Fixed price. 3–8 weeks. FDA & MDR aligned.
FDA’s 2023 Cybersecurity Guidance and MDCG 2019-16 require documented cybersecurity evidence for connected medical devices. Many companies discover gaps only when regulators, notified bodies, or buyers request proof they cannot provide.
The security risks your ogranisation faces right now
No SBOM — no visibility into what is inside your device
Without a Software Bill of Materials, you can’t show what software components are in your device or whether they have known vulnerabilities. FDA 2023 and MDCG 2019-16 require an SBOM maintained throughout the product lifecycle.
No threat model — no documented attack surface analysis
STRIDE and MITRE ATT&CK-based threat modelling are expected by FDA, notified bodies, and enterprise procurement teams. Without a formal threat model, your security posture is undocumented and cannot be presented as regulatory submission evidence.
Unmonitored CVEs are a live, compounding liability
New vulnerabilities in open-source and third-party components emerge daily. Without CVE monitoring linked to your SBOM, you can’t identify newly exploitable components or demonstrate a documented post-market response process.
Cybersecurity evidence is not submission-ready — auditors know it
FDA’s 2023 Guidance requires a Cybersecurity Management Plan for 510(k) and PMA submissions, while MDR expects equivalent evidence. Pen test screenshots and informal security notes are not enough. Regulators and reviewers can tell the difference.
What every engagement delivers
STRIDE Threat Model Report
Structured threat model using STRIDE and MITRE ATT&CK for ICS/healthcare. Covers your full attack surface, threat actors, entry points, and control gaps. Formatted for direct inclusion in FDA 510(k)/PMA and MDR technical files.
SBOM Creation (SPDX / CycloneDX)
Machine-readable Software Bill of Materials listing all third-party and open-source components with version and licence data. Aligned with FDA's 2023 requirement to submit an SBOM with every new medical device application.
CVE Monitoring Programme Setup
Automated CVE monitoring pipeline tied to your SBOM — tooling, alert thresholds, and a documented response workflow. Enables ongoing post-market cybersecurity vigilance you can demonstrate to FDA and notified bodies.
Remediation Priority Roadmap
Risk-ranked security findings with CVSS-based exploitability scores, remediation actions, effort estimates, and a sequenced 90-day action plan to reach a fully defensible, regulator-ready security baseline.
Fixed-price tiers by software class
Class A Low Risk SaMD
€13,000 / Standard Fee
€10,400
Included Scope & Deliverables
FDA / MDCG Compliance Gap Report
Full STRIDE Threat Modelling Matrix
Automated SBOM Generation & Setup (SPDX / CycloneDX)
Initial Vulnerability Scan & CVE triage
CLASS B Medium Risk SaMD
€21,000 / Standard Fee
€16,800
Included Scope & Deliverables
All Class A deliverables, plus:
STRIDE threat mapping to existing software architecture
Formal vulnerability management process drafting
Security test case generation
CLASS C High Risk SaMD
€33,000 / Standard Fee
€26,400
Included Scope & Deliverables
All Class B deliverables, plus:
Advanced threat modelling of complex cloud / device boundaries
SAST / DAST toolchain integration
Formal Post-Market Vulnerability Management Plan
We need 30 minutes to explore how to accelerate your project.
Lock in your assessment.
Engagement details
Typical timeline
Kick-off, asset inventory, architecture review
STRIDE threat modelling, SBOM generation
CVE scan, vulnerability triage, monitoring setup
Findings report and roadmap delivered Class B: 5–6 wks · Class C: 7–8 wks
Who this is for
Connected medical devices — FDA 510(k) or PMA→ SaMD / SiMD with MDR or IVDR obligations
CISOs preparing for procurement security audits
Companies with no existing threat model or SBOM
FDA pre-Sub meeting preparation
Terms
All prices are fixed fees excluding VAT.
Every engagement includes:
30-min discovery call
Written scope
Senior QA/RA review
Our Partners















