Cybersecurity applicability & plan
Cyber-device assessment, regulatory requirements, secure product development planning, roles, activities and submission artifact map.
FDA Medical Device Cybersecurity
We help manufacturers of connected medical devices and SaMD turn architecture, threats, controls, testing and post-market processes into the cybersecurity evidence expected in FDA premarket submissions.
Selected clients
Healthcare teams we have supported


















Scope and deliverables
We tailor the artifacts to the product, interfaces, deployment model and security risk. The goal is evidence that is technically defensible and practical to maintain after clearance.
Cyber-device assessment, regulatory requirements, secure product development planning, roles, activities and submission artifact map.
System context, trust boundaries, data flows, external interfaces, assets, update paths and views that make the security design reviewable.
Structured identification of threat actors, attack surfaces, threats, misuse cases and control needs using methods appropriate to the product.
Security risk analysis, control traceability, residual risk evaluation and clear linkage between cybersecurity and patient-safety risk.
Software Bill of Materials strategy, component support status, known-vulnerability review, disposition and dependency governance.
Security testing strategy, evidence coordination, vulnerability management, coordinated disclosure, monitoring, updates and patchability documentation.
Ways to work together
We lead the cybersecurity workstream and prepare the architecture, threat, risk, SBOM, testing and post-market artifacts for eSTAR.
We facilitate structured sessions with engineering and product teams, then turn the technical decisions into controlled evidence.
We interpret the FDA concern, identify the evidence or product gap and coordinate a focused technical response with your team.
How it works
Understand architecture, data, interfaces, deployment, users, update mechanisms and essential clinical performance.
Identify attack surfaces, threats and hazardous security scenarios, then select proportionate controls.
Document architecture, risk, SBOM, testing, residual risk, vulnerability handling and post-market processes.
Check traceability and eSTAR readiness, close gaps and support questions during FDA review.
Regulations, standards and guidance considered
Frequently asked questions
Section 524B defines a cyber device through criteria involving software, internet connectivity and technological characteristics that could be vulnerable to cybersecurity threats. Applicability needs to be assessed against the actual architecture and intended connectivity, including indirect or optional connections.
The exact set depends on the device, but typically includes security architecture, threat modelling, cybersecurity risk management, SBOM and component support information, security testing evidence, vulnerability management, coordinated disclosure and plans for updates and patches. These artifacts must remain mutually consistent.
We can help define the SBOM process, select or review tooling output, normalize component information and connect known-vulnerability findings to risk and disposition records. Engineering ownership is still important because the SBOM must remain accurate as the software changes.
No. Penetration testing is one part of a broader cybersecurity evidence set. FDA also expects a secure development approach, architecture, threat modelling, risk management, traceable controls, other security testing, vulnerability management and post-market processes.
A security compromise can create or contribute to a hazardous situation. Cybersecurity analysis should identify those paths and connect relevant security controls to the safety-risk file while still preserving a dedicated evaluation of security risks such as confidentiality, integrity and availability.
Yes. We can assess the question against the submitted evidence and product implementation, identify whether the gap is documentary or technical, and help prepare a response. If product changes or additional testing are required, our software team can support that work as a separate agreed scope.
Related expertise
Coordinate cybersecurity with the wider 510(k), De Novo or Pre-Submission strategy.
Implement security controls and maintain them within a controlled software lifecycle.
Respond to cybersecurity, software or AI deficiencies under a fixed FDA deadline.
Start with the product you have