The US Food and Drug Administration (FDA) issued its current medical-device cybersecurity guidance in February 2026, replacing a version published in June 2025. The revision explains how manufacturers can document security design and meet statutory duties that have applied to defined cyber devices since March 29, 2023.
Taiwan's Food and Drug Administration, the health ministry agency responsible for medical-product oversight, publishes a 2021 manufacturer guide and five assessment templates. Those materials cover design, registration and post-market maintenance, but their legal footing differs from the minimum submission duties written into US law.
Device security is narrower than hospital IT security
Medical-device cybersecurity concerns software, firmware and communications that are part of a regulated device or its connected system. The risks include unauthorized commands, altered clinical data, unavailable functions and vulnerable third-party components. A hospital scheduling platform or general records database presents serious security issues too, but it is not automatically a medical device.
Taiwan's English-language guidance applies to manufacturers of devices containing software or programmable logic and to medical-device software, while excluding hospital administration software, general health-management software and medication-record software from its scope. The guide treats confidentiality, integrity and availability as device-safety concerns when a failure could impair performance or expose protected information.
The boundary does not mean devices operate independently of hospital networks. Cloud services, wireless links, maintenance tools and integration software can all sit inside the device system. A security assessment therefore has to trace interfaces and dependencies instead of checking only the hardware at the bedside.
US law sets minimum duties for defined cyber devices
Section 524B of the US Federal Food, Drug, and Cosmetic Act applies when a product meets three conditions: it contains sponsor-authorized software, can connect to the internet and has technological characteristics that could be vulnerable to cyber threats. The FDA says the rule covers specified premarket submissions for those cyber devices and has applied to submissions filed since March 29, 2023.
The same law requires three minimum elements. A sponsor must submit a plan for monitoring and addressing post-market vulnerabilities, maintain processes that provide reasonable assurance of cybersecurity and make updates and patches available, and provide a software bill of materials (SBOM) covering commercial, open-source and off-the-shelf components.
The FDA's filing process is more precise than a claim that every incomplete package is immediately rejected. The agency says a 510(k) filed through its eSTAR system will be placed on technical-screening hold when the cybersecurity section lacks accurate responses or relevant attachments. The separate transition policy that delayed refuse-to-accept decisions expired on October 1, 2023.
The FDA's February 2026 guidance supersedes its June 2025 document and recommends evidence covering device design, labeling and premarket review. The underlying statutory obligations remain distinct from the agency's broader, nonbinding recommendations.
The recommended evidence connects threat models, architecture diagrams, risk assessments, testing, component support information and unresolved software anomalies. It also extends beyond market entry: management plans address vulnerability monitoring, coordinated disclosure, patch-development timelines, update delivery and communication with customers.
An SBOM is an inventory, not a security verdict
An SBOM records the software components and dependencies inside a device. When a library vulnerability is disclosed, manufacturers and health-care providers can use that inventory to identify products containing the affected component rather than searching every device from scratch.
The inventory still needs context. A listed component may not expose the vulnerable function, a compensating control may reduce the risk, or the component may sit on a path that an attacker cannot reach. Conversely, a complete component list does not reveal a design flaw in code written specifically for the device.
The International Medical Device Regulators Forum's April 2023 final document says an SBOM can help health-care providers identify obsolete components before purchase and manage vulnerabilities after deployment, but it is not a substitute for a comprehensive device-level security risk assessment. The forum is a group of medical-device regulators; its document supplies an international practice framework rather than one country's market authorization.
Taiwan publishes lifecycle guidance and five templates
Taiwan's regulator issued its manufacturer guidance in April 2021 and announced the English version on May 5. It asks manufacturers to address cybersecurity from product design and development through registration, post-market monitoring and the end of support. The document covers threat modeling, risk controls, security testing, an SBOM, labeling, disclosure and updates.
The Chinese original describes the document as administrative guidance and says reviewers may request additional verification material based on a product's software architecture and design. The English translation says it is for reference only and that the Chinese text prevails, which limits how confidently an English-only comparison can characterize Taiwan's legal requirements.
On December 6, 2021, the regulator published one general assessment template and four product-specific templates covering an implantable pacemaker pulse generator, a glucose test system, oxygen-saturation software and a cloud electrocardiogram management system. The page records a maintenance date of June 10, 2022 and describes the documents as references for preparing cybersecurity assessments.
The list should not be read as a five-device whitelist. A product outside those examples can still present cybersecurity risk, and a completed form does not prove that a device will pass registration. The guidance expressly leaves room for reviewers to ask for evidence suited to a product's architecture.
APPI News could not find public Taiwan statistics showing how often cybersecurity material leads to a request for more evidence, a delay or a refusal. The cited documents establish what guidance and templates are available; they do not support a measured comparison of enforcement outcomes with the United States.
Procurement has to test the maintenance promise
Premarket documentation captures a product at one point in time, while software dependencies continue to change. A useful procurement record therefore identifies the SBOM format, component support dates, the manufacturer's vulnerability contact, the patch process and the conditions under which a device reaches end of support.
The deployment plan matters as much as the document list. Hospitals need to know which network services a device requires, how it authenticates updates, whether logs can be monitored, what happens when cloud access fails and how a faulty update can be rolled back. Those questions connect device security to the surrounding network without treating every hospital IT incident as proof of a device exploit.
The published US and Taiwan materials converge on lifecycle risk management, threat modeling, software transparency and post-market maintenance. They diverge in legal form and filing mechanics. That distinction can be documented from primary sources, while comparative rejection rates and real-world security outcomes remain unverified.
Frequently asked questions
Does an SBOM prove that a medical device is secure?
No. It identifies software components and supports vulnerability triage, but exploitability, system architecture, controls and possible patient harm still require a separate assessment.
Do the US requirements apply to every medical device?
No. Section 524B applies to submissions for products that meet the US statutory definition of a cyber device. The FDA's broader guidance also discusses devices with cybersecurity risk, so the scope of a recommendation and the scope of the statute are not identical.
Do Taiwan's five templates cover every connected device?
No. The regulator labels them reference templates: one is general and four address named product types. Its guidance also allows reviewers to request evidence based on the architecture and design of a particular product.
Sources and further reading
- Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions(US Food and Drug Administration)
- Cybersecurity in Medical Devices Frequently Asked Questions(US Food and Drug Administration)
- Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity(International Medical Device Regulators Forum)
- Guidance for Industry on Management of Cybersecurity in Medical Devices(Taiwan Food and Drug Administration)English translation for reference; the Chinese version prevails
- Medical device cybersecurity assessment reference templates(Taiwan Food and Drug Administration)Chinese-language primary source
- Medical device cybersecurity guidance for manufacturers(Taiwan Food and Drug Administration)Chinese original; identifies the document as administrative guidance