Blue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 24

    From Concept to Compliance: A Guide to Med Device Approval

    With MedTech leader - Med device manufacturers, are you setting up your quality system early enough in product development? Also, are you misunderstanding the FDA’s "guidance" documents - and risking rejection?

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Trevor Slattery, COO at Blue Goat Cyber

    Reviewed by Trevor Slattery

    COO · Blue Goat Cyber

    Last reviewed: May 1, 2026

    Listen now

    Med device manufacturers, are you setting up your quality system early enough in product development? Also, are you misunderstanding the FDA’s "guidance" documents - and risking rejection?

    Today’s guests are Mark Swanson and Steve Gompertz of QRx Partners, and they’re passionate about helping MedTech companies dodge the regulatory and quality pitfalls that derail so many startups. This episode explores how to classify your device properly, why cybersecurity documentation is required even for isolated software, and the evolving role of AI in medical technology.

    Key points:

    (02:11) Startup Failure and What QRx Solves

    • Why many early-stage MedTech startups fail.

    • Startup optimism is contrasted with the harsh funding and regulatory realities.

    (12:16) Classification Chaos and Regulatory Missteps

    • The confusion around FDA’s product code database.

    (17:55) AI and Quality Systems

    • What qualifies as actual AI vs. marketing fluff.

    • How regulators handle AI in submissions.

    (31:22) National Vs State Regulations

    • The critical need for manufacturers to understand state regulations.

    • Why quality and regulatory planning must precede design.

    Thanks to Mark Swanson and Steve Gompertz for being on the show.

    Learn more about QRx Partners: https://www.qrxpartners.com

    Bring this work to your device

    Need help with fda premarket cybersecurity?

    Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.

    FDA Premarket Cybersecurity Services

    More on FDA Premarket Cybersecurity

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.