Us Code § 360n - –2. Ensuring cybersecurity of devices

Full text of Us Code United States Code § 360n — –2. Ensuring cybersecurity of devices, with citation guidance and answers to common questions.

§ 360n. –2. Ensuring cybersecurity of devices

(a) In general

A person who submits an application or submission under section 360(k), 360c, 360e(c), 360e(f), or 360j(m) of this title for a device that meets the definition of a cyber device under this section shall include such information as the Secretary may require to ensure that such cyber device meets the cybersecurity requirements under subsection (b).

(b) Cybersecurity requirements

The sponsor of an application or submission described in subsection (a) shall—

(1) submit to the Secretary a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures;

(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;


(3) provide to the Secretary a software bill of materials, including commercial, open-source, and off-the-shelf software components; and

(4) comply with such other requirements as the Secretary may require through regulation to demonstrate reasonable assurance that the device and related systems are cybersecure.

(c) Definition

In this section, the term "cyber device" means a device that—

(1) includes software validated, installed, or authorized by the sponsor as a device or in a device;

(2) has the ability to connect to the internet; and

(3) contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats.

(d) Exemption

The Secretary may identify devices, or categories or types of devices, that are exempt from meeting the cybersecurity requirements established by this section and regulations promulgated pursuant to this section. The Secretary shall publish in the Federal Register, and update, as appropriate, a list of the devices, or categories or types of devices, so identified by the Secretary.

(June 25, 1938, ch. 675, §524B, as added Pub. L. 117–328, div. FF, title III, §3305(a), Dec. 29, 2022, 136 Stat. 5832.)


Statutory Notes and Related Subsidiaries

Effective Date

Section effective 90 days after Dec. 29, 2022, see section 3305(d) of Pub. L. 117–328, set out as an Effective Date of 2022 Amendment note under section 331 of this title.

Construction

Nothing in section 3305(a) of Pub. L. 117–328, which enacted this section, to be construed to affect the Secretary's of Health and Human Services authority related to ensuring that there is a reasonable assurance of the safety and effectiveness of devices, which may include ensuring that there is a reasonable assurance of the cybersecurity of certain cyber devices, including for devices approved or cleared prior to Dec. 29, 2022, see section 3305(c) of Pub. L. 117–328, set out as a Construction of 2022 Amendment note under section 331 of this title.

Guidance for Industry and FDA Staff on Device Cybersecurity

Pub. L. 117–328, div. FF, title III, §3305(e), Dec. 29, 2022, 136 Stat. 5833, provided that: "Not later than 2 years after the date of enactment of this Act [Dec. 29, 2022], and periodically thereafter as appropriate, the Secretary [of Health and Human Services], in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall review and, as appropriate and after soliciting and receiving feedback from device manufacturers, health care providers, third-party-device servicers, patient advocates, and other appropriate stakeholders, update the guidance entitled 'Content of Premarket Submissions for Management of Cybersecurity in Medical Devices' (or a successor document)."

[For definition of "device" as used in section 3305(e) of Pub. L. 117–328, set out above, see section 321(h) of this title, as made applicable by section 3305(h) of Pub. L. 117–328, which is set out below.]

Resources Regarding Cybersecurity of Devices

Pub. L. 117–328, div. FF, title III, §3305(f), Dec. 29, 2022, 136 Stat. 5834, provided that: "Not later than 180 days after the date of enactment of this Act [Dec. 29, 2022], and not less than annually thereafter, the Secretary [of Health and Human Services] shall update public information provided by the Food and Drug Administration, including on the website of the Food and Drug Administration, with information regarding improving cybersecurity of devices. Such information shall include information on identifying and addressing cyber vulnerabilities for health care providers, health systems, and device manufacturers, and how such entities may access support through the Cybersecurity and Infrastructure Security Agency and other Federal entities, including the Department of Health and Human Services, to improve the cybersecurity of devices."

[For definition of "device" as used in section 3305(f) of Pub. L. 117–328, set out above, see section 321(h) of this title, as made applicable by section 3305(h) of Pub. L. 117–328, which is set out below.]

Definition

Pub. L. 117–328, div. FF, title III, §3305(h), Dec. 29, 2022, 136 Stat. 5834, provided that: "In this section [enacting this section, amending section 331 of this title, and enacting provisions set out as notes under this section and section 331 of this title], the term 'device' has the meaning given such term in section 201(h) of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 321(h))."

Part B—Drugs for Rare Diseases or Conditions

About This Section

21 U.S.C. § 360n is part of Title 21 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 21 U.S.C. § 360n. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Frequently Asked Questions About Us Code § 360n

What does United States Code § 360n cover?

Section 360n ("–2. Ensuring cybersecurity of devices") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 360n?

A common citation format is "United States Code § 360n" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 360n apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.