The medical device industry has seen two significant regulatory changes: FDA’s Section 524B cybersecurity requirements and the Quality Management System Regulation (QMSR). These changes affect how connected devices reach and stay on the market, and they rewrite the quality system rules that govern every device a company makes.
Section 524B applies to cyber devices, which include software, can connect to the internet, and have technological characteristics that could be vulnerable to cybersecurity threats. For these devices, a premarket submission must show a plan to monitor, identify, and address postmarket vulnerabilities, including a coordinated disclosure process.
Understanding the Requirements
The QMSR, which took effect on February 2, 2026, aligns FDA’s quality system requirements with the international standard ISO 13485 and folds risk management more deeply into the quality system. This change affects documentation, terminology, and the expectations around how a company demonstrates that its processes are controlled.
Read Also: Smarter Devices Drive Faster Evolution of Materiovigilance for Safety
Both changes touch four kinds of exposure a device maker already carries: cybersecurity exposure, product liability exposure, recall exposure, and management liability. A connected device that is compromised can trigger a product liability claim, a cyber claim, and a regulatory response tied to the postmarket obligations under 524B.
The postmarket duty raises the stakes further, as a company that knew about a vulnerability and did not act on it faces a very different claim than one that followed a documented response process. The paper trail becomes part of the liability picture, and strong process control, traceability, and risk documentation make a claim defensible.
Assessing the Impact
Many device makers are underinsured against the new baseline created by these changes. Cyber policies often exclude bodily injury, and product liability policies may not address software, firmware, and post-market updates. Recall coverage is frequently absent or set at a limit that reflects an earlier and smaller product footprint.
Underwriters are catching up to these changes, and device makers can expect to be asked for their software bill of materials, postmarket vulnerability management process, and coordinated disclosure plans. Companies that answer these questions well tend to place coverage on better terms, while those that cannot answer them may pay more for narrower coverage.
Read Also: Uganda ends Ebola outbreak after 42-day monitoring period
A company that has not updated its program to reflect 524B and QMSR may find that its coverage no longer satisfies the insurance schedule its customers require.
Management Liability and Investor Considerations
Directors and officers now face heightened exposure when regulatory or quality lapses lead to losses. The new rules increase the likelihood that oversight failures will be scrutinized by agencies, potentially triggering claims against senior executives. When a cybersecurity breach or a quality system deficiency results in patient injury, plaintiffs may allege that leadership did not implement adequate safeguards. Evidence of documented risk controls and timely response plans can be decisive in defending such actions.
Practical Steps for Aligning Policies and Contracts
Legal teams should audit existing agreements to verify that insurance clauses reflect the latest regulatory language. Hospital contracts frequently list specific coverage amounts for cyber incidents and product liability tied to software updates. Distributor and manufacturing contracts may also demand proof of a coordinated disclosure plan. Updating these provisions before a claim arises helps maintain bargaining power and prevents unexpected coverage gaps.
