The FDA says approval for medical devices now requires meeting certain cybersecurity standards issued in the omnibus spending bill signed in December 2022
The Food and Drug Administration affirmed Wednesday that medical device manufacturers must now prove their products meet certain …
Context & Ripple Effects
For six years the FDA's device cybersecurity posture was advisory: its 2016 guidelines laid out security recommendations but carried no enforcement power. Wednesday's announcement flips that lever — approval itself is now the enforcement mechanism, because manufacturers must demonstrate compliance with the cybersecurity provisions Congress wrote into the December 2022 omnibus spending bill before the agency clears their products.
The move lands mid-pattern rather than in isolation. Congress had already conditioned federal purchasing on baseline security through the [[a:960198|Senate-passed bill requiring internet-connected devices bought by the US government to meet NIST minimums]], and Brussels is pursuing the same territory with the EU's proposed Cyber Resilience Act, which pairs IoT security duties with fines. The FDA is extending that logic from procurement and penalties to the single gate every device maker must pass: regulatory clearance.
First-order effects
- Manufacturers with devices in the FDA pipeline must now produce evidence of compliance with the omnibus bill's cybersecurity standards as part of their submissions, or their clearances stall — security documentation becomes a premarket requirement rather than a post-market aspiration.
- Connected-device portfolios already cleared face no retroactive bar under this announcement, so incumbents gain a compliance moat over rivals still awaiting approval.
Second-order effects
- Device makers selling into both US and EU markets now juggle overlapping regimes — FDA approval conditions on one side, the Cyber Resilience Act's fine-backed rules on the other — creating pressure to engineer to the strictest baseline once rather than per-jurisdiction.
- Voluntary labeling schemes like the FCC's US Cyber Trust Mark risk being squeezed between a mandatory approval gate and consumer labels: if clearance requires the security posture anyway, the voluntary mark's differentiation value narrows.
Third-order effects
- If the pattern holds, cybersecurity shifts from best-practice guidance to a market-access condition enforced at every entry point — approval, procurement, and potentially liability — making sustained patchability a structural cost of selling connected hardware in regulated markets rather than a differentiator.
- The convergence of the FDA gate, the government-purchasing NIST mandate, and the EU's fines-based regime points toward de facto harmonized IoT security baselines, with multinational manufacturers setting product architecture to satisfy the toughest regulator first.
The trend: Regulators are converting IoT and medical-device security from voluntary guidance into hard market-access conditions, with approval gates, procurement mandates, and fine-backed statutes advancing in parallel across the US and EU.