How to Choose a Medical Device Penetration Testing Vendor
Seven questions that separate medical device penetration testing vendors from generic IT security firms, and the red flags that predict FDA deficiencies.
Choosing a medical device penetration testing vendor comes down to three checks: they've tested devices like yours (embedded, wireless, physical interfaces, not just web apps), their report format matches what FDA reviewers expect (full findings with severity scores and tester qualifications, not a summary certificate), and the deliverable traces into your risk assessment and eSTAR submission. Price and brand name matter less than those three. Here are the questions that surface the difference before you sign.
Why is this different from hiring a regular pen test firm?
Most penetration testing firms grew up testing corporate networks and web applications. A medical device engagement is a different animal. The attack surface includes firmware, RF protocols, debug ports, and clinical workflows. The deliverable has to satisfy an FDA reviewer, not an IT director. And the findings need to feed a regulatory risk file, not a ticket queue.
A generic firm can find real vulnerabilities in your device. What they usually can't do is hand you a report that drops into an eSTAR submission without rework. We've seen manufacturers pay twice: once for the test, then again for someone to restructure the report and disposition the findings in FDA's terms. We covered exactly what that report needs to contain in a separate post.
What questions should you ask before signing?
1. "Show me a redacted report from a medical device engagement."
The single most useful screen. You'll learn more from ten minutes with a sample report than from any sales call. Check for scope definition, methodology, per-finding severity scoring, an anomalies section, and tester qualifications. If they can't produce a device report, they haven't done this work.
2. "Who exactly will test my device?"
Firms sell senior credentials and staff junior testers. Ask for the actual names and backgrounds of the people on your engagement. FDA asks for tester qualifications in the report, so you need this information anyway.
3. "What device classes and interfaces have you tested?"
Match their history to your device. BLE-connected wearable, networked capital equipment, implantable with an inductive link, SaMD with a cloud backend: each needs different skills and equipment. A vendor that's only tested one class will scope your device like the class they know.
4. "What do you need from us, and what happens if you brick a unit?"
Experienced device testers ask for engineering builds, debug access where appropriate, and multiple test units. They'll have a plan for hardware damage. A vendor that doesn't mention test units or asks to test only your production cloud instance hasn't thought about the embedded side.
5. "Do we own the full report?"
Some firms deliver a certificate or executive summary and treat the technical detail as proprietary. That doesn't work here. The full report goes in your submission. Get deliverable ownership in the contract.
6. "How do findings map to our risk assessment?"
The best vendors ask for your threat model and risk file before testing and reference them per finding. If the vendor has never heard of AAMI TIR57 or asks what eSTAR is, keep looking.
7. "Is re-testing included?"
You'll fix the important findings and need re-test evidence for the submission. Find out now whether verification of fixes is in the price or a change order.
What are the red flags?
- A quote produced without a scoping call. They priced a template, not your device.
- "Fully automated" testing sold as a pen test. Scanners have their place, but FDA reviewers know the difference, and so do we. Our post on how a device pen test actually runs shows what manual effort looks like.
- Guaranteed clean results. A vendor that promises no findings is selling a rubber stamp, and a report with zero findings on a first-time engagement reads as a shallow test.
- No questions about intended use or patient harm. Severity scoring for medical devices has to account for clinical impact, not just data confidentiality.
- Certificate-only deliverables, per question 5 above.
How much should you expect to pay?
Enough that a suspiciously cheap quote should worry you. Real device testing takes senior people and lab time, and pricing swings with interface count, device complexity, and reporting depth. We broke down the numbers and the levers you control in our post on medical device penetration testing costs.
Where CyberMed fits
Medical device penetration testing is the core of what we do. Engineers who've built devices, testing to TIR57 and FDA's premarket guidance, reports formatted for eSTAR with findings traced to your risk assessment, and re-testing included. The details are on our penetration testing page. If you're comparing vendors, book a call and ask us the seven questions above. We enjoy answering them.
Frequently asked questions
›Can a general IT penetration testing firm test a medical device?
Technically yes, but it's risky. Generic firms test networks and web apps. Medical devices add embedded firmware, BLE and proprietary wireless, physical interfaces, and an FDA reporting format. A vendor without device experience usually produces a report that needs rework before it can go in a submission.
›What should a medical device penetration test deliverable include?
A full technical report you own: scope and configuration tested, methodology, tester qualifications, findings with CVSS severity and exploitability analysis, observed anomalies, and remediation guidance. A summary letter or certificate is not sufficient for FDA.
›How long does a medical device penetration test take?
Typically two to six weeks from kickoff to final report, depending on the number of interfaces and whether re-testing of fixes is included. Add lead time for scoping and contracting. If FDA has already issued a deficiency, ask vendors about expedited timelines.
›Should the pen test vendor also write my FDA cybersecurity documentation?
It can help. A vendor that understands eSTAR structure will produce a report that traces to your threat model and risk assessment instead of a standalone document you have to integrate yourself. Just keep the testing team independent from whoever designed the security architecture.
›What certifications should medical device penetration testers have?
OSCP, GPEN, or similar hands-on certifications are a reasonable baseline, but device-specific experience matters more than any certificate. Ask for redacted sample reports from actual medical device engagements and for the specific people who will do the work.