Course Description
Program Overview
This on-demand program provides a deep, practical understanding of how FDA regulates medical device software and cybersecurity, from first principles through the documentation a premarket submission requires. It is the full recorded masterclass, delivered as nine self-paced modules participants can watch on their own schedule and return to as often as needed.
The first modules build the software regulatory foundation: how FDA classifies device software and Software as a Medical Device, how risk drives the level of control, the Documentation Level FDA now expects, the software lifecycle under IEC 62304, risk management under ISO 14971, and how to decide when a change warrants a new submission. The later modules carry that same structure into cybersecurity, showing how threat modeling, security risk assessment, architecture, and controls align with FDA's current Cybersecurity Guidance, the Quality Management System Regulation (QMSR), Section 524B of the FD&C Act, and IMDRF principles.
Throughout, the lectures work through real examples and sample documentation, so participants finish able to recognise and assemble what FDA expects in a premarket submission, from the security risk management report through controls, architecture, and labeling, and to understand FDA's postmarket vulnerability response expectations.
Course at a Glance
PRE-RECORDED • ON-DEMAND
9 Expert-Led Video Modules
Approximately 6.5 Hours of Pre-Recorded Instruction
9 Expert-Led Video Modules
Learn at Your Own Pace
6-Month Course Access
Revisit the Modules Throughout Your Access Period
Price : $1195.00 USD
100% Online
Learn from Anywhere with a Stable Internet Connection
Certificate of Completion from CRTA
Complete the Modules and Final Knowledge Assessment
Faculty Director: Jordan John
Medical Device Software • Cybersecurity • FDA Compliance
Learning Objectives
By the end of this course, participants will be able to:
-
•
Distinguish device software functions and Software as a Medical Device from the software functions FDA does not actively regulate, and determine how a product is classified.
-
•
Apply FDA's risk framework and the current Documentation Level (Basic and Enhanced) to scope the software documentation a submission requires.
-
•
Prepare and assemble software documentation for 510(k), De Novo, and PMA submissions, including the software description, verification, and validation.
-
•
Apply the IEC 62304 software lifecycle and ISO 14971 risk management, and maintain the traceability FDA looks for.
-
•
Decide when a software change may require a new premarket submission rather than routine maintenance.
-
•
Apply Section 524B "cyber device" requirements and the Secure Product Development Framework (SPDF) to submission planning.
-
•
Build a threat model and cybersecurity risk assessment, and document security architecture and controls traceable to risk.
-
•
Prepare a Software Bill of Materials (SBOM) and the vulnerability management documentation FDA expects.
-
•
Prepare cybersecurity labeling, address interoperability, and apply controlled versus uncontrolled risk in postmarket vulnerability management, including coordinated vulnerability disclosure.
Who Should Attend
-
•
Regulatory Affairs and Quality Professionals
-
•
Software as a Medical Device (SaMD) and Digital Health Teams
-
•
Cybersecurity Specialists in MedTech
-
•
Software Developers and System Architects
-
•
Connected Device and Digital Health Innovators
-
•
FDA Submission and Compliance Teams
-
•
Risk Management and Product Security Leads
Course Outline
Module 1 - FDA Medical Device Software Regulation Foundations
• How FDA sorts the software universe: device software functions, Software as a Medical Device (SaMD), and the functions FDA does not actively regulate
• The shared risk vocabulary of severity and probability, and how risk drives the level of regulatory control
• Device classification (Class I, II, and III) and how it sets the evidentiary burden
• The current Documentation Level (Basic and Enhanced), and why the older "Level of Concern" language is retired
• Multiple-function device products, and the core documents that form the backbone of a software submission
Module 2 - Software Documentation and Premarket Submissions
• The three submission pathways (510(k), De Novo, and PMA), and how the pathway sets the burden of proof
• Substantial equivalence and what a predicate comparison must show
• The software documentation elements reviewers work from, and where real submissions fall thin
• Verification and validation, and the traceability that proves nothing fell through the cracks
• Using the Pre-Submission (Q-Sub) program to engage FDA early and specifically
Module 3 - Software Lifecycle and Change Management
• The IEC 62304 software lifecycle and where it sits within the quality system
• Requirements-to-testing traceability, the golden thread through the software file
• The four-question logic for deciding when a software change may need a new 510(k)
• Software documentation for AI and machine-learning-enabled devices, in current FDA terminology
• The Predetermined Change Control Plan (PCCP), its components, and supporting configuration management
Module 4 - Real-World Software Application and Risk Management
• The ISO 14971 risk management process applied end to end, and the risk management file
• The Quality Management System Regulation (QMSR), and how it differs from ISO 13485 alone
• Design controls and the design history file, and where teams most often get into trouble
• Verification and validation in practice
• The bridge from safety risk into security risk, where the same structure meets a new class of hazard
Module 5 - Cybersecurity Foundations and the Secure Product Development Framework
• The Secure Product Development Framework (SPDF), and why security is not a separate parallel process
• Section 524B of the FD&C Act, the "cyber device" definition, and FDA's authority to refuse to accept a submission
• The shape of the full cybersecurity submission, and where each document belongs
• Security risk management, and how it relates to but differs from safety risk management
Module 6 - Threat Modeling and Security Risk Assessment
• Why threat modeling matters, and the models the field reaches for, including STRIDE
• Mapping the system, its entry points, and its data flows
• The cybersecurity risk assessment: scoring exploitability and patient-harm severity, before and after controls
• The security risk management report, and the traceability a reviewer can follow from any threat to its evidence
Module 7 - Security Architecture and Controls
• The FDA-recommended security control categories, from authentication through firmware and software updates
• Turning the control categories into a design rather than a checklist
• Cybersecurity controls documentation, traceable to the risk assessment
• Security architecture views, and why the update mechanism draws particular FDA attention
Module 8 - SBOM and Vulnerability Management
• The Software Bill of Materials (SBOM): its recognised baseline elements and FDA's additions
• Vulnerability monitoring across the total product lifecycle, and planning for end of support
• The four kinds of cybersecurity testing FDA expects, seen as a progression
• Assessment of unresolved anomalies, and dispositioning each with reasoning
Module 9 - Labeling, Interoperability, and Postmarket Management
• Cybersecurity labeling: the security-relevant device description and the MDS2
• Interoperability, and documenting how the device connects to other systems
• Controlled versus uncontrolled risk, and evaluating the risk of patient harm
• Postmarket management: coordinated vulnerability disclosure, information sharing (ISAO), and when a change may require reporting
What Is Included
- •9 on-demand video modules, approximately 6.5 hours of instruction, available at your own pace
- •A reference list at the close of each module of the FDA guidance documents and standards covered
- •A key-takeaways summary at the end of every module