FDA Secure Product Development Framework (SPDF): Requirements And 2026 Implementation Guid

A threat model, SBOM, penetration test, and cybersecurity plan can all be part of an FDA submission. None of them, by themselves, is an SPDF.

That distinction matters because the Secure Product Development Framework (SPDF) is much broader. It brings cybersecurity into the processes used to design, develop, release, maintain, and eventually retire a medical device, so security is managed as part of the product lifecycle rather than assembled only for regulatory review.

FDA reinforced this approach in its February 2026 cybersecurity guidance, which replaced the June 27, 2025 version.

In this guide, we explain what FDA expects from an SPDF, how it connects with development and cybersecurity activities, and what medical device manufacturers need to address when implementing it in 2026.

Key Takeaways

A strong SPDF is built into everyday product decisions instead of being assembled when the submission is nearly complete.
The framework works best when security ownership, risk analysis, engineering controls, testing, and follow-up remain connected across teams.
FDA gives manufacturers flexibility in how they organize SPDF activities, but the approach still needs to fit the device’s actual risk and quality processes.
Evidence matters as much as design intent. Manufacturers need to show how identified risks were addressed and how implemented controls were checked.
Cybersecurity responsibility continues after launch. New vulnerabilities, aging components, software updates, and eventual product retirement all need ongoing attention.

Source: https://qualysec.com/fda-spdf/
New York, Technical, FDA Secure Product Development Framework (SPDF): Requirements And 2026 Implementation Guid
Belakang Seterusnya