
...an SPDF is one approach to help ensure that the QS regulation is met. Because of its benefits in helping comply with the QS regulation and cybersecurity, FDA encourages manufacturers to use an SPDF, but other approaches might also satisfy the QS regulation.
### B. Designing for Security
When reviewing premarket submissions, FDA intends to assess device cybersecurity based on a number of factors, including, but not limited to, the device's ability to provide and implement the security objectives below throughout the device architecture.
Security Objectives: • Authenticity, which includes integrity • Authorization • Availability • Confidentiality • Secure and timely updatability and patchability
...The risks presented by cybersecurity vulnerabilities; the exploitability of the vulnerabilities; and the risk of patient harm due to vulnerability exploitation.
### C. Transparency
A lack of cybersecurity information, such as information necessary to integrate the device into the use environment...[truncated — chunk continues across §C]
• The device's intended use, indications for use, and reasonably foreseeable misuse;
• The presence and functionality of its electronic data interfaces;
• Its intended and actual environment of use;18
• The risks presented by cybersecurity vulnerabilities;
• The exploitability of the vulnerabilities; and
• The risk of patient harm due to vulnerability exploitation.
Cybersecurity Guidance for Medical Devices
└ Guidance for Industry and FDA Staff
└ B. Designing for Security
└ The extent to which security requirements, architecture, supply chain, and implementation are needed to meet these objectives will depend on but may not be limited to:
└ Its intended and actual environment of use:
└ The risk of patient harm due to vulnerability exploitation.

{
"mcpServers": {
"poma-grill": {
"command": "npx",
"args": ["-y", "@poma-ai/poma-grill-mcp", "-input", "-"],
"env": { "POMA_API_KEY": "poma_prod_gr_..." }
}
}
}{
"mcpServers": {
"poma-grill": {
"type": "http",
"url": "https://mcp.poma-ai.com/grill/v1",
"headers": { "x-api-key": "poma_prod_gr_..." }
}
}
}