Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Free Guides

    Cybersecurity guides for MedTech teams.

    Practical playbooks, checklists and decoders we use on every engagement - organized by lifecycle stage.

    Format

    56 guides

    Start here

    Foundational pillars for teams new to FDA medical device cybersecurity.

    17 guides
    Vendor Selection article cover: 10 Reasons Cybersecurity Vendors Fail MedTech
    Vendor SelectionReference

    10 Reasons Cybersecurity Vendors Fail MedTech

    Why generic IT-security vendors keep blowing FDA submissions - and what to demand from a true MedTech specialist.

    Read the guide
    AI/ML article cover: AAMI CR34971 Explained: AI Risk Management for Medical Devices
    AI/MLReference

    AAMI CR34971 Explained: AI Risk Management for Medical Devices

    What CR34971 adds on top of ISO 14971, the AI-specific risk categories it covers, and how to integrate it with your existing risk file.

    Read the guide
    AI/ML article cover: FDA 2025 AI-Enabled Device Software Functions Guidance, Decoded
    AI/MLReference

    FDA 2025 AI-Enabled Device Software Functions Guidance, Decoded

    Plain-English breakdown of FDA's 2025 draft AI guidance: what it adds beyond PCCP and GMLP, transparency labeling expectations, and what reviewers want to see.

    Read the guide
    Cover image for FDA 524B Cybersecurity Requirements: Full Compliance Guide
    FDAReference

    FDA 524B Cybersecurity Requirements: Full Compliance Guide

    Master FDA 524B cybersecurity requirements. Learn how to meet SBOM, vulnerability monitoring, and patch management standards for medical device submissions.

    Read the guide
    Deficiency Response article cover: FDA Cybersecurity Deficiency Letter Response Playbook
    Deficiency ResponsePlaybook

    FDA Cybersecurity Deficiency Letter Response Playbook

    A field-tested playbook for responding to FDA cybersecurity deficiencies inside the 180-day clock - triage, gap analysis, fix sequence, and reviewer-ready format.

    Read the guide
    Cover image for FDA Cybersecurity Guidance 2026: Transition Guide and Summary
    FDAReference

    FDA Cybersecurity Guidance 2026: Transition Guide and Summary

    A plain-language summary of the FDA's Feb 3, 2026 final premarket cybersecurity guidance: what changed, the 8-slot eSTAR v7.0 checklist, and how to transition.

    Read the guide
    Threat Modeling article cover: FDA-Grade Medical Device Threat Model: Template & Worked Example
    Threat ModelingPlaybook

    FDA-Grade Medical Device Threat Model: Template & Worked Example

    Step-by-step template to build a threat model FDA reviewers will accept - architecture views, STRIDE, safety mapping, control traceability, and a worked example.

    Read the guide
    Cover image for Full-Service Cybersecurity for PMA Submissions
    PMAReference

    Full-Service Cybersecurity for PMA Submissions

    Everything a Class III PMA cybersecurity package needs - and how a single integrated team delivers threat modeling, SBOM, pen testing, postmarket plan, and reviewer engagement.

    Read the guide
    AI/ML article cover: GMLP Crosswalk: 10 Principles to Engineering Controls
    AI/MLReference

    GMLP Crosswalk: 10 Principles to Engineering Controls

    Each of the FDA/Health Canada/MHRA Good Machine Learning Practice principles mapped to concrete engineering, QMS, and documentation controls.

    Read the guide
    Cover image for How to Pass FDA 510(k) Cybersecurity on the First Submission
    510(k)Playbook

    How to Pass FDA 510(k) Cybersecurity on the First Submission

    The exact cybersecurity package that gets through 510(k) review without an AI letter. Eight artifacts, common rejection patterns, and a 30-day pre-submission readiness check.

    Read the guide
    Cover image for Medical Device SBOM Requirements for FDA: A Complete Checklist
    SBOMChecklist

    Medical Device SBOM Requirements for FDA: A Complete Checklist

    What FDA requires in your SBOM under Section 524B and the 2026 guidance: format, depth, vulnerability mapping, postmarket maintenance, and the most-cited deficiencies.

    Read the guide
    Cover image for PCCP Template & Worked Example for AI/ML Medical Devices
    AI/MLPlaybook

    PCCP Template & Worked Example for AI/ML Medical Devices

    How to write a Predetermined Change Control Plan FDA will accept - structure, the three required components, performance bounds, and a worked example.

    Read the guide
    Cover image for Penetration Testing Scope for FDA Submissions: A 510(k) / De Novo / PMA Guide
    Penetration TestingReference

    Penetration Testing Scope for FDA Submissions: A 510(k) / De Novo / PMA Guide

    How to scope penetration testing for an FDA submission so the report holds up under reviewer scrutiny. Required attack surfaces, evidence depth, and how scope differs by pathway.

    Read the guide
    Cover image for Postmarket SBOM Maintenance for Medical Devices
    PostmarketReference

    Postmarket SBOM Maintenance for Medical Devices

    How to maintain SBOMs across a fleet of cleared devices - regeneration cadence, vulnerability triage, VEX, and the postmarket cybersecurity plan that ties it together.

    Read the guide
    Cover image for Premarket FDA Cybersecurity Submission Checklist (2026)
    ChecklistChecklist

    Premarket FDA Cybersecurity Submission Checklist (2026)

    A printable, item-by-item checklist for the cybersecurity content of an FDA premarket submission - aligned to the February 2026 final guidance.

    Read the guide
    Cover image for The MedTech Cybersecurity Standards Decoder
    StandardsReference

    The MedTech Cybersecurity Standards Decoder

    FDA Section 524B, IEC 81001-5-1, AAMI TIR57, ISO 14971 and more - what they require, how they connect, and what the FDA expects to see.

    Read the guide
    Cover image for The SPDF Playbook
    SPDFPlaybook

    The SPDF Playbook

    A practical playbook for implementing the Secure Product Development Framework across your QMS and SDLC.

    Read the guide

    Premarket & submission

    510(k), De Novo, PMA, and eSTAR-ready deliverables for premarket filings.

    11 guides
    FDA article cover: Combination Product Cybersecurity: When CDER Meets CDRH §524B
    FDAReference

    Combination Product Cybersecurity: When CDER Meets CDRH §524B

    How Section 524B and the Feb 2026 guidance apply to drug-device combination products, including the CDER/CDRH lead-center split.

    Read the guide
    Cover image for Cybersecurity Management Plan for FDA Submissions: A 2026 Guide
    FDAPlaybook

    Cybersecurity Management Plan for FDA Submissions: A 2026 Guide

    What goes in the Cybersecurity Management Plan reviewers expect in eSTAR v7.0 Slot 1: scope, governance, QMS integration, postmarket commitments, and the most common deficiency patterns.

    Read the guide
    FDA article cover: De Novo Cybersecurity Submission Guide
    FDAReference

    De Novo Cybersecurity Submission Guide

    Learn the specific cybersecurity requirements for a successful De Novo submission. Ensure FDA compliance with threat modeling, SBOM, and pen testing.

    Read the guide
    Cover image for eSTAR v7.0 Cybersecurity Attachments: How the 8 Slots Map to the FDA's 2026 Guidance
    FDAReference

    eSTAR v7.0 Cybersecurity Attachments: How the 8 Slots Map to the FDA's 2026 Guidance

    Side-by-side mapping of the 8 Cybersecurity attachment slots in eSTAR v7.0 to the 15 deliverables in the FDA's February 2026 final guidance, with the most common RTA trigger per slot.

    Read the guide
    Cover image for FDA Cybersecurity RTA Prevention Checklist: Avoid Refuse-to-Accept Holds
    FDAChecklist

    FDA Cybersecurity RTA Prevention Checklist: Avoid Refuse-to-Accept Holds

    A practitioner's checklist of the cybersecurity triggers that cause FDA Refuse-to-Accept (RTA) holds under Section 524B, and how to clear each one before you submit.

    Read the guide
    Cover image for FDA Cybersecurity Technical Screening Checklist (2026)
    FDAChecklist

    FDA Cybersecurity Technical Screening Checklist (2026)

    A reviewer's-eye technical screening checklist for FDA cyber-device submissions: artifacts, formats, traceability, and the failure modes that turn a soft deficiency into a hold.

    Read the guide
    Cover image for FDA Pathway Cybersecurity Differences: 510(k), De Novo, PMA, HDE, IDE, Q-Sub, PDP
    FDAReference

    FDA Pathway Cybersecurity Differences: 510(k), De Novo, PMA, HDE, IDE, Q-Sub, PDP

    How cybersecurity expectations differ across FDA pathways - 510(k), De Novo, PMA, HDE, IDE, Q-Sub, and PDP - under Section 524B and the February 2026 final guidance.

    Read the guide
    AI/ML article cover: FDA PCCP: Predetermined Change Control Plans
    AI/MLReference

    FDA PCCP: Predetermined Change Control Plans

    How to author a Predetermined Change Control Plan the FDA will accept: modifications protocol, methods, impact assessment, and cybersecurity coverage.

    Read the guide
    Cover image for FDA PMA Cybersecurity Requirements: Expert Guide (2024)
    FDAReference

    FDA PMA Cybersecurity Requirements: Expert Guide (2024)

    Master FDA PMA cybersecurity requirements. Learn the technical documentation, risk management, and SPDF requirements needed for a successful Class III submissio

    Read the guide
    Cover image for FDA Premarket Cybersecurity Deliverables & eSTAR v7.0 Map
    FDAReference

    FDA Premarket Cybersecurity Deliverables & eSTAR v7.0 Map

    All 18 FDA premarket cybersecurity deliverables, mapped to the February 2026 guidance sections and the non-IVD eSTAR v7.0 fields. Used on 250+ submissions.

    Read the guide
    Cover image for FDA Premarket Cybersecurity Submission Checklist Guide
    FDAChecklist

    FDA Premarket Cybersecurity Submission Checklist Guide

    Ensure your 510(k) or PMA is compliant. Use our checklist for FDA premarket cybersecurity submissions, covering SBOM, threat models, and pen testing.

    Read the guide

    Threat modeling & risk

    STRIDE, ISO 14971, and hazard analysis artifacts reviewers accept.

    5 guides
    Threat Modeling article cover: 12 Critical Threat-Modeling Gaps in Submissions
    Threat ModelingReference

    12 Critical Threat-Modeling Gaps in Submissions

    Where threat models fall short of FDA expectations under the 2026 cybersecurity guidance - and how to fix the gaps.

    Read the guide
    Standards article cover: AAMI TIR57 vs TIR97: Medical Device Risk Management Guide
    StandardsReference

    AAMI TIR57 vs TIR97: Medical Device Risk Management Guide

    Compare AAMI TIR57 vs TIR97. Learn how these cybersecurity risk management standards differ and how to apply them for FDA premarket and postmarket compliance.

    Read the guide
    Standards article cover: IEC 81001-5-1 Security Risk Assessment Guide
    StandardsReference

    IEC 81001-5-1 Security Risk Assessment Guide

    Learn how to implement IEC 81001-5-1 security risk assessments for FDA compliance. Expert guidance on medical device lifecycle security mapping.

    Read the guide
    Standards article cover: ISO 14971 vs AAMI TIR57: Hazard Analysis Meets Cybersecurity Risk
    StandardsReference

    ISO 14971 vs AAMI TIR57: Hazard Analysis Meets Cybersecurity Risk

    How safety hazard analysis and security risk analysis run in parallel and converge at the patient-harm column, with a side-by-side mapping table.

    Read the guide
    Cover image for STRIDE Threat Modeling for Medical Devices
    Threat ModelingReference

    STRIDE Threat Modeling for Medical Devices

    Master STRIDE threat modeling for medical devices. Learn to identify risks, meet FDA premarket requirements, and secure your MedTech ecosystem. Read our guide.

    Read the guide

    SBOM & supply chain

    SBOM generation, VEX, and third-party vulnerability management.

    5 guides
    Standards article cover: CPE vs PURL for Medical Device SBOMs: Which Identifier and When
    StandardsReference

    CPE vs PURL for Medical Device SBOMs: Which Identifier and When

    How CPE and PURL identifiers differ, why medical device SBOMs need both, and how to map PURL to CPE for FDA postmarket CVE monitoring under Section 524B.

    Read the guide
    Standards article cover: CycloneDX vs SPDX: Medical Device SBOM Compliance Guide
    StandardsReference

    CycloneDX vs SPDX: Medical Device SBOM Compliance Guide

    Does the FDA prefer CycloneDX or SPDX? Compare SBOM formats for medical device cybersecurity compliance and premarket 510(k) submissions.

    Read the guide
    Cover image for SBOM for Medical Devices: The 2026 FDA Pillar Guide
    FDAReference

    SBOM for Medical Devices: The 2026 FDA Pillar Guide

    What an SBOM is, why the FDA requires one under Section 524B, SPDX vs CycloneDX, how to generate and submit one, and how it powers postmarket vulnerability management.

    Read the guide
    Standards article cover: SBOM Vulnerability Management for Medical Devices Guide
    StandardsReference

    SBOM Vulnerability Management for Medical Devices Guide

    Master SBOM vulnerability management for medical devices. Learn to track, triage, and mitigate software risks to meet FDA premarket and postmarket requirements.

    Read the guide
    Cover image for VEX Document Guide for FDA Medical Device Compliance
    FDAReference

    VEX Document Guide for FDA Medical Device Compliance

    Learn how VEX documents complement SBOMs for FDA medical device compliance. Expert guidance on Vulnerability Exploitability eXchange for MedTech manufacturers.

    Read the guide

    Testing & evidence

    Penetration testing, security controls, and testing taxonomy proof.

    4 guides
    Pen Testing article cover: 12 Critical Findings from Medical Device Pen Tests
    Pen TestingReference

    12 Critical Findings from Medical Device Pen Tests

    Real, recurring vulnerabilities we uncover during penetration testing on Class II/III connected medical devices.

    Read the guide
    Cover image for FDA Cybersecurity Testing Requirements: The Complete 2026 Taxonomy
    FDAReference

    FDA Cybersecurity Testing Requirements: The Complete 2026 Taxonomy

    Ten families of cybersecurity testing the Feb 2026 guidance expects, mapped to eSTAR v7.0 slots and recognized standards.

    Read the guide
    Cover image for FDA Security Control Categories: What Reviewers Expect Per Category
    FDAReference

    FDA Security Control Categories: What Reviewers Expect Per Category

    The 8 security control categories every cyber device must cover, and the evidence FDA expects for each one.

    Read the guide
    Pen Testing article cover: Penetration Testing for Medical Devices: A 2026 Explainer
    Pen TestingReference

    Penetration Testing for Medical Devices: A 2026 Explainer

    What medical device penetration testing is, why the FDA requires it under Section 524B, the four FDA-expected test categories, scope by device archetype, and what a credible deliverable contains.

    Read the guide

    Postmarket & deficiency response

    Monitoring, CVD, legacy devices, and FDA deficiency letter workflows.

    8 guides
    Cover image for 12 Reasons the FDA Rejects Cybersecurity Submissions
    FDAReference

    12 Reasons the FDA Rejects Cybersecurity Submissions

    The most common deficiencies we see in 510(k), De Novo, and PMA cybersecurity packages - and how to avoid each one.

    Read the guide
    Cover image for FDA Cybersecurity Deficiency Letter Examples & Solutions
    FDAReference

    FDA Cybersecurity Deficiency Letter Examples & Solutions

    Analyze real-world FDA cybersecurity deficiency letter examples. Learn how to address RTA and AI deficiency requests for 510(k) and PMA submissions.

    Read the guide
    Cover image for FDA Cybersecurity Deficiency Response Checklist
    FDAChecklist

    FDA Cybersecurity Deficiency Response Checklist

    Step-by-step checklist for responding to FDA cybersecurity deficiency letters without losing your submission timeline.

    Read the guide
    Cover image for Legacy Medical Device Cybersecurity: The 2026 FDA Guide
    FDAReference

    Legacy Medical Device Cybersecurity: The 2026 FDA Guide

    SBOM reconstruction, vulnerability triage without source code, and end-of-support communication for devices cleared before Section 524B.

    Read the guide
    Cover image for Medical Device CVD Guide: FDA Compliance & Best Practices
    FDAReference

    Medical Device CVD Guide: FDA Compliance & Best Practices

    Master Coordinated Vulnerability Disclosure (CVD) for medical devices. Learn FDA requirements, ISO/IEC 29147 standards, and how to handle security researchers.

    Read the guide
    FDA article cover: Postmarket Cybersecurity Monitoring Guide for MedTech
    FDAReference

    Postmarket Cybersecurity Monitoring Guide for MedTech

    Ensure FDA compliance with our guide to postmarket cybersecurity monitoring for medical devices. Master vulnerability intake, risk assessments, and disclosure.

    Read the guide
    Cover image for Postmarket Cybersecurity Readiness Plan
    PostmarketPlaybook

    Postmarket Cybersecurity Readiness Plan

    What you need in place after clearance to satisfy FDA postmarket expectations and stay ahead of vulnerabilities.

    Read the guide
    Postmarket article cover: VDP and CVD Workflows for Medical Devices
    PostmarketPlaybook

    VDP and CVD Workflows for Medical Devices

    Stand up a Vulnerability Disclosure Program and Coordinated Vulnerability Disclosure workflow that satisfies FDA, aligns to ISO/IEC 29147 / 30111, and actually works for a small MedTech security team.

    Read the guide

    Standards & cross-regulatory

    EU MDR, AI Act, IVD, SaMD, HIPAA, and cross-framework crosswalks.

    6 guides
    Cover image for Cybersecurity for IVD Devices: The FDA & Section 524B Guide
    FDAReference

    Cybersecurity for IVD Devices: The FDA & Section 524B Guide

    How Section 524B and AAMI SW96 apply to clinical analyzers, point-of-care, and connected IVD platforms, plus the pitfalls IVD teams hit.

    Read the guide
    Cover image for EU AI Act vs FDA AI/ML Cybersecurity for Devices
    AI/MLReference

    EU AI Act vs FDA AI/ML Cybersecurity for Devices

    How EU AI Act Article 15 obligations compare to the FDA's PCCP framework and Section 524B for AI/ML SaMD.

    Read the guide
    Cover image for EU MDR vs FDA Medical Device Cybersecurity: A Side-by-Side Crosswalk
    FDAReference

    EU MDR vs FDA Medical Device Cybersecurity: A Side-by-Side Crosswalk

    How EU MDR/IVDR cybersecurity requirements compare to FDA Section 524B and the February 2026 guidance - Annex I §17.2, MDCG 2019-16, SBOM, vulnerability handling, and postmarket obligations.

    Read the guide
    Standards article cover: GTM Compliance Crosswalk: FDA + SOC 2 + HIPAA + HITRUST + GDPR
    StandardsReference

    GTM Compliance Crosswalk: FDA + SOC 2 + HIPAA + HITRUST + GDPR

    Overview and crosswalk of the five frameworks every MedTech innovator must satisfy after FDA clearance - shared controls, sequencing, and FAQs.

    Read the guide
    Standards article cover: HHS HPH CPGs for Medical Device Manufacturers
    StandardsReference

    HHS HPH CPGs for Medical Device Manufacturers

    How the HHS HPH Cybersecurity Performance Goals map to manufacturer obligations, MDS2 disclosures, and Section 524B evidence.

    Read the guide
    Cover image for SaMD Cybersecurity FDA Requirements: 2024 Compliance Guide
    FDAReference

    SaMD Cybersecurity FDA Requirements: 2024 Compliance Guide

    Master SaMD cybersecurity FDA requirements. Learn premarket submission needs, SBOM standards, and postmarket monitoring for SaMD under Section 524B.

    Read the guide
    Put the guides into action

    Bring this rigor to your next submission.

    Book a 30-minute strategy session and we'll map the guides to your actual device, timeline and gaps.