Cybersecurity Baseline Assessment

Know your attack surface. Prove it to regulators.

Fixed price. 3–8 weeks. FDA & MDR aligned.

FDA’s 2023 Cybersecurity Guidance and MDCG 2019-16 require documented cybersecurity evidence for connected medical devices. Many companies discover gaps only when regulators, notified bodies, or buyers request proof they cannot provide.

The security risks your ogranisation faces right now

No SBOM — no visibility into what is inside your device

Without a Software Bill of Materials, you can’t show what software components are in your device or whether they have known vulnerabilities. FDA 2023 and MDCG 2019-16 require an SBOM maintained throughout the product lifecycle.

No threat model — no documented attack surface analysis

STRIDE and MITRE ATT&CK-based threat modelling are expected by FDA, notified bodies, and enterprise procurement teams. Without a formal threat model, your security posture is undocumented and cannot be presented as regulatory submission evidence.

Unmonitored CVEs are a live, compounding liability

New vulnerabilities in open-source and third-party components emerge daily. Without CVE monitoring linked to your SBOM, you can’t identify newly exploitable components or demonstrate a documented post-market response process.

Cybersecurity evidence is not submission-ready — auditors know it

FDA’s 2023 Guidance requires a Cybersecurity Management Plan for 510(k) and PMA submissions, while MDR expects equivalent evidence. Pen test screenshots and informal security notes are not enough. Regulators and reviewers can tell the difference.

What every engagement delivers

STRIDE Threat Model Report

Structured threat model using STRIDE and MITRE ATT&CK for ICS/healthcare. Covers your full attack surface, threat actors, entry points, and control gaps. Formatted for direct inclusion in FDA 510(k)/PMA and MDR technical files.

SBOM Creation (SPDX / CycloneDX)

Machine-readable Software Bill of Materials listing all third-party and open-source components with version and licence data. Aligned with FDA's 2023 requirement to submit an SBOM with every new medical device application.

CVE Monitoring Programme Setup

Automated CVE monitoring pipeline tied to your SBOM — tooling, alert thresholds, and a documented response workflow. Enables ongoing post-market cybersecurity vigilance you can demonstrate to FDA and notified bodies.

Remediation Priority Roadmap

Risk-ranked security findings with CVSS-based exploitability scores, remediation actions, effort estimates, and a sequenced 90-day action plan to reach a fully defensible, regulator-ready security baseline.

Fixed-price tiers by software class

Class A Low Risk SaMD

€13,000 / Standard Fee

€10,400

Included Scope & Deliverables

FDA / MDCG Compliance Gap Report

Full STRIDE Threat Modelling Matrix

Automated SBOM Generation & Setup (SPDX / CycloneDX)

Initial Vulnerability Scan & CVE triage

CLASS B Medium Risk SaMD

€21,000 / Standard Fee

€16,800

Included Scope & Deliverables

All Class A deliverables, plus:

STRIDE threat mapping to existing software architecture

Formal vulnerability management process drafting

Security test case generation

CLASS C High Risk SaMD

€33,000 / Standard Fee

€26,400

Included Scope & Deliverables

All Class B deliverables, plus:

Advanced threat modelling of complex cloud / device boundaries

SAST / DAST toolchain integration

Formal Post-Market Vulnerability Management Plan

We need 30 minutes to explore how to accelerate your project.

Lock in your assessment.

Engagement details

Typical timeline

Week 1

Kick-off, asset inventory, architecture review

Week 2

STRIDE threat modelling, SBOM generation

Week 3

CVE scan, vulnerability triage, monitoring setup

Week 4

Findings report and roadmap delivered Class B: 5–6 wks · Class C: 7–8 wks

Who this is for

Connected medical devices — FDA 510(k) or PMA→ SaMD / SiMD with MDR or IVDR obligations

CISOs preparing for procurement security audits

Companies with no existing threat model or SBOM

FDA pre-Sub meeting preparation

Terms

All prices are fixed fees excluding VAT.

Every engagement includes:

30-min discovery call

Written scope

Senior QA/RA review

Our Partners

Chamber logo
Cherry logo
Fittech logo
HTS logo
ITCorner logo
MDG logo
Medical Valley logo
Medlink logo
Medvia logo
MTC logo
Polish-Netherlands Chamber of Commerce logo
PWR logo
SIBB logo
Task Force logo
Biocom logo