Security evidence for medical devices with software

Penetration tests and secure development support for approval per MDR and FDA.

Your starting point

Anyone bringing a medical device with a software component or software as a medical device (SaMD) to market must demonstrate cybersecurity across the entire product lifecycle:

  • EU (MDR): The MDR’s general safety and performance requirements include cybersecurity. In practice, the evidence is provided via IEC 81001-5-1 (secure software lifecycle activities) and the guidance MDCG 2019-16. Both call for targeted security tests, usually penetration tests, whose results feed into the technical documentation for the notified body.
  • USA (FDA): For products with software and a data interface (“cyber devices”, Section 524B FD&C Act), the FDA requires documented cybersecurity in the approval process: vulnerability management across the product lifecycle, a software bill of materials (SBOM) and security testing. The FDA premarket guidance explicitly names penetration tests.

Without this evidence, approval is delayed or fails. With it, security turns from a mandatory item into a selling point toward hospitals and operators.

What we do for you

  • Penetration tests for devices, apps, interfaces and backend systems, from embedded hardware to cloud connectivity. You will find a detailed example of a networked medical device on our pentest page.
  • Architecture reviews and threat modeling, so that security requirements land early in the design rather than late in the findings report.
  • Secure development: we anchor the required lifecycle process in your development, from policies through training to code reviews.
  • Approval-ready reports: traceable methodology, severities per CVSS, retest after remediation. Structured so that they can be incorporated into your technical documentation for notified bodies or FDA submissions.

Why zentrust in medical technology

  • Experience with manufacturers: We test and support manufacturers of medical devices with software and of software as a medical device.
  • Research experience in health IT: we know the attack surfaces of networked health systems from our own security research, from e-health platforms to the telematics infrastructure.
  • Testing and advice from one source: whoever finds the vulnerabilities also helps close them, all the way to a passed retest.
  • You can find our company certifications about us.

Do you run a hospital or are you a health insurer? For healthcare providers we have a dedicated page: Information security in healthcare.

Effective security for your organization.

A short conversation about your product, your approval path and your timeline. That determines which tests and evidence make sense, and when.