The February 2026 Cybersecurity Final Rule Is Now Operational Reality — SBOMs, Legacy Devices, and Who Owns the Gap
The FDA's tightened medical-device cybersecurity requirements took effect on 2 February 2026, amending the bulk of what manufacturers must demonstrate and formalizing software bill of materials expectations. Seven months in, the interesting question is no longer what manufacturers must submit. It is what happens to the installed base that predates the rule.
The scale of that installed base is the problem. FDA has estimated that roughly 164 of every 1,000 devices remain vulnerable to cyberattack, and a 2025 survey found that 73 percent of healthcare organizations still run legacy devices on operating systems that no longer receive modern security support. A rule governing new submissions does nothing for an infusion pump fleet purchased in 2016.
This is where HTM and IT have to stop being separate conversations. The device inventory that clinical engineering maintains for maintenance purposes is the same inventory security needs for asset management — but the two are almost never the same document. Reconciling them is unglamorous, takes months, and is the highest-value cybersecurity project most hospitals are not running.
Where a device genuinely cannot be patched, the answer is compensating controls: network segmentation that isolates it, monitored egress, documented risk acceptance signed by someone with authority, and a replacement date on the capital plan. “Unsupported” is a finding. “Unsupported, segmented, monitored, and scheduled for replacement in FY27” is a program.
Sources: FDA — medical device cybersecurity; HealthTech — FDA tightens cybersecurity guidance (2026); MD+DI — evolving device threat landscape


































