The cybersecurity partner medical device manufacturers trust from first 510(k) to postmarket maturity. Senior-led, MedTech-only, fixed-fee.
FDA submissions supported across 510(k), De Novo, and PMA
Cybersecurity rejections to date across every submission
Median first-pass FDA deficiency response
Fee, scoped revisions, no surprise change orders
Med Device Cyber Podcast episodes published
MedTech security roots, narrowed to MedTech-only by 2017
A sample of manufacturers we've supported through FDA cybersecurity submissions, pen testing, threat modeling, and postmarket programs.






Cybersecurity Partner of the Year
Solution of the Year, cover story
Service Provider Excellence
Pacemakers, ICDs, cardiac monitors, AEDs
Robot-assisted surgery, navigation, energy devices
Smart pumps, insulin systems, auto-injectors
MRI, CT, ultrasound, X-ray, AI-assisted reads
Patches, continuous monitors, remote patient programs
Lab analyzers, point-of-care, genomics, NGS
DBS, SCS, vagus and peripheral nerve stimulators
Decision support, image analysis, PCCP-enabled devices
Oxygen concentrators, ventilators, breath analysis
Surgical, diagnostic, and vision-care systems
Navigation, implants, ortho and dental systems
Prescription DTx and connected therapy apps
Four engagement shapes, pick what matches your milestone, not what fills a retainer. Every engagement is fixed-fee, scoped before kickoff, with a 24-hour proposal SLA.
| Model | Best for | Typical timeline |
|---|---|---|
| FDA Premarket Package (flagship) | End-to-end 510(k)/De Novo/PMA cyber submission | 6 to 8 weeks |
| Single-deliverable | One artifact (pen test, threat model, SBOM) | 2 to 6 weeks |
| Deficiency surge | Active FDA cybersecurity AI letter | 48 hr to 30 days |
| Postmarket retainer | Cleared device, ongoing obligations | Continuous |
The later a cybersecurity gap surfaces, the more it costs to fix, and the more it threatens your clearance timeline. Engaging at concept is the cheapest insurance you can buy.
Illustrative. Industry studies consistently show 10–100× remediation cost between design and postmarket stages.
Each FDA deficiency round adds 30 to 90 days of review clock. In-field findings stop shipments.
Late-stage fixes touch firmware, architecture, and labeling. Engineering hours scale with how late they land.
A vulnerability that surfaces postmarket can trigger a Safety Communication, recall, or 522 order.
Deficiency letters that bounce a second time force a new 90-day review cycle and reset the clearance plan.
Postmarket incidents pull in MDR reporting, FDA Form 483 observations, and potential plaintiff exposure.
Mapped 1:1 to FDA Section 524B and the Feb 3, 2026 premarket cybersecurity guidance. Every phase produces evidence the FDA will ask for, in the format reviewers expect.
Design-input review, asset inventory, STRIDE + patient-safety threat model, and a defensible attack surface map. Output: threat model document and security risk registry.
Security architecture views, control selection (IEC 81001-5-1), data-flow diagrams, and trust-boundary documentation aligned with the risk management file.
SBOM generation (CycloneDX/SPDX), VEX statements, static/dynamic analysis, and full penetration testing across hardware, firmware, wireless, mobile, cloud, and AI/ML surfaces.
Submission package drafting, eSTAR mapping, reviewer Q&A, and rapid response to any cybersecurity deficiency letter, typically within 48 hours.
CVD program, SBOM/VEX maintenance, KEV monitoring, incident playbooks, and annual reassessment aligned with the FDA's postmarket guidance.
FDA submissions supported
Cyber-related submission failures
Median deficiency response
Senior-led, US-based delivery
A pre-revenue wearable startup engaged us 9 weeks before submission with no formal threat model, an incomplete SBOM, and zero pen test evidence. We delivered the full 524B package: STRIDE plus patient-safety threat model, CycloneDX SBOM with VEX, hardware, firmware, and mobile pen test, architecture views, and labeling. All eSTAR-ready in 7 weeks. The device cleared on first review with zero cybersecurity deficiencies.
"Their report helped us achieve FDA clearance without any additional questions. It was a truly seamless experience."
In the field
We earn trust the same way we earn submissions, by showing up. Recent moments from MedTech World North America, EU, and partner stages.








Every engagement is led by someone on this page. The same people who scope your project are the ones writing your threat model, running your pen test, and defending your submission.

U.S. Air Force Academy graduate and veteran, 30+ years in cybersecurity. Founded Alpine Security (acquired by CISO Global, 2020), then Blue Goat Cyber in 2022. Author of the forthcoming Medical Device Cybersecurity (2026). 275+ FDA submissions supported.
Full bio
Heads Blue Goat's penetration testing practice across hardware, firmware, wireless, mobile, cloud, and AI/ML, plus red-team and physical assessments and product security consulting. 18+ years in IT, 13+ in cybersecurity. Previously Principal Consultant at Cerberus Sentinel; led pen testing at Alpine Security.

Owns the regulatory and compliance lane across FDA premarket and postmarket submissions. Aligns cybersecurity evidence with Section 524B, eSTAR, and the broader regulatory file so every package holds together end-to-end.

Builds and grows Blue Goat's channel and partner network. Former cardiac stepdown nurse, brings clinical insight to MedTech partnerships with consultants, regulatory experts, and technology vendors.

Global commercial leader with 25+ years across life sciences, medical device, and MedTech. Background spans sales, marketing, business development, and operations, including product launches and go-to-market strategy.

Drives complex MedTech cybersecurity engagements from kickoff through FDA clearance. Coordinates technical, QA, and regulatory workstreams to keep submissions moving and clients informed at every checkpoint.

Owns engagement timelines, deliverables, and FDA interactions end-to-end. Keeps threat models, pen tests, SBOMs, and submission packages on rails so engineering and regulatory teams stay aligned without surprises.
Scope your device, indication, and target submission date.
Fixed-fee proposal with deliverables and timeline, signed before kickoff.
Senior team mobilized, design inputs reviewed, threat model started.
Submission-ready artifacts produced in the format CDRH reviewers expect.
Deficiency response inside the FDA's clock, then postmarket sustain.
Download the designed PDF to share with stakeholders, procurement, and regulatory teams.
Download the PDFMedical device security is patient safety.
Why we exist: so the devices people depend on can't be turned against them.
Connected medical devices that are secure by design and resilient for their entire service life.
The world we are working toward, with no end date.
By 2028, help medical device teams get 1,000 devices through FDA review with zero cybersecurity-driven rejections, and teach the industry to start cybersecurity early.
What we do daily, with a deadline: secure the devices in front of us, and through books, stages, podcasts, webinars, and mentoring, help every other team understand what cybersecurity means for their device before it costs them.
Full story, mission, and the team behind the work.
Christian Espinosa, USAFA, MBA, 30+ years in cyber.
Premarket, postmarket, pen testing, SBOM, and more.
Anonymized outcomes from real FDA submissions.
What sets our methodology apart from generalist firms.
Scope an engagement or request a fixed-fee proposal.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.