FDA medical-device cybersecurity
45 scoped preparation workpapers and 90 evidence review actions
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
No explicit technical test mapping is listed for this framework in the checked C32 mapping files. Use its evidence workpapers and manual review workflow; do not assume a scanner result covers these requirements.
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
Medical-device product and submission preparation using FDA's February 2026 nonbinding recommendations and the identified section 524B statutory duties. Scope depends on device, submission and modification. This is not FDA clearance, QMSR certification, a licensed ISO/IEC catalog, or a substitute for device-specific safety and security testing. General host scans do not validate a medical device. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.