Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Playbook · Threat Modeling

    Medical Device Threat Modeling Starter Kit

    STRIDE-per-element + AAMI TIR57 methodology, a device-specific threat checklist, an attack-tree template, and the traceability matrix reviewers want.

    All playbooks
    Updated April 2026 6 pages 13-min read Download PDF

    Why this matters

    The FDA's 2026 final premarket guidance and AAMI TIR57:2016/(R)2023 both require a structured, documented threat model. Reviewers reject generic 'STRIDE applied to a SaMD' write-ups. This kit gives you a repeatable methodology you can run on your own device today and present to a reviewer with confidence.

    Key takeaway: A threat model is not a one-time deliverable. It is a living artifact that gets updated every time the architecture changes - new interface, new dependency, new deployment target.

    The five-step methodology

    Device-specific threats to walk through (sample)

    What's in the full PDF

    Want the full 6-page playbook?

    Includes every checklist, table, and template - formatted for printing and sharing.

    Download PDF
    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.