Medical device cybersecurity services from former FDA reviewers

Expert support for FDA submissions and the security work that follows, including regulatory readiness, threat modeling, SBOMs, and incident response.

The most expensive submission is the one you have to file twice.

100%FDA approval rate since 2023
45-60 daysAINN response time, reduced from 180 days
200+successful projects across 60+ clients

Premarket cybersecurity services

Prepare your security evidence for FDA review and build cybersecurity into your development process.

  • FDA submission readiness

    Prepare cybersecurity evidence for submissions and requests for additional information.

    Regulatory cybersecurity readiness

    Navigate regulatory complexities with ease. Whether preparing a submission or addressing FDA requests for additional information, our experts work with you to achieve FDA clearance or approval efficiently.

    See FDA submission readiness
  • Threat modeling

    Connect your threat model and risk assessment to device risk management.

    Threat modeling and risk mitigation

    Navigating FDA cybersecurity requirements is complex. Our experts simplify the process using the AAMI TIR-57/SW96 framework, helping you develop or refine your Threat Model and Cybersecurity Risk Assessment to align with your device’s Risk Management Process from analysis to review.

    See threat modeling
  • Maturity assessments

    Benchmark your security capabilities, identify gaps, and plan improvements.

    Cybersecurity maturity assessments

    Advance your security posture with a tailored assessment that benchmarks your security capabilities, identifies gaps, and provides a roadmap for improvement.

  • PKI and cryptography

    Assess certificate management and identify practical mitigations for medical devices.

    PKI and cryptography analysis

    We assess your PKI and certificate management practices, perform gap analysis with industry best practices and regulatory guidance, and develop realistic and actionable mitigation strategies for medical devices.

    See encryption and key security
  • FDA hold letter response

    Get guidance on interpreting and responding to an FDA hold letter.

    In the event of an FDA hold letter, Medcrypt provides immediate guidance to navigate the response process effectively.

    See FDA cybersecurity deficiency response
  • SDLC integration

    Build SBOMs, vulnerability scanning, and security testing into device development.

    Our experts help you integrate SBOM generation, vulnerability scanning, and security testing considerations into your development lifecycle, ensuring continuous security validation throughout development.

  • Penetration testing support

    Connect device risks, testing findings, remediation, and retesting to FDA evidence.

    Medical device penetration testing

    Plan testing around device risks and connect findings, remediation, and retesting to your FDA evidence.

    See medical device penetration testing

Postmarket cybersecurity services

Keep your device security, response plans, and documentation current after clearance.

  • Risk management

    Prioritize threats by patient safety, exploitability, and regulatory requirements.

    Cybersecurity risk management

    We help you prioritize cybersecurity threats based on patient safety impact, exploitability, and regulatory requirements using proven methodologies. We assess your security posture, help you prioritize risks, and develop a strategic roadmap that aligns security investments with industry standards and regulatory requirements.

  • SBOM monitoring

    Validate SBOMs and track emerging vulnerabilities in third-party software components.

    SBOM validation and monitoring

    Automated SBOM validation and continuous monitoring to track and mitigate emerging vulnerabilities in third-party components, helping ensure compliance with regulatory requirements.

    See SBOM and vulnerability management
  • Regulatory change management

    Keep device security and documentation aligned with evolving cybersecurity requirements.

    Proactive tracking of evolving cybersecurity regulations, guidance and standards, including FDA and global requirements, with strategic guidance to keep your device security and documentation aligned with the latest compliance expectations.

  • Incident response

    Test and refine response plans through simulated incident tabletop exercises.

    Cybersecurity incident response

    Prepare for real-world threats with our Incident Response Tabletop Exercise. We simulate attacks to test, refine, and validate your response plans.

    See incident response
  • Vulnerabilities and patches

    Plan ongoing monitoring and regulatory-compliant device patches and updates.

    Vulnerability management and patch strategy

    We'll work with you to establish processes for continuous monitoring of vulnerabilities and threats. This includes developing regulatory-compliant patching and update strategies to ensure the ongoing integrity of your medical devices.

    See response and patch strategy
  • Legacy device security

    Assess older-device risks, unsupported components, compensating controls, and support needs.

    Legacy medical device cybersecurity

    Assess cybersecurity risk in devices already in use and plan for unsupported components, compensating controls, and the device support lifecycle.

    See legacy device cybersecurity support

Meet the experts

Work with former FDA staff and specialists in medical device security.

Naomi Schwartz

Naomi Schwartz

Former FDA premarket reviewer and consumer safety officer

Prior to Medcrypt, she was a premarket reviewer and consumer safety officer in CDRH for 6+ years, focusing on software, interoperability, and cybersecurity for connected diabetes devices. She holds an MS in Electrical and Computer Engineering from Carnegie Mellon University and is a Certified Quality Auditor.

Seth Carmody

Seth Carmody

Eight years at the FDA

Prior to Medcrypt, he spent 8 years at the FDA, architecting technology policy and laws that impact software-enabled medical devices, including the FDA’s medical device cybersecurity policies. He holds a PhD in Chemistry from Indiana University.

AJ Reiter

AJ Reiter

Digital transformation and business optimization

AJ started his career as a management consultant specializing in Digital Transformation and Business Optimization for the enterprise space. AJ holds a degree from Georgetown where he majored in Economics.

Nick Atwell

Nick Atwell

PKI, risk management, and regulatory compliance

Nick is a cybersecurity expert with extensive experience in PKI, Risk Management, and regulatory compliance. Previously, Nick led PKI initiatives at Cerner, managing enterprise cryptographic infrastructure and implementing automation to streamline security processes.

Preparing a submission outside the US?

Review the cybersecurity expectations for Canadian licensing and European market access.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness