Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Free Guides

    Cybersecurity guides for MedTech teams.

    Practical playbooks, checklists and decoders we use on every engagement.

    Format

    66 guides

    Cover image for SaMD Cybersecurity FDA Requirements: A Compliance Guide
    FDAReference

    SaMD Cybersecurity FDA Requirements: A Compliance Guide

    Master SaMD cybersecurity FDA requirements. Learn premarket submission needs, SBOM standards, and postmarket monitoring for SaMD under Section 524B.

    Read the guide
    Standards article cover: SBOM Vulnerability Management for Medical Devices
    StandardsReference

    SBOM Vulnerability Management for Medical Devices

    Master SBOM vulnerability management for medical devices. Learn to track, triage, and mitigate software risks to meet FDA premarket and postmarket requirements.

    Read the guide
    FDA article cover: Section 524B Post-Market Retrofit Guide
    FDAReference

    Section 524B Post-Market Retrofit Guide

    A retrofit playbook for bringing already-cleared Class II devices into compliance with FDA Section 524B postmarket cybersecurity expectations — typical 6–10 week timeline, eSTAR cyber pack scope, and supporting evidence.

    Read the guide
    Standards article cover: Security Questionnaire Response Pack
    StandardsReference

    Security Questionnaire Response Pack

    Pre-Completed Vendor Security Questionnaire Pack Hospital and OEM security questionnaires answered once, kept current, ready to send.

    Read the guide
    Standards article cover: SOW Line-Item Map for MedTech Cybersecurity
    StandardsReference

    SOW Line-Item Map for MedTech Cybersecurity

    SOW Line-Item Justification Map Map every line item on a typical cybersecurity SOW to the FDA artifact it produces.

    Read the guide
    Cover image for STRIDE Threat Modeling for Medical Devices: A Guide
    Threat ModelingReference

    STRIDE Threat Modeling for Medical Devices: A Guide

    Master STRIDE threat modeling for medical devices. Learn to identify risks, meet FDA premarket requirements, and secure your MedTech ecosystem. Read our guide.

    Read the guide
    Standards article cover: Technical Scoping Call Agenda
    StandardsReference

    Technical Scoping Call Agenda

    Technical Scoping Session Agenda + Input Checklist Ninety minutes to scope a cybersecurity engagement precisely so the SOW reflects reality.

    Read the guide
    Standards article cover: The MedTech Cybersecurity Funding Ask Guide
    StandardsReference

    The MedTech Cybersecurity Funding Ask Guide

    60–80% 6–10 wk 90–180 d 0 Founders underbudget cyber by Class II eSTAR cyber pack Avg. delay from a single AI letter Submissions rejected INDUSTRY AVERAGE TYPICAL TIMELINE FDA DATA BLUE GOAT TRACK RECORD

    Read the guide
    Cover image for The MedTech Cybersecurity Standards Decoder
    StandardsReference

    The MedTech Cybersecurity Standards Decoder

    FDA Section 524B, IEC 81001-5-1, AAMI TIR57, ISO 14971 and more - what they require, how they connect, and what the FDA expects to see.

    Read the guide
    Put the guides into action

    Bring this rigor to your next submission.

    Book a 30-minute strategy session and we'll map the guides to your actual device, timeline and gaps.