Proof, not adjectives.
Securing medical devices since 2014. A 12+ year track record across every major FDA cybersecurity shift - 250+ devices cleared, the standards we map to, the certifications we hold, redacted deliverables you can review, and the press, podcasts, and clients who've vouched for us.
Last updated: Nov 2026 · Self-reported
250+ FDA submissions, broken down.
Competitors quote round numbers. We quote what's actually in the binder. Every entry below comes from a real FDA submission we supported between 2019 and today.
0 cybersecurity-related RTAs or AI-Rs across these submissions, as of this update. Numbers refresh quarterly.
Securing medical devices since 2014.
A 12+ year track record focused exclusively on medical device cybersecurity. Our methodology, templates, and review playbooks have been refined through every major FDA cybersecurity shift - draft guidance, the PATCH Act, Section 524B, the September 2023 premarket guidance, QMSR modernization, and the Feb 3, 2026 final premarket guidance. When the rules change, our deliverables already match.
Started in medical device cybersecurity
Began securing connected medical devices when 'medtech cybersecurity' was barely a category. Built our first FDA premarket cyber packages.
FDA premarket cybersecurity guidance (draft)
Adapted our methodology to FDA's draft premarket cybersecurity guidance - SBOM thinking, threat modeling, security risk management - well before it became table stakes.
Section 524B becomes law
Re-tooled deliverables for the new statutory authority: refuse-to-accept (RTA) for cyber, SBOMs in submissions, postmarket plans. Zero cyber-related RTAs since.
FDA Sept 2023 premarket guidance (superseded)
Aligned templates and traceability matrices to SPDF expectations and AAMI SW96 / TIR57 inputs. Superseded by the Feb 3, 2026 final guidance.
QMSR (21 CFR Part 820) modernization
Updated quality-system inputs as FDA harmonized with ISO 13485, including cybersecurity risk management touchpoints.
FDA Feb 3, 2026 final premarket guidance
Current binding edition. Refreshed every template, threat model, and SBOM/VEX workflow to the seven-section submission format reviewers now enforce at Technical Screening - so submissions clear on the first cycle.
Twelve years of reps means our SPDF, threat model, SBOM/VEX, and AI-letter-response templates have been pressure-tested through hundreds of submissions - not invented yesterday in response to the latest guidance.
Real engagements with real numbers.
Anonymized to honor NDAs - but every standard, timeline, deliverable, and outcome is exactly what we shipped.
Series-B imaging AI manufacturer (US, ~60 FTEs)
30-day FDA response window - delivered in 21 days
- 21 days - Deficiency cleared in
- De Novo granted - Final submission outcome
- 0 - Additional reviewer rounds
Cardiac remote-monitoring manufacturer (US/EU dual market)
16 weeks pre-submission (Jan - Apr 2025), first-cycle clearance in 84 days
- Granted on first cycle - 510(k) clearance
- 0 - Cybersecurity AIs from FDA
- 100% - High/critical findings closed pre-submission
Implantable neurostimulator manufacturer (Class III, life-sustaining)
11 months across pre-PMA and PMA review (May 2024 - Apr 2025), 2 AI rounds resolved
- Approved - PMA outcome
- 2 of 2 - Cybersecurity AI rounds resolved
- 100% - Field-replaceable cyber controls at approval
Sample deliverables.
Most firms won't show you what they actually ship. Here are real, redacted artifacts from real submissions - the same files we'd hand your team.
Redacted CycloneDX 1.5 SBOM
Real SBOM from a Class II SaMD submission with 312 components mapped against KEV/EPSS. Client name and component fingerprints redacted.
PDF · 14 pages
Threat model excerpt (STRIDE + ISO 14971)
Two pages from a 47-threat STRIDE model showing the traceability matrix from threat → harm → control. Demonstrates AAMI SW96 conformance.
PDF · 2 pages
FDA AI-R cybersecurity response letter
12-page response to a real FDA cybersecurity AI Request, with reviewer questions verbatim and our line-by-line response. Submission identifiers redacted.
PDF · 12 pages
Pen test executive summary
Sample executive summary page from a medical device pen test report - finding rollup, severity heatmap, and remediation roadmap.
PDF · 1 page
Want a sample sent over? Email info@bluegoatcyber.com and we'll share the redacted version under a mutual NDA.
Certifications.
Held across the team. We don't list expired certs or letters that look impressive but aren't relevant to medtech.
Standards we map to.
Every deliverable cross-references the relevant guidance and standards line-by-line. No hand-waving.
- FDA Premarket Cybersecurity Guidance (Feb 3, 2026 final)
- FDA Section 524B (PATCH Act)
- AAMI SW96:2023
- AAMI TIR57
- IEC 81001-5-1
- IEC 62304
- ISO 14971
- NIST SP 800-30 / 800-53
- MDCG 2019-16 (EU MDR)
The work is published.
Competitors saying the same words can't show the same work. Here's ours, in public.
Our full pen test methodology - published, not gatekept.
Public CVD policy with intake form. Researchers can report safely.
Plain-English glossary of every FDA, AAMI, IEC, ISO standard we map to.
Six topic hubs aggregating our work, guides, and references on each subject.
What clients say.
Blue Goat Cyber helped us navigate our first end-to-end cybersecurity testing for our wearable medical device. Their communication was excellent, their timeline exceeded expectations, and their report helped us achieve FDA clearance without any additional questions. It was a truly seamless experience.
Blue Goat provided testing on our system for cybersecurity and provided the necessary documentation to add to our regulatory submission. They were very knowledgeable in the requirements, and performed the testing onsite which made the logistics of equipment availability easier for us. The communication was excellent, and they were able to expedite the testing and provide final reports in a very short period of time. My experience with this team was fantastic and I would not hesitate to use them again in the future.
Blue Goat Cyber takes the burden off our engineers and makes FDA cybersecurity requirements easy to understand. Their expertise and smooth process mean we can focus on our product, not the paperwork. The organized documentation, perfectly formatted for eSTAR, saves us countless hours.
Press, podcasts, and awards.
Validation we didn't write ourselves.
Medical Device Cybersecurity Solution of the Year 2026 - Blue Goat Cyber cover story
ViewCybersecurity Services Provider of the Year - Blue Goat Cyber
ViewMedTech Service Provider Excellence Award of the Year 2025 - announcement
ViewChristian Espinosa on FDA cybersecurity expectations and 510(k) pitfalls
ViewChristian Espinosa: 5 things you need to know to build a successful cybersecurity company
ViewWhy medical device cybersecurity can no longer be an afterthought
ViewComparing vendors? Send them this page.
When a competitor uses the same words we do, ask them for the same receipts: 250+ named submission breakdown, 0 cyber-related RTAs, certifications with verifiable holders, redacted SBOMs and threat models you can read, and a published methodology.
Get FDA cleared without the cybersecurity headaches.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.
