No status read is recorded for this entry — this record has not read a publisher surface for it, which is a fact about this record and not about the publisher. A status read is recorded for 7 of
132 tracked entries, 5 of
which banked a passage.
Verification what a person or
a tool has confirmed here, and when
Publisher: US Food and Drug AdministrationLast checked:not yet verifiedLast read:
Evidence state what this
record holds
not currently retrievable — no retrieval of the document this entry names has produced a digest
How this status is recorded
Recorded
superseded — no as-of date is recorded
Established by
Read from the source by tooling on 7 September 2026.
No person confirmed it. A further check by
a person is
asserted on this row and the verification log does not corroborate
that further check, which counts toward no verified total.
Filed core. For that label this archive undertakes to put an entry's status to a person. The label records what this archive undertakes for a class of entries. It states no finding about this one, and it is not a ranking.
Read from the source by tooling, not confirmed by a person. This publisher states no status a machine can read; the value comes
from the document's own text. It is excluded from the "verified by a
person" count on the tracker.
Resolution: direct document
What this archive can and cannot establish about this entry. What this row hashes is the successor's page. All 49 observation records ask the URL recorded above — FDA's June 2025 slug, `cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions` — and all 49 record `redirected: true` with a `final_url` at FDA's February 2026 page, `cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket` (40 bare, 9 carrying a tracking query string). One digest covers all 49, and it is the same digest `fda-device-cybersecurity-2026` carried on its first 24 records, 2026-07-31 to 2026-08-08, before those records were re-scoped to that entry. FDA's structured guidance index holds no row for the URL recorded here — read 2026-08-25 at the retained-index rung of this row's retrieval ladder and recorded there as no statement about this document rather than a statement of none. The 2026-08-08 correction entry for `fda-device-cybersecurity-2026` states that this entry's referent problem stays open and that it needs either its own surface or a ruling. The question is filed and open; no ruling is recorded, so nothing here says whether following the redirect is a defect or a deliberate choice. This account states what the record holds and does not settle that. Account written 2026-08-25; this row carried none before.
The dated facts this record holds for this entry. Each line below states
what one kind of dated fact amounts to here, and links to the list holding
it where this entry has one; the list carries the dates, the words and the
addresses they were read from. Nothing is counted twice: where a line
states a number, the section it names states none.
—No publisher-dated calendar entry is recorded
for this entry.
—No revision has been detected for this entry.
Detection is this record’s own act rather than a
publisher’s statement, so its absence says nothing about
whether the document moved.
—No archived version of this entry is
held.
—No difference between two versions of this
entry is published.
Change history —
2 entry(ies) in this record’s own
changelog, each dated by the day this record acted.
Every dated reading of this entry — the day, the address that
answered, the response and the digest — is in Observation history below, which
states its own counts.
What is not published. This build serves 3 address(es) holding
a time-ordered list for an entry — a TimeMap in JSON, its
link-format sibling and an index — each expanding to one
document per tracked entry. What they list is CAPTURES of this
entry’s source held at a web archive, carrying that
archive’s own capture instants; this record serves no copy of
a tracked document, so none of those addresses is one of this
record’s, and a capture address is published only where the
terms filing recorded for the source host permits it. This
entry’s own is at /api/v1/timemap/fda-device-cybersecurity.json.
The route set naming them, and what each one answers, is published
at /developers.
— status change (unknown → superseded) correction: this row's status is superseded and its document series is ended. Every observation it made was of the successor document; the successor row holds the one series.
— archive metadata change (no account — the successor's digest rendered under the June 2025 edition's title → an account naming what the series hashes and recording that the referent question stays open) correction: this entry hashes the February 2026 successor's page, not its own. It now carries an account of what it tracks; the referent question stays open and is not settled here.
What sits around this entry, counted. Every figure below is drawn from a
value already rendered elsewhere on this page; where a count has a list,
the count is here and the list stays in the section holding its evidence.
The direct document, and the activity around it what this record’s observations of
the document recorded inside a stated window, beside the official
signals dated inside the same one
—This entry holds no observation of the
document it names, so no window can be marked either way. What
its series does hold is in Observation history
below.
Around it official signals naming this entry, by
the class their publisher stated
—The signal store holds no record for any
entry, so nothing here is an absence measured on this one. The
store’s own state is attempted not written, and what
that state means for every count drawn from the store is stated
at the signals index.
Related sources other entries reachable from this one by
a relation a publisher states
0 relation(s) this entry’s own publisher
states, 5 citation edge(s) out of its retained
text and 0 into it. They reach
5 other entry(ies) this record
tracks.
Each one is listed with the words that state it and the
address they were read from, in the section holding it below.
Related standards which of those entries call themselves a
standard, in their own publisher’s word
Of the 5 entry(ies) reached,
3 carry their
publisher’s word for a consensus standard,
1 state another class and
1 state none. A related entry is counted as a standard only where that entry’s own record carries the publisher’s word for it, quoted and cited on that entry’s page. Nothing is read from a designator: a title containing the letters of a standards body is not a publisher calling a document a standard. Where an entry states no class, it is counted as stating none rather than as not being one.
Topics the controlled identifiers this entry
carries, and the voice each one is in
2 identifier(s), minted by the convention
published at /conventions. The values
themselves are not listed again here; what this adds is the
identifier and the voice it is in.
2 come(s) from a term
this document’s own publisher states about it, quoted
with its citation lower on this page: topic.cybersecurity · topic.medical-devices.
Before, now and next where the record’s day sits among
the publisher-dated facts this entry holds
— This entry holds no publisher-dated lifecycle fact, so no position can be derived. What is absent is a dated statement this record has read.
Next holds the publisher-dated facts this record already carries that fall after the day this record calls today — a stated effective date, a consultation close. Nothing is projected and no step is inferred from a lifecycle: where a publisher has stated no further date, the cell says so, and what is absent is a statement rather than a future.
Subject and class (as stated)
The words this document uses about itself, matched verbatim against its
own title. Not a statement of scope, and not a judgment about which
organisations or products fall under it: each value quotes the span it
was read from and links to where that span was read.
This document does not call itself a regulation, a guidance or a
standard, so no class is recorded. It is filed under
title states no class.
Citations (within the tracked corpus)
One document's retained text contained a form another document is
published under, on the date shown, with the words it was read from. An
edge cannot tell the manner of a citation — a document naming
another in order to exclude it produces the same entry as one adopting
it.
NIST CSF 2.0as “NIST Cybersecurity Framework” generally referred to as the NIST Cybersecurity Framework or NIST CSF.25 FDA recommends thatsource↗ (opens in new tab) fda.gov · read
NIST SP 800-82as “NIST SP 800-82” Life Cycle Processes. 102Definition is cited from NIST SP 800-82 Guide to Operational Technologysource↗ (opens in new tab) fda.gov · read
IEC 62443as “ISA-62443” Health IT Joint Security Plan version 2 (JSP2). 27ANSI/ISA-62443-4-1 Security for industrial automation andsource↗ (opens in new tab) fda.gov · read
ISO 13485as “ISO 13485” incorporates by reference the 2016 edition of ISO 13485.12 By incorporating ISO 13485 bysource↗ (opens in new tab) fda.gov · read
ISO 14971as “ISO 14971” safety risk management as described in ISO 14971. The distinction in the performance ofsource↗ (opens in new tab) fda.gov · read
These citations are drawn together on the citation
graph, where every row carries the same quote and source.
What this record holds for this entry, rung by rung, each mark derived
from a field, a count or a stored reading. Rungs in the order the record acquires them, from what an entry is to what has been checked about it. The order is fixed; a rung’s position says nothing about any entry.
The 12 rungs, as marked for this entry
✓held. identityan address that describes this document rather than a list it sits inThis record holds an address that describes this document, and the names it is published under.
✓held. publisherthe body that published itThe publishing body is recorded as US Food and Drug Administration.
✓held. jurisdictionthe jurisdiction the publishing body belongs toThe jurisdiction is recorded as US.
✗read, and not there. typethe class the document calls itself, quoted from its own titleThe title was read and it does not call this document a regulation, a guidance or a standard, so no class is recorded.
—nothing held. current editiona statement of which edition or revision this record holdsNo reading of an edition or revision statement is recorded for this entry.
—nothing held. publication datea date the publisher states for this documentNo reading of a publication date is recorded for this entry.
—nothing held. lifecycle signala stage, step or status wording read from a publisher surfaceNo read of a publisher surface for a stage or status wording is recorded for this entry.
—nothing held. publisher noticesofficial notices the publisher issued about this documentNo collection of publisher notices has succeeded: of 11 declared sources, 1 has never been attempted and 10 have been attempted without a recorded success. The store holds nothing for any entry.
✗read, and not there. observation historya dated series of what the publisher’s address returnedEvery one of 95 records in this entry’s series is classified as a record of something other than the document this entry names.
✗read, and not there. textprose retained from the retrieved bytes, against which a quotation can be checkedThe bytes this entry retains are classified as bytes of something other than the document it names, so there is nothing here a quotation from this document could be checked against.
✗read, and not there. diffa comparison of two retrievals of this documentThe records this entry holds are classified as records of something other than the document it names, so no comparison of this document has been made.
△held in part. verificationa person’s check of this entry against the primary sourceThis entry was read from the source by tooling on a recorded day, and no person confirmed it.
✓ held — this record holds it, and the sentence beside it names what from · ✗ read, and not there — a reading ran and did not find it — an absence this record measured · — nothing held — no reading of this rung is recorded — nobody has looked, which is not the same as looking and finding nothing · △ held in part — part of it is held, or it is held under a limit the sentence states
The first rung a reading ran on and did not find: type — The title was read and it does not call this document a regulation, a guidance or a standard, so no class is recorded.
What the evidence states
This record holds an address that describes this document, and the names it is published under.
The publishing body is recorded as US Food and Drug Administration.
The jurisdiction is recorded as US.
What it does not state
The title was read and it does not call this document a regulation, a guidance or a standard, so no class is recorded.
No reading of an edition or revision statement is recorded for this entry.
No reading of a publication date is recorded for this entry.
No read of a publisher surface for a stage or status wording is recorded for this entry.
No collection of publisher notices has succeeded: of 11 declared sources, 1 has never been attempted and 10 have been attempted without a recorded success. The store holds nothing for any entry.
Every one of 95 records in this entry’s series is classified as a record of something other than the document this entry names.
The bytes this entry retains are classified as bytes of something other than the document it names, so there is nothing here a quotation from this document could be checked against.
The records this entry holds are classified as records of something other than the document it names, so no comparison of this document has been made.
This entry was read from the source by tooling on a recorded day, and no person confirmed it.
No conclusion is drawn from absence. An absence here is not evidence that a document does not exist, is not in force, or does not govern.
Of the 12 rungs on this entry, 3 are held, 1 are held in part under a limit each one states, and 8 cannot
be established from what this record holds. Each of those carries the reading that produced it and
whose blank it is. Ordered by whose blank each names: this record’s own first, then the publisher’s, then the blanks this record cannot attribute at all.
typethe publisher’s own surfacethe class the document calls itself, quoted from its own titleThe title was read and it does not call this document a regulation, a guidance or a standard, so no class is recorded.
current editionthis record has not lookeda statement of which edition or revision this record holdsNo reading of an edition or revision statement is recorded for this entry.
publication datethis record has not lookeda date the publisher states for this documentNo reading of a publication date is recorded for this entry.
lifecycle signalthis record has not lookeda stage, step or status wording read from a publisher surfaceNo read of a publisher surface for a stage or status wording is recorded for this entry.
publisher noticesthis record has not lookedofficial notices the publisher issued about this documentNo collection of publisher notices has succeeded: of 11 declared sources, 1 has never been attempted and 10 have been attempted without a recorded success. The store holds nothing for any entry.
observation historythis record has not lookeda dated series of what the publisher’s address returnedEvery one of 95 records in this entry’s series is classified as a record of something other than the document this entry names.
textthis record has not lookedprose retained from the retrieved bytes, against which a quotation can be checkedThe bytes this entry retains are classified as bytes of something other than the document it names, so there is nothing here a quotation from this document could be checked against.
diffthis record has not lookeda comparison of two retrievals of this documentThe records this entry holds are classified as records of something other than the document it names, so no comparison of this document has been made.
7 this record has not looked — no reading of this rung is recorded here. The blank is this record’s, and it is not evidence about the publisher · 1 the publisher’s own surface — a reading reached a surface the publisher published and what was asked for is not on it, bounded to the surfaces read
Established for this entry: identity · publisher · jurisdiction. Held in part: verification.
All 8 evidence states, marked against this
entry’s own fields. The axis at the top of this page publishes the
first of them this entry meets; a state it meets after that is marked as
met and not carried, because a state an entry meets and does not carry is
not the same fact as one it fails. 7 of
the 8 come from the published model
and 1 was recorded here.
The order, and why it is not a ranking,
is stated on the observatory.
×not a documentnot meta body, committee or programme — there is no document here to retrieve, quote or dateThe object model records this entry’s own type as document.
×a registernot metretrieved and hashed daily; the tier promises no person-verificationThe record tier this entry declares is core and its freeze reason is not recorded.
×unstated by the publishernot meta surface was read and it states no status term this publisher’s family declares; bounded to the surfaces readThis entry carries no status basis and no recorded tool reading that found none, and no status read on file for it reports a surface that states none.
×verified by a personnot meta person checked this entry against the primary source on a recorded dayThis entry records the check as made by tooling: checked_by reads machine.
×source access limitednot metthe publisher’s licence or its access policy limits what this record takes from the sourceThe freeze reason this entry declares is not recorded, its licence class is open, and its record of whether the publisher excludes automated clients reads false.
×publisher metadatanot metwhat is held is metadata the publisher publishes about the document — a catalogue entry or a stage record — not the documentThe resolution strategy this entry declares is direct_document, what its address points at is declared as document, and no stage the publisher publishes is held for it.
×observednot metthe document at the address the publisher answered is retrieved and hashed here on a dated seriesNo dated retrieval of the document this entry names carries a digest here.
◆not currently retrievablecarriedno retrieval of the document this entry names has produced a digestNo retrieval of the document this entry names has produced a digest here.
◆ carried — the entry meets this test and no state before it in the order does, so this is the state its evidence axis publishes · × not met — the entry does not meet this test, and the line beside it names what was read
Each term states what this record does for this entry and what it does not, derived from the entry’s own fields and its own series. It is a record of coverage, not a finding about the document.
Observed cadence how often this record has reached this entry’s address
Every interval between consecutive days holding an observation is 1 day. The term this record declares for the entry is “monthly”.
Text: public, and retained whether the publisher’s text is public, and whether prose from it is kept here
The publisher’s text is freely reproducible. Prose is retained from what was retrieved, and every record in this entry’s series is classified as being of something other than the document it names, so the prose held is not this document’s.
Hash what is digested for this entry, and of what
No record in this series is classified as being of the document this entry names, so no digest here is of that document. The series carries 95 digest(s) across 95 record(s) of something other than it.
Status verification which check this record undertakes for the published status, and which it holds
This entry’s label asks for a person’s check. A machine read is recorded, dated 2026-09-07, and no person’s confirmation is.
Lifecycle tracked which lifecycle facts this record follows for this entry
This record follows no lifecycle fact for this entry: no effective date, no dated event, no archived version, no publisher stage record and no detected revision is held. That is what has been recorded here, not a reading of what exists. 36 of 132 tracked entries carry at least one such fact.
Known limits the limits this entry’s own record declares
1 of the 8 limits this record can record is set on this entry, and each is listed below with the field it was read from.
observation class No record in this entry’s series of 95 is classified as being of the document the entry names. What the class projection says of them is only that: something other than that document.
The test an entry is admitted under is published in full, with its
negative limb and its worked examples, at the inclusion rule. What this record
holds about THIS entry's admission is below, each line naming the store it
was read from.
Inclusion-rule limb which of the four limbs was applied
—No field in this record names which limb an
entry satisfies, so none is stated for this one. Membership was
closed as a human judgment on 2026-08-11, and the four-limb test
is applied by a person rather than by code. This entry’s own
stated subject is not read as a limb: a title word standing in for
a rule would be a classification this record authored.
Admission entry the dated act that added this entry
—No admission entry is recorded for this entry.
21 of 132 tracked entries carry one, so
an absence here is ordinary rather than a gap peculiar to this
entry.
Declared tier-1 list a recorded judgement that this belongs
This entry is not a member of the declared tier-1 list.
That list names 37 identifiers,
of which 35 resolve to one of
the 132 tracked entries, so most
of the corpus sits outside it and non-membership says nothing
about this entry on its own.
Admissions boundary the jurisdictions this record adds from
This entry’s jurisdiction is US. It is inside the admissions boundary ruled on 2026-08-16,
which names 4 jurisdictions
— EU · US · UK · International — and which is
one of the two admission tests this record enforces in code. The
other is that a candidate carry the publisher’s own address:
a mention is not a citation.
All 95 marks, one per observation, oldest first. · unchanged · ! content changed ·
~ fetched but rendered client-side, no hash ·
× could not be fetched, no hash.
Every one of the 49 days from 2026-08-08 to 2026-09-25 holds an observation.
observations: 95 · carrying a digest: 95 · changes detected: 0 · first observed: 2026-08-08
Method
resolution: direct document · watch cadence: monthly · last fetch method: direct
Evidence
The most recent record is addressed at 2026-09-25·1.
Published at
/observations/fda-device-cybersecurity — every record of this row, with its address. /api/v1/series.jsonl — the same records for every row, one line each.
Each observation is addressed by this row’s identifier, the date it was observed, and its sequence within that date — the same key /api/v1/series.jsonl publishes as `sequence`, counted in the order the store recorded them.
SHA-256:b52b706d5cca10eb0012d3205f0b49473176a2d3da7dd45cf8d268cfaa66648e This digest is a leaf of the integrity root, and the command that recomputes it is published at /how.
Counts and dates over a stated window. No figure here is a mark out of a hundred, no cell is ordered against another, and none of it is a statement about the publisher: a day this record did not reach is a fact about this record’s reach.
Fetch outcomes how the requests in the window
answered
95 of 95 fetch records in the
90 calendar days ending carry no error.
Last fetched the most recent record in the whole
series
— the latest day this record holds ().
The method recorded is direct. What that record returned is in Observation history above.
Address stability where the requests actually
landed
95 record(s) in the window recorded the address
that answered, across 6 distinct
address(es).
93 of them record that the
request was redirected before it answered. The most recent answered address is not the one
this entry declares. A request records where it landed and not
only where it aimed.
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket80 record(s), 2026-08-08 to 2026-09-25
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket?trk=public_post_comment-text9 record(s), 2026-08-10 to 2026-09-19
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket?utm_medium=email&utm_source=govdelivery1 record(s), 2026-08-21 to 2026-08-21
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket?ref=hackernoon.com1 record(s), 2026-08-24 to 2026-08-24
https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket?utm_campaign=FDA%20Releases%20Draft%20Recom%20on%20Premrkt%20Sub%20Manag%20Cybersecurity&utm_medium=email&utm_source=Eloqua2 record(s), 2026-09-02 to 2026-09-03
https://www.fda.gov/media/119933/download2 record(s), 2026-09-07 to 2026-09-07
Access posture what the publisher declares, and what
the requests met
Declared: no AI-specific disallow · crawlable yes · renders server-side.
Met: no request was recorded as refused, over 95 record(s) in the window.
A refusal is what one request of this record met on one day; it
is not a policy the publisher stated.
Expected and observed cadence the declared term, the days held, and
the days holding none
The term this record declares for this entry is monthly. Over its own window, to , 49 of 49 calendar days
hold at least one observation.
None holds none. Every interval between consecutive days
holding one is 1, counted
in days. Both figures are stated and the difference between them is
not adjudicated here.
Each format carries the permalink and the date this entry was observed. The
observation date is part of the citation: the underlying source may have changed
since.
Plain text
GxPlex. Cybersecurity in Medical Devices — Quality System Considerations and Content of Premarket Submissions [entry record]. Observed 25 September 2026. https://gxplex.com/r/fda-device-cybersecurity Primary source: https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions
BibTeX
@misc{gxplexrfdadevicecybersecurity,
author = {{GxPlex}},
title = {{Cybersecurity in Medical Devices — Quality System Considerations and Content of Premarket Submissions}},
year = {2026},
note = {entry record, observed 25 September 2026},
howpublished = {\url{https://gxplex.com/r/fda-device-cybersecurity}},
urldate = {2026-09-25},
url = {https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions}
}
APA
GxPlex. (2026). Cybersecurity in Medical Devices — Quality System Considerations and Content of Premarket Submissions [entry record]. Retrieved 25 September 2026, from https://gxplex.com/r/fda-device-cybersecurity
JSON
{
"@context": "https://schema.org",
"@type": "Dataset",
"name": "Cybersecurity in Medical Devices — Quality System Considerations and Content of Premarket Submissions",
"publisher": "GxPlex",
"url": "https://gxplex.com/r/fda-device-cybersecurity",
"temporalCoverage": "2026-09-25",
"observation": {
"url": "https://gxplex.com/observations/fda-device-cybersecurity#obs-2026-09-25-1",
"observedDate": "2026-09-25",
"sha256": "b52b706d5cca10eb0012d3205f0b49473176a2d3da7dd45cf8d268cfaa66648e",
"verifiedAt": "https://gxplex.com/verify"
},
"isBasedOn": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions"
}
observation.url addresses the single observation this
citation rests on.
Every observation of this document is addressed and separately citable at
the observation series.
Listed primary first, then the further addresses this record holds for
this entry, then the route it was found by, then dated third-party copies.
Repeated URLs appear once, at their first position.
Assessment note
A field and some words a reader may keep beside this entry while reading
it. This record never sees the note: nothing is sent anywhere, nothing is
stored on this device, and it is gone when the page is reloaded. Nothing
below is selected until a reader selects it — no default is offered here,
and this record states no view about which of the four words belongs on
this entry.
Those four words are a reader's own vocabulary, not this record's
description of the document. A judgement of consequence, a decision to
keep watching, a decision to look further and a decision to raise are
refused in this record's own voice by the wall it publishes under, and
that refusal is why the choice sits with a reader rather than being made
here.
The copy control puts the note on this device's clipboard as Markdown,
carrying this entry's identifier and the four published addresses of its
evidence packet at /packet/fda-device-cybersecurity, so a note and
the packet it belongs beside can be filed together. The note is not merged
into the packet's own bytes: merging needs either a request this control
does not make, or a copy of a published surface inside every entry page,
and neither is taken.