The quick version for busy people:
FDA now aligns with ISO 13485.
One global quality system. Nice.Cybersecurity is now clearly part of the QMS.
Engineering and quality are about to spend more time together.Threat modeling, vulnerability management, and updates now live inside documented quality processes.
Not just engineering notes anymore.You may need to buy ISO 13485 to read it.
Regulatory harmonization apparently includes a shopping step.
So What Actually Changed?
The FDA’s new Quality Management System Regulation (QMSR) replaces the old Part 820 framework with a system based on ISO 13485:2016.
The goal is simple: align the U.S. with the rest of the world.
Most companies will barely notice the change in day-to-day engineering work. The device still needs to be secure. Software still needs to be maintained. Vulnerabilities still need to be managed.
For a more complete and entertaining description of the overall changes, my go-to person, Lisa Voronkova, has an excellent article here.
What does change is where cybersecurity lives organizationally.
Under the old system, cybersecurity often sat primarily with engineering. Teams handled threat modeling, vulnerability management, and update mechanisms, and then documented them when regulatory time came.
Under the new framework, cybersecurity is much more clearly tied to the Quality Management System itself.
That means activities like:
- threat modeling,
- vulnerability management,
- secure update processes,
- software lifecycle controls,
- and post-market monitoring
now fit directly into design controls, risk management, and post-market surveillance processes inside the QMS.
Translation: cybersecurity is no longer just an engineering activity. It is a quality system activity.
Quality teams and engineering teams are about to become even better friends.
The Small but Funny Surprise
There is also one small practical change that has caught a few startups off guard. Under the previous system, companies could read 21 CFR Part 820 online for free.
ISO standards work differently.
ISO 13485 is copyrighted, so companies usually need to purchase the standard to use it. It is not a massive cost, usually a couple of hundred dollars, but it does create a moment many founders recognize.
Someone eventually asks:
“Wait… do we actually have to buy the regulation?”
Not quite.
But you probably will buy the document that the regulation now points to.
The Bottom Line
From a cybersecurity perspective, the work itself has not changed much.
What has changed is that cybersecurity now sits squarely within the quality system rather than living mostly within engineering.
And somewhere along the way, someone will be approving a small purchase order for an ISO PDF.
Welcome to regulatory harmonization.