Skip to content
Contact us

Penetration Testing Services › FDA cyber security testing

FDA premarket submissions

Your reviewer reads our report,
not a summary of it.

FDA guidance says that where a third party performs the testing, the manufacturer should provide the original third-party report. Ours is written on the assumption that a reviewer reads it exactly as submitted.

Talk to us about your submissionMedical device testing

What the rules actually say

Where a penetration test fits

Section 524B applies to cyber devices

Added to the FD&C Act at the end of 2022 and effective from March 2023, it obliges the sponsor of a premarket submission for a cyber device to include cyber security information. This is the binding instrument; the guidance below is how the FDA says to satisfy it.

The guidance points at third-party testers

It says that in some cases it may be necessary to use third parties to ensure an appropriate level of independence between those testing the device and those who designed it. Independence is not a formality here — it is one of the five things the report has to establish.

The original report goes in

Not a summary, not a certificate: the guidance asks manufacturers to provide the original third-party report. That makes report quality part of the submission rather than a courtesy to your engineers.

Section V.C

The five elements, and what we put against each

Guidance for a penetration test report, and the part of our deliverable that answers it.

What the guidance asks a report to containWhat is in ours
Independence and technical expertise of testersThe named testers who did the work, their qualifications, and our independence from your development team — stated on the report itself, not supplied on request.
Scope of testingThe exact system boundary tested — device, firmware, companion app, cloud, the protocols between them — and, just as explicitly, what was out of scope.
Duration of testingThe engagement dates and the effort behind them, proportionate to the complexity of the system rather than to a template.
Testing methods employedThe methodology, the tools with their versions and configuration, and the manual work — mapped to our published test catalogue so a reviewer can see what was covered.
Test results, findings, and observationsEvery finding with reproduction steps, evidence, severity and remediation guidance — and the things we tried that did not work, which is what makes the rest credible.

Source: FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026, section V.C. Supersedes the 27 June 2025 edition. The guidance is marked Contains Nonbinding Recommendations; the binding requirement is section 524B of the FD&C Act. Read the guidance

Penetration testing is not the only testing named

Security requirements

Evidence that each design input requirement was implemented, plus the boundary analysis and the rationale behind its assumptions.

Threat mitigation

Evidence that your risk controls actually hold — tested against the threat model rather than assumed from it.

Vulnerability testing

Abuse and misuse cases, malformed input, robustness and fuzzing, attack surface analysis, vulnerability chaining, known-vulnerability scanning, software composition analysis of binaries, and static and dynamic analysis including hardcoded and default credentials.

A penetration test is one item on that list, not a substitute for it. We do the testing work above where it is in scope, and we say plainly which parts we did not do rather than letting a submission imply otherwise.

Where we stop

Worth saying out loud, because the boundary is what makes the rest trustworthy.

We do not write your submission

Your regulatory team owns the submission, the security risk management file and the SBOM. We give you a test report they can put into it, and we will answer questions about it.

We do not clear your device

The FDA reviews the whole submission. A good test report is necessary, not sufficient, and any supplier implying otherwise is selling.

We do not write your findings assessment

The guidance asks manufacturers for their own assessment of every finding, including the rationale where something is deferred. That reasoning has to be yours — our job is to describe the finding precisely enough that you can write it. A tester who helped author your assessment of their own findings would undercut the independence the guidance asks us to have.

Bring us the device and the deadline.

Tell us what is going into the submission and when it has to be there, and we will tell you what testing it needs.

Talk to usMedical device testing