Preparing for the PATCH Act and RTA
Summary
Companies must develop a product monitoring plan, cyber-anomaly response plan, coordinated messaging of cyber vulnerabilities, Software Bill of Materials (SBOM) and demonstrate the ability to release critical vulnerability patches ‘as soon as possible.’ In accordance with the Patch Act, the FDA announced that it may Refuse to Accept (RTA) premarket submissions that do not meet these requirements, beginning on October 1, 2023. The FDA announced that as of October 1, 2023, they may “refuse to accept” (RTA) premarket submissions that do not meet requirements under 524B of the FD&C Act. FDA will probably provide some slack for 90 days or so—maybe as much as a half a year—and then it will get real serious and start rejecting submissions if the devices are not properly constructed. We have seen three warning letters this year that mention software, and they are very interesting because two of them were issued to very small manufacturers versus organizations developing high-risk devices. Kaminski: There is also a lot more focus from the FDA on did the company have control over specific devices in the field, and which version and in which location did the cyber security issues occur?