet QMSR requirements. A continuous vulnerability record, retained by version, avoids the question.

What did the February 2026 cybersecurity guidance change?

FDA reissued Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions to align with QMSR, replacing QS regulation references with QMSR and ISO 13485 references. The core technical expectations did not change.

How does ELTON make vulnerability data inspection-ready?

Every finding is retained with its test case, product-adjusted rating, exploitability verdict and evidence, disposition and rationale, release and status history, remediation and retest, and view-relative clocks. An investigator reads the same record your reviewers did, and the record continues across releases and across the rule change.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo →
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Proof over ProbabilityExploitability VerificationFDA MDDTCVSSv4 MigrationQMSR Audit Compliance One SolutionSubscription TestingAI-NativeELTON vs. Legacy TestingThreat-Led AI PentestingCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionAI Inside the ProductCybersecurity TestingSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsData SecurityContact Meet ELTON →
See the graph decide, live →>