Why FDA asks for a threat model
Section 524B of the FD&C Act requires "cyber devices" to show they were designed with reasonable assurance of cybersecurity.
FDA's premarket cybersecurity guidance names the threat model as the starting point for that evidence. It feeds your risk assessment, your security requirements and your test plan.
A thin or generic threat model is a common finding in FDA cybersecurity reviews.
How it works for your team
Build your first draft
Start from what you have.
Upload AWS, Visio or Draw.io diagrams and link your source repos. No re-drawing.
Get a first draft in hours, not weeks.
MSI generates threat scenarios and attack trees using STRIDE or your team's own method, and checks CVSS scores for consistency.
Illustrative threat register
For your team
- You find design problems earlier, before pen testing, when they're cheaper to fix.
- The same team covers the whole portfolio. No new hires for each device.
Review and prepare your submission
Expert review.
Former FDA CDRH reviewers read the model the way an FDA reviewer would, and flag the gaps.
Export for your submission.
The output lines up with ISO 14971 and AAMI SW96 templates, so it drops into your risk file.
Illustrative review checkpoint
For your team
- The FDA paperwork comes out of the security work, rather than being written afterwards.
What customers say
"In the course of filing for a 510(k) clearance we needed to establish a threat model that meets regulator's expectations. Medcrypt not only helped us with their deep expertise but even more with the excellent understanding of our company-specific needs."

FAQ
Automation does the first draft. FDA expects the model to reflect your device and your engineering decisions, which is why every MSI model is reviewed by people who have done FDA reviews.
STRIDE, attack trees and other recognized methods. We work in your team's existing approach rather than replacing it.
If it includes software, can connect to the internet, and could be vulnerable to cybersecurity threats, assume yes. "Can connect" means the capability, not just the intended use.
Yes. See threat modeling training.
Threat modeling training