PMA and De Novo reviewers expect a multi-patient harm view and an operational postmarket program at the time of filing - not promises. Submissions that ship without them are drawing Major Deficiency Letters.
Higher-risk submissions need deeper cybersecurity evidence - multi-patient harm views, complete pen-test scope, and a fielded postmarket cybersecurity management plan. We own all of it for PMA and De Novo, aligned to Section 524B and the FDA February 2026 final guidance. 275+ devices supported.
Free 30-min call · Senior US expert · Mutual NDA before the call
275+
Devices supported
None
Cybersecurity-related rejections to date
24 hrs
Quote turnaround
Last updated
“Blue Goat's niche expertise in FDA-facing cybersecurity made all the difference. Their reports were built with the FDA's expectations in mind; it gave us confidence that we were submitting exactly…”
Scott Odland, Solutions Architect, Rhaeos
Trusted by medical device teams worldwide
Lifecycle scope
What's different about PMA & De Novo cybersecurity
Premarket to postmarket. One senior team owns every cybersecurity artifact the FDA reviewer will open.
01
Multi-patient harm view
Threat model includes a multi-patient harm analysis required for higher-risk devices - not just the single-patient view sufficient for many 510(k)s.
02
Full pen-test scope
Device, cloud, mobile, wireless, BLE/RF, and any clinical workflow integrations. Independent testers, documented scope, and reviewer-ready findings.
03
SPDF inside your QMS
Secure Product Development Framework integrated with QMSR (21 CFR 820), ISO 13485 design controls, and your ECO/change management process.
04
Postmarket plan that holds up
Vulnerability monitoring, CVD procedures, patch authentication, rollback, and Section 524B(b)(1) postmarket reporting - operational before market.
05
Major Deficiency response
If a Major Deficiency Letter or hold lands, we author the point-by-point response, cover letter, and traceability matrix inside your 180-day clock.
06
Pre-Sub (Q-Sub) support
We help you frame the cybersecurity questions for a Pre-Submission meeting so reviewer expectations are locked in before you file.
Common FDA findings
Where PMA & De Novo cyber submissions get stopped
Higher-risk pathways get deeper FDA review. These are the cybersecurity gaps that trigger Major Deficiency Letters on PMA and De Novo submissions.
Single-patient threat model only
Threat model considers harm to one patient but not the multi-patient cascade - the failure mode FDA expects to see addressed on PMA-class devices.
Pen test scope misses cloud or RF
Device-only pen test with no cloud API or wireless coverage. Reviewers flag the missing attack surface and the submission stalls.
SPDF documented but not integrated
SPDF exists as a standalone document with no traceability into design controls, ECOs, or risk management. Reviewers ask for the integration evidence.
Postmarket plan is aspirational
Postmarket cybersecurity management plan describes what you intend to do, not what is operational. Reviewers want evidence the program exists today.
No interoperability or compensating controls
Device connects to clinical networks or shared infrastructure with no documented compensating controls for the connected environment.
Risk file not updated for cybersecurity
ISO 14971 risk file does not include cybersecurity-driven hazards or controls. Mandatory under AAMI TIR57 alignment and called out by reviewers.
Blue Goat Cyber vs. the alternatives
What you actually get versus a PMA consultant without cyber depth, or building Class III cyber evidence in-house.
Capability
Blue Goat Cyber
PMA consultant without cyber depth
In-house
Class III / De Novo cyber experience
Submissions across Class II + III + De Novo
Cyber treated as add-on to regulatory work
Built clause-by-clause from statute
SPDF + threat model + SBOM + VEX
Integrated, reviewer-format
Piecemeal across subcontractors
Multiple owners, integration gaps
Postmarket commitments documented
CVD + monitoring + patch SLAs
Premarket only
Deferred until audit
Submission track record
275+
Variable, cyber-specific track unclear
First-submission risk
Pricing model
Fixed fee, revisions included
Hourly + change orders
Hidden internal cost
What happens after you book the call
1Day 0
Mutual NDA + 30-min PMA / De Novo scoping
Mutual NDA, then a 30-minute call to map your device classification, intended use, multi-patient exposure, and the cybersecurity evidence the reviewer will expect.
2Day 1
Written strategy + fixed-fee quote
Point-by-point cybersecurity strategy mapped to Section 524B and the FDA February 2026 final guidance, plus a fixed-fee quote covering threat model, pen test, SPDF, and postmarket plan.
3Weeks 2-12
Reviewer-ready submission package
Multi-patient threat model, full-scope pen test, SPDF integrated into your QMS, and postmarket cybersecurity management plan - delivered in eSTAR-attachable format.
"Blue Goat's niche expertise in FDA-facing cybersecurity made all the difference. Their reports were built with the FDA's expectations in mind; it gave us confidence that we were submitting exactly what reviewers want to see."
- Scott Odland, Solutions Architect, Rhaeos
Cybersecurity deficiency remediation included
If the FDA raises a cybersecurity deficiency, we fix it at no additional cost. 275+ devices supported.
Mutual NDA before the call
We sign a mutual NDA before the initial call so you can share device details, architecture, and FDA correspondence freely.
Fixed-fee quote within 24 hours of the call
No sales pressure. After the call, you get a concrete written strategy mapped to Section 524B and the FDA February 2026 final guidance.
Senior US engineers, fixed fee
Senior-led delivery on every FDA-facing artifact. No offshoring, no hourly billing. Revisions included. Every artifact is eSTAR-ready.
Common questions
Who you're talking to
Christian Espinosa, Founder & CEO
MBA, CISSP · U.S. Air Force Academy graduate · 30+ years in cybersecurity
Christian leads the senior medical device cybersecurity team behind 275+ devices supported. Author of three books including Medical Device Cybersecurity: An In-Depth Guide.
30 minutes with a senior medical device cybersecurity engineer. Mutual NDA signed before the call. No pitch - we'll tell you straight if you don't need us.