Penetration Testing Services › FDA cyber security testing
FDA premarket submissions
Your reviewer reads our report,
not a summary of it.
FDA guidance says that where a third party performs the testing, the manufacturer should provide the original third-party report. Ours is written on the assumption that a reviewer reads it exactly as submitted.
What the rules actually say
Where a penetration test fits
Section 524B applies to cyber devices
Added to the FD&C Act at the end of 2022 and effective from March 2023, it obliges the sponsor of a premarket submission for a cyber device to include cyber security information. This is the binding instrument; the guidance below is how the FDA says to satisfy it.
The guidance points at third-party testers
It says that in some cases it may be necessary to use third parties to ensure an appropriate level of independence between those testing the device and those who designed it. Independence is not a formality here — it is one of the five things the report has to establish.
The original report goes in
Not a summary, not a certificate: the guidance asks manufacturers to provide the original third-party report. That makes report quality part of the submission rather than a courtesy to your engineers.
Section V.C
The five elements, and what we put against each
Guidance for a penetration test report, and the part of our deliverable that answers it.
| What the guidance asks a report to contain | What is in ours |
|---|---|
| Independence and technical expertise of testers | The named testers who did the work, their qualifications, and our independence from your development team — stated on the report itself, not supplied on request. |
| Scope of testing | The exact system boundary tested — device, firmware, companion app, cloud, the protocols between them — and, just as explicitly, what was out of scope. |
| Duration of testing | The engagement dates and the effort behind them, proportionate to the complexity of the system rather than to a template. |
| Testing methods employed | The methodology, the tools with their versions and configuration, and the manual work — mapped to our published test catalogue so a reviewer can see what was covered. |
| Test results, findings, and observations | Every finding with reproduction steps, evidence, severity and remediation guidance — and the things we tried that did not work, which is what makes the rest credible. |
Source: FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026, section V.C. Supersedes the 27 June 2025 edition. The guidance is marked Contains Nonbinding Recommendations; the binding requirement is section 524B of the FD&C Act. Read the guidance
Penetration testing is not the only testing named
Security requirements
Evidence that each design input requirement was implemented, plus the boundary analysis and the rationale behind its assumptions.
Threat mitigation
Evidence that your risk controls actually hold — tested against the threat model rather than assumed from it.
Vulnerability testing
Abuse and misuse cases, malformed input, robustness and fuzzing, attack surface analysis, vulnerability chaining, known-vulnerability scanning, software composition analysis of binaries, and static and dynamic analysis including hardcoded and default credentials.
A penetration test is one item on that list, not a substitute for it. We do the testing work above where it is in scope, and we say plainly which parts we did not do rather than letting a submission imply otherwise.
Where we stop
Worth saying out loud, because the boundary is what makes the rest trustworthy.
We do not write your submission
Your regulatory team owns the submission, the security risk management file and the SBOM. We give you a test report they can put into it, and we will answer questions about it.
We do not clear your device
The FDA reviews the whole submission. A good test report is necessary, not sufficient, and any supplier implying otherwise is selling.
We do not write your findings assessment
The guidance asks manufacturers for their own assessment of every finding, including the rationale where something is deferred. That reasoning has to be yours — our job is to describe the finding precisely enough that you can write it. A tester who helped author your assessment of their own findings would undercut the independence the guidance asks us to have.
Bring us the device and the deadline.
Tell us what is going into the submission and when it has to be there, and we will tell you what testing it needs.