Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Free Guides

    Cybersecurity guides for MedTech teams.

    Practical playbooks, checklists and decoders we use on every engagement.

    Format

    66 guides

    Cover image for Patient-Safety-First Threat Modeling Guide
    Threat ModelingReference

    Patient-Safety-First Threat Modeling Guide

    Patient-Safety Threat Modeling Worksheet A right-sized STRIDE pass that maps cybersecurity threats to ISO 14971 hazards.

    Read the guide
    Cover image for PCCP Template & Worked Example for AI/ML Medical Devices
    AI/MLPlaybook

    PCCP Template & Worked Example for AI/ML Medical Devices

    How to write a Predetermined Change Control Plan FDA will accept - structure, the three required components, performance bounds, and a worked example.

    Read the guide
    Pen Testing article cover: Penetration Test Refresh Guide
    Pen TestingReference

    Penetration Test Refresh Guide

    Pen Test Refresh vs. Full Re-Test Decision Guide When a delta-only refresh is sufficient, and when FDA expects a full re-test.

    Read the guide
    Cover image for Penetration Testing Scope for FDA Submissions: A 510(k) / De Novo / PMA Guide
    Penetration TestingReference

    Penetration Testing Scope for FDA Submissions: A 510(k) / De Novo / PMA Guide

    How to scope penetration testing for an FDA submission so the report holds up under reviewer scrutiny. Required attack surfaces, evidence depth, and how scope differs by pathway.

    Read the guide
    Cover image for Postmarket Cybersecurity Readiness Plan
    PostmarketPlaybook

    Postmarket Cybersecurity Readiness Plan

    What you need in place after clearance to satisfy FDA postmarket expectations and stay ahead of vulnerabilities.

    Read the guide
    Cover image for Postmarket SBOM Maintenance for Medical Devices
    PostmarketReference

    Postmarket SBOM Maintenance for Medical Devices

    How to maintain SBOMs across a fleet of cleared devices - regeneration cadence, vulnerability triage, VEX, and the postmarket cybersecurity plan that ties it together.

    Read the guide
    Cover image for Premarket FDA Cybersecurity Submission Checklist (2026)
    ChecklistChecklist

    Premarket FDA Cybersecurity Submission Checklist (2026)

    A printable, item-by-item checklist for the cybersecurity content of an FDA premarket submission - aligned to the February 2026 final guidance.

    Read the guide
    FDA article cover: Re-Engagement Sequence: Restarting a Stalled Cyber Program
    FDAReference

    Re-Engagement Sequence: Restarting a Stalled Cyber Program

    Re-Engagement Sequence (After Going Dark) A plain, no-pressure sequence to re-open a cybersecurity conversation after a quiet period.

    Read the guide
    Cover image for Right-Sized Threat Modeling for MedTech
    Threat ModelingReference

    Right-Sized Threat Modeling for MedTech

    250+ 0 6–10 wk FDA submissions supported Cybersecurity rejections Class II eSTAR cyber pack SINCE 2014 TRACK RECORD TYPICAL TIMELINE

    Read the guide
    Put the guides into action

    Bring this rigor to your next submission.

    Book a 30-minute strategy session and we'll map the guides to your actual device, timeline and gaps.