The February 3, 2026 guidance, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions — which supersedes the June 2025 version, which itself superseded the original September 2023 guidance most existing compliance content still cites — contains a subsection titled, verbatim,

Threat Modeling for FDA Premarket Medical Device Submissions

FDA doesn’t imply a threat model is expected.
It names the section “Threat Modeling.”

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

The Secure Product Development Framework is where PASTA fits

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

TMaaS for the TPLC obligation

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

What this doesn’t mean

Frequently Asked Questions

FDA’s guidance is nonbinding — it uses “should” to describe recommendations, not requirements. That said, the current guidance names threat modeling as a specific, recommended component of the security risk management report, and recommends premarket submissions include threat modeling documentation to demonstrate how the device system was analyzed for security risk.
Per the February 2026 guidance, a threat model should identify system risks and mitigations, state assumptions about the device’s environment of use (e.g., assuming hospital networks are inherently hostile), and capture risks introduced through the supply chain, manufacturing, deployment, interoperability, maintenance, and decommissioning.
Much of the available guidance content still references FDA’s original September 2023 guidance. FDA superseded that guidance in June 2025, and superseded that version again on February 3, 2026 — the version currently in effect.
FDA’s guidance recommends updating threat modeling and risk assessment documentation throughout the device’s total product lifecycle (TPLC), whenever new threats, vulnerabilities, or adverse impacts are identified — not only at the premarket stage.
No. FDA’s guidance is nonbinding, and premarket clearance decisions are based on FDA’s review of the complete submission. A threat model is one recommended component of the security risk management report, not a standalone basis for clearance.