Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Free Guides

    Cybersecurity guides for MedTech teams.

    Practical playbooks, checklists and decoders we use on every engagement.

    Format

    43 guides

    Cover image for FDA Submission Track Record Reference Guide
    FDAReference

    FDA Submission Track Record Reference Guide

    Submission Track Record by Device Class & Pathway What we have supported, by class and pathway, with the kind of detail you can hand to procurement.

    Read the guide
    Cover image for Firmware Access Requirements for Pen Testing
    Pen TestingReference

    Firmware Access Requirements for Pen Testing

    What We Need (and Don't) for Firmware Pen Testing A clear list of what we need from your team to run a useful firmware pen test - and what we don't.

    Read the guide
    Standards article cover: Fixed-Fee vs. Time-and-Materials Decision Guide
    StandardsReference

    Fixed-Fee vs. Time-and-Materials Decision Guide

    Fixed-Fee vs. T&M Decision Guide When fixed-fee is cheaper, when time-and-materials is, and what to ask for in either.

    Read the guide
    Standards article cover: GTM Compliance Crosswalk: FDA + SOC 2 + HIPAA + HITRUST + GDPR
    StandardsReference

    GTM Compliance Crosswalk: FDA + SOC 2 + HIPAA + HITRUST + GDPR

    Overview and crosswalk of the five frameworks every MedTech innovator must satisfy after FDA clearance - shared controls, sequencing, and FAQs.

    Read the guide
    Standards article cover: Internal Champion Toolkit
    StandardsReference

    Internal Champion Toolkit

    250+ 0 6–10 wk FDA submissions supported Cybersecurity rejections Class II eSTAR cyber pack SINCE 2014 TRACK RECORD TYPICAL TIMELINE

    Read the guide
    Standards article cover: IP & Data Ownership Guide for MedTech Cyber Engagements
    StandardsReference

    IP & Data Ownership Guide for MedTech Cyber Engagements

    IP & Data Ownership Standard Terms Who owns what when our work is done. Plain language, no surprises in the redline.

    Read the guide
    Standards article cover: Late-Stage Competitor Comparison & Best-and-Final Framework
    StandardsReference

    Late-Stage Competitor Comparison & Best-and-Final Framework

    Late-Stage Competitor Comparison + Best-and-Final Framework What to compare, and how to ask for a best-and-final, when you are between two cybersecurity vendors.

    Read the guide
    Standards article cover: LOI Bridge: Locking In Scope Before the SOW
    StandardsReference

    LOI Bridge: Locking In Scope Before the SOW

    Letter of Intent: A Bridge Document Before MSA A short, non-binding LOI that lets work start while procurement processes the master agreement.

    Read the guide
    Standards article cover: MedTech Cybersecurity Engagement Kickoff Agenda
    StandardsReference

    MedTech Cybersecurity Engagement Kickoff Agenda

    Cybersecurity Engagement Kickoff Agenda Sixty minutes to align scope, owners, and timeline before any artifact work begins.

    Read the guide
    Put the guides into action

    Bring this rigor to your next submission.

    Book a 30-minute strategy session and we'll map the guides to your actual device, timeline and gaps.