Regulatory documentation & submission support

Cyber certainty for your regulatory submission

Our team produces documentation calibrated to what reviewers actually look for. Regulators evaluate documentation, not testing activity. How findings are documented, how methodology is described, and how evidence is presented in your submission artifacts is what shapes reviewer confidence in the work. Stratigos produces documentation built for submission from the start: formatted for review, designed for medical device file inclusion, and written to withstand scrutiny from reviewers and independent experts.

Our deepest regulatory experience is with FDA, and the same evidence expectations run through EU MDR, Health Canada, and other regimes – documentation built to this standard travels with your device wherever you take it.

What we deliver

Outputs and assistance to support your submission

Submission-ready penetration test reports

Our reports are formatted for inclusion in regulatory submissions, eSTAR packages, and medical device files. Every finding documents the specific methodology used, the observed cause and conditions, and the resulting effect, with evidence sufficient for an independent party to reproduce it. Your regulatory team uses our output directly.

Remediation and retest reports

When penetration testing identifies findings, regulators expect a documented remediation and retesting cycle. Our post-remediation testing addendum references original finding IDs, documents the updated device version, applies the original technique (or notes why it no longer applies), and records the result. It passes the same independent review process as the original report.

Cybersecurity deficiency response

If you've received a cybersecurity deficiency letter or information request, we help you understand what the reviewer is asking for, prepare the response documentation, and conduct additional testing to address the specific concerns raised, if needed. We can join calls with reviewers to explain methodology or clarify findings.

Independent review

Every deliverable passes a separate evidentiary check

Every Stratigos deliverable passes an independent review before delivery. A qualified reviewer who was not the primary tester examines all findings for evidentiary sufficiency: is the cause-to-effect chain documented, is it relevant to a real hazard or threat, and can the finding be reproduced from the steps as written? The independence and completeness of the test report as a standalone document is a reviewable characteristic of any submission.

Why it matters

Three sentences in 60 pages – one of the highest-scrutiny areas in the submission

Penetration testing is only three sentences in the 60-page premarket cybersecurity guidance, yet it's consistently one of the highest-scrutiny areas of a submission. Reviewers look for a complete, independent test report with findings that connect cleanly to the device's hazard analysis and align with the product's version history. Our documentation is designed to meet that expectation on the first read, designed by people who understand the review process from the inside, structured to give reviewers what they need, and timed to keep your submission moving.

Next step

Get documentation built for submission from day one