Facts, logos and bios for journalists.
Everything below is approved for publication. For interviews or expert comment on FDA medical device cybersecurity, email info@bluegoatcyber.com.
Company facts
- Company
- Blue Goat Cyber
- Founded
- 2014
- Headquarters
- Scottsdale, Arizona, USA
- Founder and CEO
- Christian Espinosa, MBA
- Focus
- Medical device cybersecurity for FDA premarket submissions and postmarket programs
- Track record
- 275+ medical devices supported
- Mission
- Help secure 1,000 medical devices by 2028
- Membership
- Member, Medical Technology Enterprise Consortium (MTEC)
Boilerplate
Blue Goat Cyber is a medical device cybersecurity firm based in Scottsdale, Arizona. Founded in 2014, it helps medical device makers meet FDA cybersecurity requirements under Section 524B and the FDA's February 2026 premarket cybersecurity guidance, with threat modeling, SBOMs, penetration testing, and submission documentation. The firm has supported 275+ medical devices and aims to help secure 1,000 devices by 2028.
Services
- Full-Service FDA Premarket Cybersecurity
Full-service: we own 100% of SPDF, SBOMs, threat modeling, pen testing, and eSTAR documentation.
- Medical Device Penetration Testing
FDA-compliant device, firmware, app, and cloud testing.
- Medical Device Threat Modeling
FDA-aligned threat models that identify risks early and speed approvals.
- FDA-Compliant SBOM Services
Create, validate, and maintain SBOMs for premarket and postmarket.
- FDA Deficiency Response
Got an FDA hold or AI letter? We close cybersecurity deficiencies fast.
- FDA Postmarket Cybersecurity
Continuous compliance, monitoring, and vulnerability response.
- SaMD Cybersecurity
End-to-end FDA premarket cybersecurity package for Software as a Medical Device - cloud, mobile, and web SaMD.
- AI/ML Medical Device Security
Defend AI/ML SaMD against adversarial attacks - and meet FDA's PCCP, GMLP, and 2025 AI-enabled device guidance.
Full list on the services page.
Founder
Christian Espinosa, MBA, is the founder and CEO of Blue Goat Cyber. He speaks on FDA premarket and postmarket cybersecurity, SBOM obligations and secure product design at MedTech events in the US, Europe and Asia, and hosts the Med Device Cyber Podcast. More on the About page and media page.
Media assets
Please don't alter the logos. Credit photos to Blue Goat Cyber.
Media inquiries
Email info@bluegoatcyber.com or use the contact page. Past coverage is on the press page.
Get FDA cleared without the cybersecurity headaches.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.


