Your starting point
Anyone bringing a medical device with a software component or software as a medical device (SaMD) to market must demonstrate cybersecurity across the entire product lifecycle:
- EU (MDR): The MDR’s general safety and performance requirements include cybersecurity. In practice, the evidence is provided via IEC 81001-5-1 (secure software lifecycle activities) and the guidance MDCG 2019-16. Both call for targeted security tests, usually penetration tests, whose results feed into the technical documentation for the notified body.
- USA (FDA): For products with software and a data interface (“cyber devices”, Section 524B FD&C Act), the FDA requires documented cybersecurity in the approval process: vulnerability management across the product lifecycle, a software bill of materials (SBOM) and security testing. The FDA premarket guidance explicitly names penetration tests.
Without this evidence, approval is delayed or fails. With it, security turns from a mandatory item into a selling point toward hospitals and operators.
What we do for you
- Penetration tests for devices, apps, interfaces and backend systems, from embedded hardware to cloud connectivity. You will find a detailed example of a networked medical device on our pentest page.
- Architecture reviews and threat modeling, so that security requirements land early in the design rather than late in the findings report.
- Secure development: we anchor the required lifecycle process in your development, from policies through training to code reviews.
- Approval-ready reports: traceable methodology, severities per CVSS, retest after remediation. Structured so that they can be incorporated into your technical documentation for notified bodies or FDA submissions.
Why zentrust in medical technology
- Experience with manufacturers: We test and support manufacturers of medical devices with software and of software as a medical device.
- Research experience in health IT: we know the attack surfaces of networked health systems from our own security research, from e-health platforms to the telematics infrastructure.
- Testing and advice from one source: whoever finds the vulnerabilities also helps close them, all the way to a passed retest.
- You can find our company certifications about us.
Do you run a hospital or are you a health insurer? For healthcare providers we have a dedicated page: Information security in healthcare.
