Resources

The documents your reviewer is reading

When we tell you what a reviewer expects, it is often because we sat in the working group that wrote the expectation down. Everything here is public. Every link goes to the document itself, not to the programme page it lives under.

Ours, kept current

Our running notes on FDA guidance

Working notes we keep up to date as the guidance moves. The version record is the one to bookmark: FDA has revised the premarket guidance three times in thirty months and two of those versions carry the identical title.

  1. Kept current

    Which FDA cybersecurity guidance applies to my submission?

    Every version of the premarket guidance, what each superseded, and how to tell which one your submission was written against.

  2. February 2026

    What the February 2026 FDA premarket update changes

    A minor update that aligns the guidance with the QMSR. Two things to change in your procedures.

  3. June 2025

    The 2025 FDA premarket cybersecurity guidance, section by section

    Our read at the time, plus the full internal review as a document: what changed, and which single change was genuinely new.

  4. March 2026

    FDA is asking for known vulnerabilities alongside your SBOM

    What reviewers have been asking for, in machine-readable VEX form, and the five things to do before your next submission.

Guidance and standards

What manufacturers are measured against

Documents that tell manufacturers and regulators what is expected. We were in the working groups that wrote them.

  1. 2026 contributor

    Validating Medical Device Cybersecurity Through Penetration Testing

    MDIC Cybersecurity Working Group

    Stratigos Security is one of only two recognized contributing consulting firms to this guidance, which was developed with FDA participation. MDIC, the Medical Device Innovation Consortium, is the public-private body FDA works with on industry guidance.

    How to scope, resource, run and dispose of a medical device penetration test inside a quality system. Written for quality, program and R&D management rather than for security engineers.

  2. 2021 facilitator and trainer

    Playbook for Threat Modeling Medical Devices

    MITRE and the Medical Device Innovation Consortium, commissioned by FDA

    The FDA-commissioned medical device threat modeling playbook and the training that goes with it, which is the reference most manufacturers now write their threat models against.

The published record

The venues clinicians, regulators and policymakers read, years before the expectations reached a guidance document.

  1. 2023 invited speaker

    Cybersecurity Seminar Series: medical device security in practice

    UCSF-Stanford Center of Excellence in Regulatory Science and Innovation

    A seminar for the FDA-funded regulatory science centre at UCSF and Stanford, for an audience of regulatory scientists rather than security engineers.

  2. 2021 co-author

    Cybersecurity Challenges and the Academic Health Center: An Interactive Tabletop Simulation for Executives

    Academic Medicine (journal of the AAMC)

    Why a teaching hospital carries a risk profile that neither a hospital nor a university security program covers on its own, and a tabletop for running executives through it.

  3. 2021 co-author

    Building resilient medical technology supply chains with a software bill of materials

    npj Digital Medicine (Nature Portfolio)

    The case for SBOM in medical technology, in a peer-reviewed venue clinicians and regulators read. An SBOM is to software what an ingredients list is to food.

  4. 2020 panelist

    Roundtable Discussion: Finding a Universal Language to Discuss Healthcare Cybersecurity

    Biomedical Instrumentation & Technology (AAMI journal)

    Manufacturers, hospitals and FDA in one room on the words they each use for the same risk, and why a shared vocabulary is a prerequisite for anything else working.

  5. 2019 co-author

    The Case for a Hippocratic Oath for Connected Medical Devices

    Journal of Medical Internet Research (JMIR)

    A viewpoint on the duty of care owed by the people who build connected medical devices.

  6. 2015 co-author

    The Healthcare Internet of Things: Rewards and Risks

    Atlantic Council

    The argument, a decade before it reached a guidance document, that connected care equipment carries patient-safety consequences that neither hospital IT nor device engineering owns alone.

Next step

Want this applied to your submission?