FDA Recognizes CVSS v4.0 What You Need to Know

FDA Approves CVSS v4.0

The U.S. FDA (Food and Drug Administration) recognized the Common Vulnerability Scoring System (CVSS) v4.0 on December 23, 2024, as a consensus standard for medical devices. Find details here

This recognition comes approximately one year after the release of CVSS v4.0 by NIST (National Institute of Standards and Technology). The recognition number for this standard is 13-140.

The FDA had previously recognized CVSS v3.0 in October 2020, and both versions remain valid for medical device manufacturers to use in their regulatory submissions, including threat modeling and vulnerability assessments.

Manufacturers can utilize either CVSS v3.0 or v4.0 until December 20, 2026, at which point CVSS v4.0 will fully supersede v3.0. This transition period allows manufacturers to adapt their processes and documentation to align with the updated scoring system while still meeting regulatory requirements.

What is CVSS?

CVSS is a framework that communicates the severity and characteristics of software vulnerabilities.

It is a commonly used scoring system to assess and prioritize the severity of vulnerabilities (or “threats”). It offers a standardized way to evaluate vulnerabilities, helping organizations make better decisions about their security. Despite its widespread use, CVSS is often criticized, mainly because it’s applied in ways it wasn’t originally intended. Since it was created, CVSS has evolved through several updates to improve its accuracy and usability. Access the CVSS user guide here.

It was developed by the Forum of Incident Response and Security Teams (FIRST), a non-profit organization. CVSS v4.0 is the latest version of the CVSS standard. It includes new metrics, nomenclature, and other changes.

The updated framework allows for a more accurate depiction of real-world risks associated with vulnerabilities, helping organizations prioritize their remediation efforts effectively. This transition to CVSS v4.0 is expected to enhance the overall effectiveness of vulnerability management in medical devices, addressing many limitations of its predecessor while promoting better cybersecurity practices within the industry.

Contact MedQair today to learn how we can help you navigate the FDA’s approval of CVSS v4.0 and enhance your vulnerability assessment strategies. Don’t wait. Take the next step towards robust cybersecurity solutions now!

Latest Regulatory News

June 23, 2026

On 17 June 2026, the European Commission published the reference of EN ISO 15223-1:2021/A1:2025 in the Official Journal of the

January 6, 2026

On 19 November 2025, the European Commission unveiled the Digital Omnibus package, a legislative proposal introducing targeted amendments to several

December 17, 2025

On 3 December 2025, the European Commission released a 12-page draft Implementing Regulation (Ares(2025)10569703) establishing detailed rules for the operation

logo

Unlock Your Quick Guide to AI Act
Compliance!

Explore AI-enabled SaMD requirements with our easy step-by-step guide.

Cookies help us improve your experience on our website. By using our site, you consent to the use of cookies as described in this policy.