The documents your reviewer is reading
When we tell you what a reviewer expects, it is often because we sat in the working group that wrote the expectation down. Everything here is public. Every link goes to the document itself, not to the programme page it lives under.
Our running notes on FDA guidance
Working notes we keep up to date as the guidance moves. The version record is the one to bookmark: FDA has revised the premarket guidance three times in thirty months and two of those versions carry the identical title.
- Kept current
Which FDA cybersecurity guidance applies to my submission?
Every version of the premarket guidance, what each superseded, and how to tell which one your submission was written against.
- February 2026
What the February 2026 FDA premarket update changes
A minor update that aligns the guidance with the QMSR. Two things to change in your procedures.
- June 2025
The 2025 FDA premarket cybersecurity guidance, section by section
Our read at the time, plus the full internal review as a document: what changed, and which single change was genuinely new.
- March 2026
FDA is asking for known vulnerabilities alongside your SBOM
What reviewers have been asking for, in machine-readable VEX form, and the five things to do before your next submission.
What manufacturers are measured against
Documents that tell manufacturers and regulators what is expected. We were in the working groups that wrote them.
- 2026 contributor
Validating Medical Device Cybersecurity Through Penetration Testing
MDIC Cybersecurity Working GroupStratigos Security is one of only two recognized contributing consulting firms to this guidance, which was developed with FDA participation. MDIC, the Medical Device Innovation Consortium, is the public-private body FDA works with on industry guidance.
How to scope, resource, run and dispose of a medical device penetration test inside a quality system. Written for quality, program and R&D management rather than for security engineers.
- 2021 facilitator and trainer
Playbook for Threat Modeling Medical Devices
MITRE and the Medical Device Innovation Consortium, commissioned by FDAThe FDA-commissioned medical device threat modeling playbook and the training that goes with it, which is the reference most manufacturers now write their threat models against.
The published record
The venues clinicians, regulators and policymakers read, years before the expectations reached a guidance document.
- 2023 invited speaker
Cybersecurity Seminar Series: medical device security in practice
UCSF-Stanford Center of Excellence in Regulatory Science and InnovationA seminar for the FDA-funded regulatory science centre at UCSF and Stanford, for an audience of regulatory scientists rather than security engineers.
- 2021 co-author
Cybersecurity Challenges and the Academic Health Center: An Interactive Tabletop Simulation for Executives
Academic Medicine (journal of the AAMC)Why a teaching hospital carries a risk profile that neither a hospital nor a university security program covers on its own, and a tabletop for running executives through it.
- 2021 co-author
Building resilient medical technology supply chains with a software bill of materials
npj Digital Medicine (Nature Portfolio)The case for SBOM in medical technology, in a peer-reviewed venue clinicians and regulators read. An SBOM is to software what an ingredients list is to food.
- 2020 panelist
Roundtable Discussion: Finding a Universal Language to Discuss Healthcare Cybersecurity
Biomedical Instrumentation & Technology (AAMI journal)Manufacturers, hospitals and FDA in one room on the words they each use for the same risk, and why a shared vocabulary is a prerequisite for anything else working.
- 2019 co-author
The Case for a Hippocratic Oath for Connected Medical Devices
Journal of Medical Internet Research (JMIR)A viewpoint on the duty of care owed by the people who build connected medical devices.
- 2015 co-author
The Healthcare Internet of Things: Rewards and Risks
Atlantic CouncilThe argument, a decade before it reached a guidance document, that connected care equipment carries patient-safety consequences that neither hospital IT nor device engineering owns alone.