img

FDA Medical Device Software & Cybersecurity Regulatory Masterclass

Course Description

Program Overview


This on-demand program provides a deep, practical understanding of how FDA regulates medical device software and cybersecurity, from first principles through the documentation a premarket submission requires. It is the full recorded masterclass, delivered as nine self-paced modules participants can watch on their own schedule and return to as often as needed.


The first modules build the software regulatory foundation: how FDA classifies device software and Software as a Medical Device, how risk drives the level of control, the Documentation Level FDA now expects, the software lifecycle under IEC 62304, risk management under ISO 14971, and how to decide when a change warrants a new submission. The later modules carry that same structure into cybersecurity, showing how threat modeling, security risk assessment, architecture, and controls align with FDA's current Cybersecurity Guidance, the Quality Management System Regulation (QMSR), Section 524B of the FD&C Act, and IMDRF principles.


Throughout, the lectures work through real examples and sample documentation, so participants finish able to recognise and assemble what FDA expects in a premarket submission, from the security risk management report through controls, architecture, and labeling, and to understand FDA's postmarket vulnerability response expectations.

Course at a Glance

PRE-RECORDED • ON-DEMAND
9 Expert-Led Video Modules

Approximately 6.5 Hours of Pre-Recorded Instruction

9 Expert-Led Video Modules

Learn at Your Own Pace

6-Month Course Access

Revisit the Modules Throughout Your Access Period

Price : $1195.00 USD
location Created with Sketch Beta.
100% Online

Learn from Anywhere with a Stable Internet Connection

certificate-ribbon-solid
Certificate of Completion from CRTA

Complete the Modules and Final Knowledge Assessment

Faculty Director: Jordan John
Medical Device Software • Cybersecurity • FDA Compliance

Learning Objectives

By the end of this course, participants will be able to:

  • Distinguish device software functions and Software as a Medical Device from the software functions FDA does not actively regulate, and determine how a product is classified.
  • Apply FDA's risk framework and the current Documentation Level (Basic and Enhanced) to scope the software documentation a submission requires.
  • Prepare and assemble software documentation for 510(k), De Novo, and PMA submissions, including the software description, verification, and validation.
  • Apply the IEC 62304 software lifecycle and ISO 14971 risk management, and maintain the traceability FDA looks for.
  • Decide when a software change may require a new premarket submission rather than routine maintenance.
  • Apply Section 524B "cyber device" requirements and the Secure Product Development Framework (SPDF) to submission planning.
  • Build a threat model and cybersecurity risk assessment, and document security architecture and controls traceable to risk.
  • Prepare a Software Bill of Materials (SBOM) and the vulnerability management documentation FDA expects.
  • Prepare cybersecurity labeling, address interoperability, and apply controlled versus uncontrolled risk in postmarket vulnerability management, including coordinated vulnerability disclosure.

Who Should Attend

  • Regulatory Affairs and Quality Professionals
  • Software as a Medical Device (SaMD) and Digital Health Teams
  • Cybersecurity Specialists in MedTech
  • Software Developers and System Architects
  • Connected Device and Digital Health Innovators
  • FDA Submission and Compliance Teams
  • Risk Management and Product Security Leads

Course Outline

Module 1 - FDA Medical Device Software Regulation Foundations

How FDA sorts the software universe: device software functions, Software as a Medical Device (SaMD), and the functions FDA does not actively regulate

The shared risk vocabulary of severity and probability, and how risk drives the level of regulatory control

Device classification (Class I, II, and III) and how it sets the evidentiary burden

The current Documentation Level (Basic and Enhanced), and why the older "Level of Concern" language is retired

Multiple-function device products, and the core documents that form the backbone of a software submission

Module 2 - Software Documentation and Premarket Submissions

The three submission pathways (510(k), De Novo, and PMA), and how the pathway sets the burden of proof

Substantial equivalence and what a predicate comparison must show

The software documentation elements reviewers work from, and where real submissions fall thin

Verification and validation, and the traceability that proves nothing fell through the cracks

Using the Pre-Submission (Q-Sub) program to engage FDA early and specifically

Module 3 - Software Lifecycle and Change Management

The IEC 62304 software lifecycle and where it sits within the quality system

Requirements-to-testing traceability, the golden thread through the software file

The four-question logic for deciding when a software change may need a new 510(k)

Software documentation for AI and machine-learning-enabled devices, in current FDA terminology

The Predetermined Change Control Plan (PCCP), its components, and supporting configuration management

Module 4 - Real-World Software Application and Risk Management

The ISO 14971 risk management process applied end to end, and the risk management file

The Quality Management System Regulation (QMSR), and how it differs from ISO 13485 alone

Design controls and the design history file, and where teams most often get into trouble

Verification and validation in practice

The bridge from safety risk into security risk, where the same structure meets a new class of hazard

Module 5 - Cybersecurity Foundations and the Secure Product Development Framework

The Secure Product Development Framework (SPDF), and why security is not a separate parallel process

Section 524B of the FD&C Act, the "cyber device" definition, and FDA's authority to refuse to accept a submission

The shape of the full cybersecurity submission, and where each document belongs

Security risk management, and how it relates to but differs from safety risk management

Module 6 - Threat Modeling and Security Risk Assessment

Why threat modeling matters, and the models the field reaches for, including STRIDE

Mapping the system, its entry points, and its data flows

The cybersecurity risk assessment: scoring exploitability and patient-harm severity, before and after controls

The security risk management report, and the traceability a reviewer can follow from any threat to its evidence

Module 7 - Security Architecture and Controls

The FDA-recommended security control categories, from authentication through firmware and software updates

Turning the control categories into a design rather than a checklist

Cybersecurity controls documentation, traceable to the risk assessment

Security architecture views, and why the update mechanism draws particular FDA attention

Module 8 - SBOM and Vulnerability Management

The Software Bill of Materials (SBOM): its recognised baseline elements and FDA's additions

Vulnerability monitoring across the total product lifecycle, and planning for end of support

The four kinds of cybersecurity testing FDA expects, seen as a progression

Assessment of unresolved anomalies, and dispositioning each with reasoning

Module 9 - Labeling, Interoperability, and Postmarket Management

Cybersecurity labeling: the security-relevant device description and the MDS2

Interoperability, and documenting how the device connects to other systems

Controlled versus uncontrolled risk, and evaluating the risk of patient harm

Postmarket management: coordinated vulnerability disclosure, information sharing (ISAO), and when a change may require reporting

What Is Included
  • 9 on-demand video modules, approximately 6.5 hours of instruction, available at your own pace
  • A reference list at the close of each module of the FDA guidance documents and standards covered
  • A key-takeaways summary at the end of every module
Jordan John, H.BSc, RAC, MBA
Faculty Director’s Bio:

Jordan John, H.BSc, RAC, MBA

Distinguished Expert in Regulatory Affairs, Quality Management, and Cybersecurity

Jordan John is a recognized leader in regulatory affairs, quality management, and cybersecurity compliance, with over a decade of experience navigating complex regulatory landscapes in medical devices, pharmaceuticals, natural health products (NHPs), and other industries. He has held leadership roles, including Director of Regulatory Affairs, Director of Quality, and Security Officer, ensuring compliance with FDA, EU MDR/IVDR, Health Canada, TGA, PMDA, and other international regulatory frameworks.

As an Advisory Board Member at Humber College, Jordan provides strategic insights into clinical regulatory and compliance education. He has also served as a Professor at leading academic institutions, where he developed and delivered courses in regulatory affairs, quality assurance, and compliance. His industry experience spans top tier biopharmaceutical and medical device companies, including Stryker, Johnson & Johnson, Fio Corporation, Southmedic, and others.

With a deep understanding of global regulatory requirements and industry best practices, Jordan is committed to advancing education and training, ensuring the highest standards of quality, safety, and compliance in regulated industries

Become Our Faculty Director Today

Be part of a global network of virtual and in-person workshops

Global Pharma companies and CROs employing our graduates

Global Pharma companies and CROs
employing our graduates