
We'll Add Cybersecurity Later - Why doesn't the previous strategy work anymore?
It used to be a normal plan: build the device first, add the cybersecurity documentation later. That plan doesn't work anymore. The gap between "later" and "too late" keeps getting shorter.
Why doesn't the previous strategy work anymore?
Cybersecurity used to be a recommendation. Now it's a legal requirement.
Since March 2023, Section 524B of the FD&C Act makes cybersecurity a legal condition for premarket submissions of connected medical devices. FDA's June 2025 guidance made it stricter: a machine-readable SBOM (Software Bill of Materials), a Security Risk Management Report, a documented threat model, and penetration testing evidence are now standard requirements, not extras.
Fixing security gaps late is also just more expensive. NIST-cited research shows that fixing a software defect after release costs about 30 times more than catching it during development. The same applies to medical device cybersecurity: a threat model built after the architecture is frozen, or an SBOM built from memory instead of maintained release by release, takes longer and produces weaker evidence than doing the same work continuously.
Reviewers can tell the difference too. A threat model built into the software development lifecycle from day one looks like a living document tied to the real system architecture. A threat model built the week before submission looks exactly like what it is — assembled after the fact — and that's what triggers extra questions or a Refuse to Accept decision.
What changed, in short
Timing — Before: compile documentation before filing. Now: FDA and MDCG 2019-16 expect proof that cybersecurity risk management, vulnerability monitoring, and secure coding practices ran throughout development.
SBOM — Before: list components if someone asks. Now: a legally required, machine-readable SBOM, kept current as dependencies and third-party components change.
Vulnerability management — Before: react if something breaks after launch. Now: an active Cybersecurity Management Plan with coordinated vulnerability disclosure (CVD), CVE monitoring, and a patching process defined before the device ships.
Connectivity changes — Before: add a new sensor or wireless link, update the paperwork later. Now: any new connectivity, cloud integration, or data interface changes your threat model and attack surface immediately.
Why this matters for connected medical systems specifically
Connected medical devices — infusion pumps, patient monitors, glucose monitors, IoMT platforms — carry more cybersecurity risk than standalone software because they combine embedded firmware, wireless connectivity, cloud backends, and mobile apps in one system. Each layer needs its own threat model, its own vulnerability monitoring, and its own place in the SBOM. Building secure, auditable connected medical systems takes real technical depth across embedded engineering, network security, and regulatory documentation — not just software development skills on their own.
This is where technical teams based in strong engineering hubs make a visible difference. Wrocław, Poland has become one of Europe's established technology centers, and Wrocław-based developers building cybersecurity-focused connected medical systems bring hands-on experience across IEC 62304 software lifecycle processes, IEC 81001-5-1 health software cybersecurity requirements, threat modeling (STRIDE, MITRE ATT&CK), SBOM management, and secure architecture design for IoMT devices — the exact mix of skills FDA and MDR now expect to see documented, not just implied.
What this means in practice
None of this requires a total process overhaul. It means threat modeling, SBOM maintenance, penetration testing, and vulnerability monitoring start when development starts — tied to the same IEC 62304 lifecycle as everything else, not bolted on as a separate step once the product is "basically done."
The cost of making that shift is small compared to the alternative: a submission delay, a Refuse to Accept, or a notified body audit that stalls on cybersecurity documentation nobody kept up to date.
Where to start
If cybersecurity has been a "we'll get to it" item on your roadmap, a structured gap assessment is the fastest way to see where you actually stand — before an auditor or reviewer finds the gap for you.
Thaumatec's Cybersecurity Baseline Assessment covers SBOM setup, threat modeling, penetration testing readiness, and a risk-ranked remediation roadmap for connected medical devices — fixed price, 3–8 weeks depending on device class.
See scope and pricing by class →
Or skip straight to a conversation: book a 30-min call →