Jul 31, 2026
How to Choose a Medical Device Penetration Testing Vendor
Seven questions that separate medical device penetration testing vendors from generic IT security firms, and the red flags that predict FDA deficiencies.
Notes from submissions, deficiency letters, and test reports.
34 articles, newest first
Jul 31, 2026
Seven questions that separate medical device penetration testing vendors from generic IT security firms, and the red flags that predict FDA deficiencies.
Jul 31, 2026
The sections FDA reviewers expect in a medical device penetration test report: scope, methodology, findings with CVSS scores, anomalies, and how it ties to your risk assessment.
Jul 31, 2026
Medical device penetration testing typically runs $15,000 to $75,000+. The drivers: interface count, device complexity, FDA reporting depth, and re-testing.
Apr 15, 2026
A practical medical device security testing guide: architecture reviews, code review, fuzzing, penetration testing, and FDA-ready evidence.
Mar 31, 2026
The Health Care Cybersecurity and Resiliency Act just cleared the Senate HELP Committee. For medical device manufacturers, this is not a drill.
Mar 25, 2026
The Stryker wiper attack exposed the gap between FDA compliance and operational resilience. Here's what medical device companies should actually do about it.
Mar 24, 2026
Forescout just published its 2026 Riskiest Devices report, and for anyone working in medical device security, the IoMT section is worth reading carefully.
Mar 4, 2026
Practical SBOM generation for medical device software across common stacks, with validation and quality gates for FDA submission.
Feb 24, 2026
FDA released its 3rd cybersecurity guidance in 3 years. The update swaps QSR for QMSR and leaves the 14 required documents untouched. Here is what changed.
Jan 8, 2026
A plain-language guide to medical device encryption for QA and regulatory teams: symmetric vs asymmetric, key management, and quantum implications.
Nov 24, 2025
How to write a Software Design Specification that meets IEC 62304 clause 5.4 and FDA expectations, with checklists, examples, and common pitfalls.
Oct 28, 2025
Map IEC 62304 processes to FDA eSTAR requirements. Complete guide to 10 required software documents for medical device submissions with examples.
Sep 4, 2025
How medical device teams balance cybersecurity controls with clinical usability using risk-based design, collaboration, and FDA-aligned documentation.
Aug 20, 2025
Twelve rules that decide whether your FDA cybersecurity risk assessment satisfies a reviewer or triggers an AI request, each mapped to the guidance.
Aug 6, 2025
Catalogs the software and cybersecurity documents FDA expects in eSTAR submissions and offers guidance on organizing evidence for reviewers.
Jul 22, 2025
Shows how to use the STRIDE framework to categorize threats, map mitigations, and meet FDA cybersecurity expectations.
Jul 17, 2025
Details how to build cybersecurity traceability matrices that connect threats, controls, and verification evidence for modern FDA submissions.
Jul 9, 2025
Covers the monitoring, vulnerability response, and legacy planning manufacturers need to keep medical devices cybersecure after FDA clearance.
Jun 25, 2025
Clarifies how FDA's Secure Product Development Framework complements IEC 62304 and what dual documentation packages reviewers expect.
Jun 18, 2025
Explains why secure architecture decisions early in development prevent costly rework and position medical devices for smoother FDA cybersecurity reviews.
Apr 26, 2025
Explore the innovative application of the Common Vulnerability Scoring System (CVSS) in medical device risk assessment.
Feb 20, 2025
How to choose, build, and verify cybersecurity controls for medical devices, with each control traced to a specific threat in your model.
Feb 19, 2025
How to conduct medical device penetration testing: scoping, black, white, and grey box approaches, the five test phases, and FDA-ready reporting.
Feb 19, 2025
Secure SDLC for medical devices: which security activity belongs in each stage, the FDA artifact it produces, and common submission failures.
Feb 18, 2025
How to create data flow diagrams for medical devices: the four core components, steps to build one, and how DFDs feed threat modeling for FDA.
Feb 18, 2025
Learn how to perform a security code review: preparation, manual and automated techniques, and how to catch vulnerabilities before code ships.
Feb 14, 2025
How to build the medical device security architecture view FDA reviewers expect, step by step, aligned with AAMI SW96 and TIR57.
Feb 11, 2025
Provides a step-by-step playbook for building an FDA-aligned patch and security update program for connected devices.
Feb 10, 2025
Guides teams through threat modeling a cloud-connected device using FDA's 2023 cybersecurity guidance alongside AAMI TIR57 and SW96.
Jan 31, 2025
What FDA actually expects in the cybersecurity package for a software-based medical device, mapped to where each artifact lives in your submission.
Jul 29, 2024
Outlines five cybersecurity gaps that now trigger FDA refusal-to-accept decisions for 510(k) submissions and how to close them.
Jul 18, 2024
The update path is privileged code execution shipped to every device. Here is the architecture that keeps medical device software updates secure.
Jul 18, 2024
Makes the case that remote update capability is now essential under FDA cybersecurity rules and explains how to implement it safely.
Jul 18, 2024
Breaks down the cybersecurity evidence FDA expects in submissions for software-enabled medical devices, from threat models to testing reports.
The full medical device cybersecurity book is free to read online, chapter by chapter, no signup.
Open chapter 1