
On this page
Published:
Key Takeaways
- If your device runs software and can connect, plan as if Section 524B applies to it.
- Your first premarket submission needs a threat model, SBOM, security testing and a postmarket plan.
- Security decisions made before design freeze are far cheaper than fixes made after it.
- Sequence the work: readiness review, threat model and architecture, then penetration testing on a stable build.
- Investors ask about cybersecurity in diligence; a written plan answers them.
- A Pre-Sub can confirm your cybersecurity approach with the FDA before you file.
When should a medical device startup start cybersecurity work?
Medical device startups should start cybersecurity during early design, not after design freeze. If the device has software and can connect, Section 524B likely applies, so the first FDA submission needs a threat model, SBOM, security testing and a postmarket vulnerability plan. Starting early keeps costs down and gives investors a clear answer in diligence.
Startups ask us the same few questions: Do we need this yet? What will the FDA want? What does it cost? This page answers those for a team building its first connected device. If you are new to the topic, start with our guide, What Is Medical Device Cybersecurity?
Last reviewed: October 2026 against Section 524B of the FD&C Act and the FDA's February 3, 2026 final premarket cybersecurity guidance.
Why this matters for a startup
A startup usually has one device, one runway and one shot at a clean first submission. Cybersecurity gaps found late force redesigns of things like boot security, update mechanisms or wireless pairing, and those changes ripple through testing and documentation. Our post on cybersecurity before MVP vs after market fit walks through what waiting costs.
Is your device a cyber device?
Section 524B covers devices that include software, can connect to the internet and could be vulnerable to cybersecurity threats. Bluetooth, Wi-Fi, USB, a companion app or a cloud service can all bring a device into scope, and device class does not exempt it. See Section 524B explained for the statutory text.
What the FDA will expect in your first submission
The February 2026 guidance describes the cybersecurity content of a premarket submission. In practice, that is a set of deliverables including:
- A threat model and cybersecurity risk assessment
- Architecture views showing how data and trust move through the system (architecture views guide)
- A software bill of materials with known-vulnerability review
- Penetration testing and other security testing
- A postmarket plan for monitoring and fixing vulnerabilities
Our 18-deliverables eSTAR map lists every item and where it goes in eSTAR.
A startup timeline that works
- Early design: run the early-stage readiness checklist and fix gaps while changes are cheap.
- Architecture settling: build the threat model and architecture views; pick SBOM tooling.
- Before filing: consider a Pre-Sub to confirm your approach with the FDA.
- Design stable: run penetration testing on a near-final build and close findings.
- Submission: assemble the package. A full package typically takes us 6 to 8 weeks.
What it costs
A penetration test for a simple device with no travel starts at about $15,000. A full premarket cybersecurity package is quoted as a fixed fee after a scoping call, because scope depends on the device. More detail is in medical device cybersecurity cost.
What investors ask
Investors and acquirers want to know the FDA path will not stall on cybersecurity. Expect questions like: Is the device a cyber device? Is there a threat model? Who owns the SBOM? What happens when a vulnerability is found after launch? A written plan with a timeline answers all of them.
How Blue Goat Cyber approaches this
We work only on medical devices. For startups, we start with a scoping call, then offer two paths: a full-service FDA premarket cybersecurity package, or a penetration test once the design is stable. Every engagement has a fixed fee, a project manager, a shared Slack channel and secure file sharing. Testing is done in-house, and retests are included until findings are closed. We have supported 275+ devices.
FAQ
Is it too early to think about cybersecurity before we have a prototype?
No. Architecture decisions such as how the device updates, authenticates and talks to apps set most of your security posture. Reviewing them early is the cheapest time to change them.
Do Class I or Class II devices need cybersecurity?
If the device meets the Section 524B definition and needs a premarket submission, yes. Class alone does not decide it. See device class and cybersecurity scope.
Can we do the cybersecurity work ourselves?
Some teams draft parts in-house. The FDA expects independent, objective security testing, and the documentation has to tie together across risk, testing and the SBOM, which is where first-time teams often get deficiency questions.
When should we do penetration testing?
When the hardware, firmware and software are close to final. Testing an early prototype usually means testing again.
Building your first connected device?
Book a discovery session and we will map out the cybersecurity work for your submission. Prefer to send details first? Get a fixed-fee scope.




