CPMS Regulatory Compliance & Security Standards 3 — Questions and Answers
Question 1: The FDA's 2023 final rule on cybersecurity for medical devices (Section 524B of FD&C Act) requires manufacturers to submit a Software Bill of Materials (SBOM). The primary purpose of the SBOM is to:
- Replace the need for penetration testing
- Enable identification of software components and their known vulnerabilities (Correct answer)
- Satisfy FDA's Unique Device Identifier (UDI) requirements
- Document the software development lifecycle process
Correct answer: Enable identification of software components and their known vulnerabilities
An SBOM provides a comprehensive inventory of software components, enabling manufacturers and users to rapidly identify which products are affected when new vulnerabilities in third-party components are disclosed.
Question 2: Under ISO 14971:2019, the risk management process requires that residual risks be evaluated against:
- Zero-risk benchmarks established by regulatory authorities
- Benefits of the intended use, weighed using an overall risk-benefit analysis (Correct answer)
- Historical incident rates from similar devices on the market
- The manufacturer's internal acceptable risk thresholds set before development begins
Correct answer: Benefits of the intended use, weighed using an overall risk-benefit analysis
ISO 14971:2019 requires that overall residual risk be weighed against the overall benefit of the device's intended use, and the risk-benefit analysis must conclude that benefits outweigh risks.
Question 3: Which regulatory pathway is most appropriate for a novel Class III medical software device with no predicate device?
- 510(k) Premarket Notification
- De Novo Request
- Premarket Approval (PMA) (Correct answer)
- Humanitarian Device Exemption (HDE)
Correct answer: Premarket Approval (PMA)
Class III devices that cannot claim substantial equivalence and do not qualify for De Novo must submit a Premarket Approval (PMA) application, the most stringent FDA premarket review pathway.
Question 4: SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports:
- Cover additional trust service criteria not included in Type I
- Assess the design AND operating effectiveness of controls over a period of time (Correct answer)
- Are required by HIPAA for cloud service providers handling ePHI
- Involve external penetration testing as a mandatory component
Correct answer: Assess the design AND operating effectiveness of controls over a period of time
SOC 2 Type II evaluates both the design suitability and the operating effectiveness of controls over an observation period (typically 6–12 months), whereas Type I assesses only design at a single point in time.
Question 5: A medical device manufacturer must retain Device History Records (DHRs) under 21 CFR Part 820 for a minimum of:
- 2 years from the date of manufacture
- The expected life of the device or 2 years from the date of release, whichever is longer (Correct answer)
- 5 years from the date of the last sale
- 7 years to align with FDA inspection cycles
Correct answer: The expected life of the device or 2 years from the date of release, whichever is longer
21 CFR 820.184 requires DHRs to be retained for a period equivalent to the design and expected life of the device, but in no case less than 2 years from the date of release for commercial distribution.
Question 6: In a threat modeling exercise for a networked infusion pump, the STRIDE model categorizes 'an attacker forging dosage commands by impersonating a clinician workstation' under which threat category?
- Spoofing (Correct answer)
- Tampering
- Information Disclosure
- Elevation of Privilege
Correct answer: Spoofing
Spoofing in the STRIDE model refers to an attacker illegitimately assuming the identity of another user, system, or device—exactly what occurs when commands are forged by impersonating a legitimate clinician workstation.
Question 7: The EU MDR requires manufacturers of Class IIb and Class III devices to perform clinical follow-up through a Post-Market Clinical Follow-Up (PMCF) plan. When must this plan be updated?
- Only after a serious adverse event has been reported to the Notified Body
- Continuously, as part of the ongoing post-market surveillance system (Correct answer)
- Every 10 years as part of the periodic safety update report cycle
- Only when the device is modified or a new indication is added
Correct answer: Continuously, as part of the ongoing post-market surveillance system
Under EU MDR Article 83 and Annex XIV, PMCF is an ongoing process integrated into the post-market surveillance system, not a one-time or event-triggered activity.
The FDA's 2023 final rule on cybersecurity for medical devices (Section 524B of FD&C Act) requires manufacturers to submit a Software Bill of Materials (SBOM).
The primary purpose of the SBOM is to: