Whitepaper · October 3, 2025
Joint Security Plan (JSP) Quick Reference Guide: Who Does What, When, and Why
The JSP Quick Reference Guide helps medical device teams understand their role in building and maintaining a secure product. Using the cybersecurity house analogy, it simplifies complex regulatory requirements into four phases — Concept, Design & Development, Verification & Validation, and Maintenance — so everyone, from product managers to executives, can see where they fit and what’s expected of them.

Executive summary
What this whitepaper covers
The Joint Security Plan (JSP) is the medical technology industry’s framework for embedding cybersecurity across the total product lifecycle. Medcrypt’s JSP Quick Reference Guide distills this comprehensive plan into a practical, shareable resource that helps teams understand who does what, when, and why in building secure medical devices. Using a simple “house” analogy — Foundation (Concept), Framing (Design & Development), Inspection (Verification & Validation), and Maintenance (Postmarket) — this guide makes it easy for product teams, executives, and service functions to align on their cybersecurity responsibilities and regulatory expectations.
Why it matters
The regulatory and product context
The JSP is the backbone of medical device cybersecurity, but many teams struggle to operationalize it. This guide bridges that gap, translating complex regulatory requirements into clear, actionable steps. As the FDA, HSCC, and AAMI continue to emphasize secure-by-design development and lifecycle traceability, understanding the JSP isn’t optional; it’s essential to achieving compliance, building resilient products, and fostering trust with hospitals and regulators.
Key insights
What you’ll take away
- The JSP maps cybersecurity activities across all phases of product development.
- Every function, from engineers to executives, plays a role in securing the product.
- Clear documentation and evidence are essential for FDA and regulatory alignment.
- Lifecycle management (SBOMs, patching, surveillance) is an ongoing responsibility.
- The JSP complements standards like IEC 81001-5-1, offering a “what and why” overview alongside “how and when” resources.
Who should read this
- Product Managers, Engineers, and QA/RA professionals responsible for lifecycle documentation
- Executives and cybersecurity program leaders ensuring organizational readiness
- Clinical and usability teams validating safety and workflow compatibility
- Sales, marketing, and service teams who communicate security value to customers
