How we work

    How a MedTech team works with us.

    Nine steps from the first call to an FDA-ready cybersecurity package, and support after you submit. Here's what happens at each step, what we need from you and what we do.

    The short answer

    You book a free strategy call, get a fixed-fee proposal and meet your project manager at kickoff. You send your IFU, architecture, threat model and hazard analysis. We build the deliverables and test the device, you fix what we find and we retest. You get an FDA-ready package, and if the FDA raises a cybersecurity deficiency on our work, we help you respond at no extra cost.

    1. Before you sign

      1

      Strategy call

      A free 30-minute call about your device, your submission type and your timeline. We tell you plainly what the FDA will expect and where the gaps are likely to be.

      You: Describe the device, how it connects and your target submission date.
      Us: Map the likely deliverables and suggest the right scope.
    2. 2

      Scoping and fixed-fee proposal

      After a short scoping call, you get a written proposal with a fixed fee, what's included and a schedule. No hourly billing and no surprise change orders for work in scope.

      You: Share basic details: interfaces, software stack, cloud parts and test builds.
      Us: Write the scope, fee and timeline.
    3. Getting started

      3

      Kickoff

      Once the contract is signed, you get a named project manager, a shared Slack channel and secure file shares. The kickoff call sets dates, contacts and how we'll report progress.

      You: Name your technical lead and regulatory contact.
      Us: Assign the project manager and engineers, and set the schedule.
    4. 4

      Intake documents

      We ask for the documents that let us trace every finding and deliverable back to how the device is used and what could harm a patient.

      • Instructions for Use (IFU)

        How the device is used and by whom

      • System architecture

        What connects to what

      • Threat model

        What we test against. We can build it if you don't have one.

      • Hazard analysis

        Links each finding to patient harm

      You: Upload what you have. Missing a threat model is fine; we can build it with you.
      Us: Review the documents and flag gaps early.
    5. The work

      5

      Build and test

      Depending on scope, we build the premarket deliverables (threat model, risk assessment, SBOM, architecture views, labeling, management plan) and run a mostly manual, white-box penetration test.

      You: Answer engineering questions and provide test units or builds.
      Us: Do the work and share progress in Slack.
      See how pen test findings trace to patient harm →
    6. 6

      Findings, fixes and retest

      You get an early tear sheet of findings so your engineers can start fixing. We retest your fixes until the findings are closed, and each one is rated for patient-harm risk, not CVSS alone.

      You: Fix what we find and tell us when builds are ready.
      Us: Retest and update the risk ratings.
    7. Submission

      7

      FDA-ready package

      Reports and deliverables are formatted for the FDA's February 2026 guidance and the eSTAR template, with a signed Letter of Attestation for the pen test.

      You: Drop the package into your submission.
      Us: Walk your regulatory team through each document.
      See all 18 FDA cybersecurity deliverables →
    8. 8

      Deficiency response

      If the FDA sends a cybersecurity deficiency on work we delivered, we help you respond at no extra cost. Clearance is always the FDA's decision.

      You: Forward the FDA's letter as soon as it arrives.
      Us: Deliver a gap analysis within 48 hours and draft the response.
      How deficiency response works →
    9. After clearance

      9

      Postmarket (optional)

      Once the device is on the market, we can monitor new vulnerabilities in your SBOM, handle disclosures and keep your management plan current.

      You: Decide whether you want ongoing support.
      Us: Monitor daily and raise urgent items within two business days.
      Postmarket cybersecurity services →

    Common questions

    How do I start working with Blue Goat Cyber?
    Book a free 30-minute strategy call. After a short scoping call you get a fixed-fee proposal with scope and schedule. Once signed, a named project manager runs kickoff and sets up a shared Slack channel.
    What documents do you need before a medical device pen test?
    The Instructions for Use, system architecture, threat model and hazard analysis. They let us trace each finding to a threat and a hazard and rate its risk in terms of patient harm. If you don't have a threat model yet, we can build it with you first.
    Is the fee fixed?
    Yes. After scoping you get a fixed fee for the agreed scope, with no hourly billing.
    What happens if the FDA sends a cybersecurity deficiency?
    For work we delivered, we help you respond at no extra cost, starting with a gap analysis within 48 hours. Clearance is always the FDA's decision.
    Do you do verification and validation (V&V) testing?
    No. We do penetration and security testing and FDA cybersecurity documentation, not V&V or general software testing.
    Step 1

    Start with a free 30-minute strategy call.

    Tell us about your device and timeline. You'll leave knowing what the FDA will expect.