How a MedTech team works with us.
Nine steps from the first call to an FDA-ready cybersecurity package, and support after you submit. Here's what happens at each step, what we need from you and what we do.
The short answer
You book a free strategy call, get a fixed-fee proposal and meet your project manager at kickoff. You send your IFU, architecture, threat model and hazard analysis. We build the deliverables and test the device, you fix what we find and we retest. You get an FDA-ready package, and if the FDA raises a cybersecurity deficiency on our work, we help you respond at no extra cost.
Before you sign
1Strategy call
A free 30-minute call about your device, your submission type and your timeline. We tell you plainly what the FDA will expect and where the gaps are likely to be.
You: Describe the device, how it connects and your target submission date.Us: Map the likely deliverables and suggest the right scope.- 2
Scoping and fixed-fee proposal
After a short scoping call, you get a written proposal with a fixed fee, what's included and a schedule. No hourly billing and no surprise change orders for work in scope.
You: Share basic details: interfaces, software stack, cloud parts and test builds.Us: Write the scope, fee and timeline. Getting started
3Kickoff
Once the contract is signed, you get a named project manager, a shared Slack channel and secure file shares. The kickoff call sets dates, contacts and how we'll report progress.
You: Name your technical lead and regulatory contact.Us: Assign the project manager and engineers, and set the schedule.- 4
Intake documents
We ask for the documents that let us trace every finding and deliverable back to how the device is used and what could harm a patient.
Instructions for Use (IFU)
How the device is used and by whom
System architecture
What connects to what
Threat model
What we test against. We can build it if you don't have one.
Hazard analysis
Links each finding to patient harm
You: Upload what you have. Missing a threat model is fine; we can build it with you.Us: Review the documents and flag gaps early. The work
5Build and test
Depending on scope, we build the premarket deliverables (threat model, risk assessment, SBOM, architecture views, labeling, management plan) and run a mostly manual, white-box penetration test.
See how pen test findings trace to patient harm →You: Answer engineering questions and provide test units or builds.Us: Do the work and share progress in Slack.- 6
Findings, fixes and retest
You get an early tear sheet of findings so your engineers can start fixing. We retest your fixes until the findings are closed, and each one is rated for patient-harm risk, not CVSS alone.
You: Fix what we find and tell us when builds are ready.Us: Retest and update the risk ratings. Submission
7FDA-ready package
Reports and deliverables are formatted for the FDA's February 2026 guidance and the eSTAR template, with a signed Letter of Attestation for the pen test.
See all 18 FDA cybersecurity deliverables →You: Drop the package into your submission.Us: Walk your regulatory team through each document.- 8
Deficiency response
If the FDA sends a cybersecurity deficiency on work we delivered, we help you respond at no extra cost. Clearance is always the FDA's decision.
How deficiency response works →You: Forward the FDA's letter as soon as it arrives.Us: Deliver a gap analysis within 48 hours and draft the response. After clearance
9Postmarket (optional)
Once the device is on the market, we can monitor new vulnerabilities in your SBOM, handle disclosures and keep your management plan current.
Postmarket cybersecurity services →You: Decide whether you want ongoing support.Us: Monitor daily and raise urgent items within two business days.
Common questions
- How do I start working with Blue Goat Cyber?
- Book a free 30-minute strategy call. After a short scoping call you get a fixed-fee proposal with scope and schedule. Once signed, a named project manager runs kickoff and sets up a shared Slack channel.
- What documents do you need before a medical device pen test?
- The Instructions for Use, system architecture, threat model and hazard analysis. They let us trace each finding to a threat and a hazard and rate its risk in terms of patient harm. If you don't have a threat model yet, we can build it with you first.
- Is the fee fixed?
- Yes. After scoping you get a fixed fee for the agreed scope, with no hourly billing.
- What happens if the FDA sends a cybersecurity deficiency?
- For work we delivered, we help you respond at no extra cost, starting with a gap analysis within 48 hours. Clearance is always the FDA's decision.
- Do you do verification and validation (V&V) testing?
- No. We do penetration and security testing and FDA cybersecurity documentation, not V&V or general software testing.
Start with a free 30-minute strategy call.
Tell us about your device and timeline. You'll leave knowing what the FDA will expect.
