
On this page
Published:
MedTech is the industry that builds technology to diagnose, treat and monitor patients. A medical device is a legal category defined by the FDA, and it includes simple items like scalpels and sutures. Life sciences is broader still, covering pharma and biotech as well as MedTech. For cybersecurity, the group that matters is the cyber device: a medical device with software that can connect to a network.
People use "MedTech," "medical device" and "life sciences" as if they mean the same thing. They don't, and the mix-up has real costs. A founder who thinks every product in MedTech needs an SBOM and a penetration test may overspend. A founder who assumes a connected app is "just software" may miss that the FDA regulates it as a device, and that FDA Section 524B applies. Investors, recruiters and suppliers each use the terms loosely too, which adds to the noise.
This post sorts the four terms from widest to narrowest: life sciences, MedTech, medical device and cyber device. Along the way we use everyday examples, from a scalpel to an insulin pump, to show where each product lands and what that means for the FDA and for cybersecurity.
Why this matters
The category a product falls into decides which rules apply. Being "in MedTech" carries no regulatory weight on its own. Being a "medical device" does: it brings FDA classification, premarket pathways such as 510(k), De Novo or PMA, and quality system requirements. Being a "cyber device" adds another layer on top.
Section 524B of the FD&C Act, added in 2022, requires sponsors of cyber devices to include cybersecurity information in their premarket submissions. That includes a plan to monitor and address vulnerabilities after release, processes that give reasonable assurance the device is secure, and a software bill of materials (SBOM). The FDA's final guidance, "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions," dated February 3, 2026, explains what reviewers expect to see.
None of that applies to a scalpel. All of it applies to a Bluetooth-connected insulin pump. Knowing which side of the line a product sits on shapes budgets, timelines and hiring from the start. It also stops teams from treating cybersecurity as a late add-on when their product clearly needs it, which is one of the most common reasons submissions stall.
What is life sciences?
Life sciences is the umbrella term. It covers companies that study living things and turn that research into products for health. It usually includes three big groups:
- Pharmaceuticals: drugs made from chemical compounds, such as pain relievers or statins.
- Biotechnology: products made from living systems, such as vaccines, gene therapies and antibodies.
- MedTech: the technology used to diagnose, treat and monitor patients.
Life sciences also includes research tools, lab equipment suppliers and contract research firms. When a consulting firm or investor says "life sciences," it usually means all of these at once. For a device maker, the term is too broad to be much help. Drug rules and device rules follow very different paths at the FDA.
What is MedTech?
MedTech, short for medical technology, is the part of life sciences that builds tools rather than drugs or biologics. It is an industry term, not a legal one. MedTech usually includes:
- Medical devices of every kind, from tongue depressors to MRI scanners
- In vitro diagnostics (IVDs), such as blood glucose test strips and lab analyzers
- Software as a Medical Device (SaMD), such as an app that reads ECG data to flag an irregular rhythm
- Digital health products, some regulated and some not, such as wellness trackers
That last point is where the confusion starts. A step-counting fitness band is often called MedTech, but if it makes no medical claims, the FDA generally treats it as a low-risk wellness product, not a medical device. A smartwatch feature cleared to detect atrial fibrillation is a medical device. Same industry, very different obligations.
One more source of mix-ups: "med tech" is also a job title. In many places it is short for medical technologist, a lab professional. Searches for "what is a medtech" often mean the job, not the industry.
What is a medical device?
"Medical device" is a legal term. Section 201(h) of the Federal Food, Drug, and Cosmetic Act defines a device as an instrument, apparatus, machine, implant, in vitro reagent or similar item intended to diagnose, cure, treat or prevent disease, or to affect the structure or function of the body, and which does not achieve its main purpose through chemical action or metabolism. That last part is what separates a device from a drug.
The FDA sorts devices into three classes by risk:
| Class | Risk | Everyday examples | Typical path |
|---|---|---|---|
| Class I | Low | Scalpels, tongue depressors, elastic bandages | Often exempt from premarket review |
| Class II | Moderate | Sutures, powered wheelchairs, insulin pumps, infusion pumps | Usually 510(k) |
| Class III | High | Pacemakers, implantable defibrillators, heart valves | Usually PMA |
So yes, a scalpel is a medical device. So is a suture. Neither has software, a battery or a radio, and that matters for what comes next. Our post on the different classes of medical devices according to the FDA goes deeper on classification.
Software can be a medical device too. If software is intended to diagnose or treat a condition on its own, it is SaMD, even with no physical hardware at all.
What is a cyber device?
A cyber device is a narrower group inside medical devices. Under FDA Section 524B, a cyber device is a device that:
- Includes software validated, installed or authorized by the sponsor, as a device or in a device
- Has the ability to connect to the internet
- Contains technological characteristics that could be vulnerable to cybersecurity threats
The FDA reads "ability to connect" broadly. A device that pairs with a phone over Bluetooth, which then reaches the internet, can qualify. So can a device with a USB port used for updates. Our guide on what counts as a cyber device under Section 524B walks through edge cases.
Sponsors of cyber devices must submit a plan to monitor, identify and address postmarket vulnerabilities, show processes that provide reasonable assurance the device is cybersecure, and provide an SBOM covering commercial, open source and off-the-shelf software components.
See also: CVSS Scoring for Medical Devices: A Complete Walkthrough, Medical Device Software Development: A Compliance Guide, and When to Start Medical Device Cybersecurity.
For a device like a Bluetooth insulin pump, that means planning for postmarket cybersecurity and secure product design from the start, not after the first test.
Where do everyday products land?
Here is how common products fall across the four terms:
| Product | Life sciences? | MedTech? | Medical device? | Cyber device? |
|---|---|---|---|---|
| Statin tablet | Yes | No | No (a drug) | No |
| Scalpel | Yes | Yes | Yes, Class I | No |
| Absorbable suture | Yes | Yes | Yes, Class II | No |
| Basic digital thermometer, no connectivity | Yes | Yes | Yes | Usually no |
| Fitness tracker with no medical claims | Loosely | Often called MedTech | Generally no | No |
| Bluetooth insulin pump | Yes | Yes | Yes, Class II | Yes |
| ECG analysis app (SaMD) | Yes | Yes | Yes | Often yes |
| Pacemaker with wireless telemetry | Yes | Yes | Yes, Class III | Yes |
The pattern is simple. Moving down the list, products pick up software and connectivity, and that is what adds cybersecurity work. A suture maker has quality system and biocompatibility work to do, but no SBOM. An insulin pump maker has all of that plus threat modeling, penetration testing, an SBOM and a postmarket vulnerability plan. Our full-service FDA premarket cybersecurity package brings those pieces together for connected devices like the pump, the ECG app and the pacemaker in the table.
Common points of confusion
"We're MedTech, so we need FDA clearance." Not always. Clearance depends on whether the product is a medical device and what class it falls into, not on the industry label.
"It's only an app, so it isn't a device." Software that diagnoses or treats a condition can be a device on its own. Software running on a device is part of that device.
"Our device has no Wi-Fi, so 524B doesn't apply." Bluetooth, USB, NFC and wired service ports can all count as connectivity. Check before assuming.
"Life sciences and MedTech are the same market." They overlap, but drug makers and device makers answer to different FDA centers and follow different submission paths.
How Blue Goat approaches this
When a new client comes to us, the first question isn't about tools or tests. It's about scope: is this product a medical device, and is it a cyber device under Section 524B? We look at the software, every interface (wireless, wired and removable media) and how updates reach the device. That answer sets the rest of the plan.
For cyber devices, we then map the work to what the FDA expects in the submission: threat modeling, security risk management, an SBOM, penetration testing and a postmarket vulnerability plan. Our full-service FDA premarket cybersecurity package covers those pieces in one engagement. For teams that only need testing, our medical device penetration testing service tests the device and its connected parts. If a product turns out not to be a cyber device, we say so. There's no reason to pay for work the FDA doesn't expect.
FAQ
Is MedTech the same as a medical device?
No. MedTech is an industry term that covers medical devices, diagnostics, SaMD and some digital health products. "Medical device" is a legal term defined in Section 201(h) of the FD&C Act. Every medical device is part of MedTech, but not every MedTech product is a medical device. A wellness tracker with no medical claims, for example, is often called MedTech but is generally not regulated as a device.
Is a scalpel a medical device?
Yes. A manual scalpel is a Class I medical device, the lowest risk class. Many Class I devices are exempt from premarket review, though makers still register with the FDA and follow general controls. A scalpel has no software or connectivity, so it is not a cyber device and needs no cybersecurity documentation in any submission.
Are sutures a medical device?
Yes. Surgical sutures are regulated as medical devices, and most types are Class II, which usually means a 510(k) submission. Sutures have no software or network connection, so FDA Section 524B does not apply. Their main regulatory focus is material safety, strength, sterility and biocompatibility rather than cybersecurity.
What is the difference between life sciences and MedTech?
Life sciences is the broad group of companies working on health products from living systems and science, including pharma, biotech and MedTech. MedTech is one part of it, focused on devices, diagnostics and health software rather than drugs or biologics. The difference matters at the FDA, where drugs, biologics and devices follow separate review paths.
Does every medical device need cybersecurity documentation?
No. Section 524B applies to cyber devices: devices with sponsor software that can connect to the internet and could be vulnerable to cyber threats. A scalpel or suture needs none. Many connected devices do, and the FDA reads connectivity broadly, including Bluetooth and USB. When in doubt, check the device against the definition early in development.
Is software a medical device?
It can be. Software intended to diagnose, treat, cure or prevent a disease on its own is Software as a Medical Device (SaMD). Software that runs inside hardware, such as pump firmware, is part of that device. Either way, if the software can connect to a network, the product may be a cyber device under Section 524B.
CTA
Not sure whether your product counts as a cyber device, or what the FDA will expect in your submission? Book a short call with our team. We'll look at your device's software and interfaces, tell you plainly whether Section 524B applies, and outline the documentation you'll need.
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
