Two regulatory changes have landed close together, and together they reset what adequate protection means for a medical device company. FDA’s Section 524B cybersecurity requirements now govern how connected devices reach and stay on the market. The Quality Management System Regulation, which took effect on February 2, 2026, rewrites the quality system rules that sit underneath every device a company makes.
What Cyber Devices Must Now Prove
Section 524B of the Federal Food, Drug, and Cosmetic Act applies to cyber devices, which the statute defines broadly. A cyber device is one that includes software, can connect to the internet, and has technological characteristics that could be vulnerable to cybersecurity threats. For those devices, a premarket submission has to show a plan to monitor, identify, and address postmarket vulnerabilities, including a coordinated disclosure process.
It has to show that the device and the systems it connects to are reasonably secure. And it has to make security updates and patches available on a regular cycle, supported by a software bill of materials that lists the components inside the device. FDA has authority to refuse submissions that do not meet these requirements.
The important word is postmarket. 524B is not a one-time gate at clearance. It creates an ongoing obligation to watch for vulnerabilities and respond to them for as long as the device is in use. That ongoing duty is where the risk lives, because it means a company’s exposure does not end when the product ships. It follows the device into the field.
A New Quality System Standard
The Quality Management System Regulation replaced the older Quality System Regulation and took effect on February 2, 2026. It aligns FDA’s quality system requirements with the international standard ISO 13485 and folds risk management more deeply into the quality system. In practice it changes documentation, terminology, and the expectations around how a company demonstrates that its processes are controlled. For companies already certified to ISO 13485, much of the work is reconciliation. For companies that built their quality system around the older regulation, it is a genuine transition, and the transition itself is a moment when gaps surface.
Read Also: How AI is uncovering hidden truths in medical device development
The two changes touch four kinds of exposure a device maker already carries. Cybersecurity exposure is the most visible, but the others are no less significant. A connected device that is compromised does not produce a tidy, single-category claim. Consider a monitoring device that feeds data into a hospital network. A vulnerability in that device that leads to patient harm can trigger a product liability claim.
The same event can trigger a cyber claim for the data and network side, and a regulatory response tied to the postmarket obligations under 524B. The postmarket duty raises the stakes further. A company that knew about a vulnerability and did not act on it faces a very different claim than one that followed a documented response process. The paper trail becomes part of the liability picture.
How New Rules Change Liability
Product liability exposure is sharpened by the QMSR. When a claim alleges a defect, the company’s quality records are the defense. Strong process control, traceability, and risk documentation make a claim defensible. Gaps in the quality system make the same claim harder to defend and more expensive to resolve. Under QMSR, the quality system is not just a compliance artifact. It is evidence, and the quality of that evidence often decides how a claim resolves. This creates a tension that is hard to ignore. The regulations have raised the bar for what companies must document, but many insurance policies were written for an older world where documentation was a checkbox rather than a defense.
Where Device Makers Are Underinsured Against The New Baseline
The most common problem is a mismatch between how the risk now behaves and how the policies were written. Many cyber policies were built around data breach and network events, and they exclude bodily injury. A connected device that harms a patient through a security failure can fall into the gap between a cyber policy that excludes bodily injury and a product liability policy that was not written with software in mind. Neither policy clearly answers the claim, and the company discovers the gap at the worst possible moment.
Product liability policies often do not address software, firmware, and the post-market updates that 524B now requires a company to push. A device that changes after it ships, through a patch or an update, is a different risk than a device that is fixed at the point of sale. Policy language written for the second kind of device can leave the first kind exposed, and the update obligation under 524B guarantees that many devices now change after they ship.
Read Also: FDA Solicits Public Input on Generative AI Medical Devices
Recall coverage is frequently absent, or set at a limit that reflects an earlier and smaller product footprint. Retroactive dates and claims-made structures can leave prior acts outside the policy that is in force when a claim finally arrives. The theme is consistent. The regulations moved the risk. In many programs, the policy language did not move with them.
What Underwriters Are Asking For, And How Contracts Fit
What Insurers Will Ask Next
Underwriting is catching up to both changes, and the questions are becoming more specific. A device maker preparing for a review or renewal should expect to be asked for its software bill of materials and its postmarket vulnerability management process. Expect questions about coordinated disclosure, patch cadence, and incident response. Expect to be asked whether the quality system is aligned with ISO 13485 and how risk management is documented. Expect questions about recall planning and any prior field actions.
The companies that answer these questions well tend to place coverage on better terms, because the answers are evidence of a controlled risk. The companies that cannot answer them are harder to place and pay more for narrower coverage.
Contracts sit alongside the underwriting. Hospital agreements, distributor agreements, and contract manufacturing relationships almost always specify insurance requirements, and those requirements are written by parties who are paying attention to the same regulatory changes. A company that has not updated its program to reflect 524B and QMSR can find that its coverage no longer satisfies the insurance schedule its customers require. Reading those requirements before signing, rather than after a claim, is where a company keeps its leverage.
