Security Requirements Testing vs Penetration Testing
Security requirements testing verifies your design inputs; penetration testing attacks the built device. What the FDA's Feb 2026 guidance expects for each.
Read articleEvery article in our archive tagged Primer.
Looking for a quick answer instead? The FDA medical device cybersecurity FAQ covers Section 524B scope, SBOMs, threat models, CR515 and GMLP, deficiencies, and postmarket duties.
Showing 12 of 121 articles tagged Primer · Page 1 of 11
Security requirements testing verifies your design inputs; penetration testing attacks the built device. What the FDA's Feb 2026 guidance expects for each.
Read article
You're two years into product development and still "not ready" for cybersecurity? You're already late.
Read article
A phase-by-phase mapping of the FDA's SPDF onto IEC 81001-5-1 activities, so dual FDA + EU submissions produce one artifact set instead of two.
Read article
IEC 62304 governs the software lifecycle. IEC 81001-5-1 adds security activities on top.
Read article
JSP2 is a development framework, MDS2 is a procurement disclosure form. Here's how the two artifacts complement each other across the device lifecycle.
Read article
The FDA lists JSP2, SPDF, IEC 81001-5-1, and ISA/IEC 62443-4-1 as acceptable cybersecurity frameworks. Here's how to actually pick one for your submission.
Read article
The 2026 FDA premarket cybersecurity submission checklist: the six Section 524B deliverables reviewers score on 510(k), De Novo, and PMA filings.
Read article
SPDF vs SSDLC for medical devices. Why the FDA's Secure Product Development Framework demands more than a standard Secure SDLC, and what to add.
Read article
What the FDA's Feb 2026 guidance recommends for IDE cybersecurity: informed consent, architecture views, SBOM, labeling, and what's not required yet.
Read article
MQTT is one of the most common protocols in IoMT and one of the most commonly misconfigured.
Read article
How to build FDA-defensible fuzz harnesses for the protocols medical devices actually speak.
Read article
How to operationalize SBOM diffing and CVE correlation across releases so postmarket vulnerability monitoring holds up under FDA Section 524B and the Feb.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.