SaMD Penetration TestingCloud, API, Web and Mobile, Ready for FDA Review.
Your SaMD has no circuit board, so the attack surface is the cloud, the APIs, the apps and the identity system. We test all of it as one engagement, scoped from your threat model, and deliver a report built for an FDA premarket submission.
The short answer
What is SaMD penetration testing?
SaMD penetration testing checks software-only medical devices the way an attacker would: the cloud backend, APIs, web portals, mobile apps and the identity system that ties them together. Because connected SaMD counts as a cyber device under Section 524B, the FDA expects penetration testing as part of the cybersecurity evidence. We scope the test from your threat model, rate findings with CVSS and patient-harm impact, and trace each one back to your risk file.
275+ devices supported. Mostly manual, expert-led testing.
- Cloud + IAM
- API authorization
- Web + mobile apps
- Threat-model traceability
- Retests until findings close
- Free 30-min call
- No obligation
- Senior expert, not a sales rep
- Fixed-fee quote in 24 hours
- NDA available on request
Why a generic web app pen test falls short for SaMD
An IT pen test can find the same bugs. It rarely produces evidence an FDA reviewer can use.
No link to the threat model
The FDA expects testing to verify the threats and controls you documented. A report that never mentions your threat model leaves the reviewer to connect the dots, and they usually ask instead.
Threat model gap assessmentCVSS alone is not patient-harm risk
A medium CVSS finding that lets one clinic see another clinic's results matters more than a critical finding with no path to a patient. Findings need a patient-harm rating that feeds your ISO 14971 file.
Pieces tested separately
When the cloud, the mobile app and the web portal are tested by different vendors, nobody tests the paths between them. That is often where tenant isolation and token handling break.
What we test in a SaMD engagement
Scope comes from your threat model and architecture views, so the report matches what you describe in the submission.
Cloud & Identity
- IAM least-privilege review (AWS / Azure / GCP)
- Key management and storage exposure
- Tenant isolation between customers and sites
- Secrets in code, config and CI/CD
APIs
- Object- and function-level authorization (BOLA / BFLA)
- Token lifecycle, refresh and revocation
- Input handling, injection and SSRF
- Rate limits and mass assignment
Web & Mobile Apps
- Login, session and role boundaries (OWASP ASVS)
- iOS and Android data storage and transport (OWASP MASVS)
- Patient data exposure in the UI, logs and exports
- Update and configuration integrity
AI/ML Models (when present)
- Model and training-data access controls
- Tampering with model updates
- Adversarial input handling where in scope
How a SaMD pen test runs
- 01
Scoping call
We review your architecture, threat model and hazard analysis, agree on the environment and test windows, and send a fixed-fee quote. If the threat model or hazard analysis is missing or thin, we start there.
- 02
Kickoff and intake
A project manager runs the engagement over Slack and secure file sharing. You provide test accounts, API docs and read-only cloud access where possible.
- 03
Testing
Manual, white-box testing of the cloud, APIs and apps, using synthetic accounts and data. We never pull real patient data.
- 04
Report and retests
An FDA-ready report with CVSS and patient-harm ratings traced to your threat model, then retests until findings close.
Reviewer-ready deliverables in one engagement
Every samd penetration testing engagement ships with the artifacts FDA reviewers expect to see - traceable, complete, and aligned with current guidance.
- Cloud backend, IAM and tenant isolation testing
- API authorization testing (OWASP API Top 10)
- Web and mobile app testing (OWASP ASVS / MASVS)
- FDA-ready report with threat-model traceability and retests
Pricing Guidance
Fixed-fee. Cloud scope scales with surface area, not just lines of code.
Single-Cloud, Single-Tenant
$15k - $30k
One cloud (AWS or Azure or GCP), single-tenant deployment, modest API surface, no IoT broker or limited MQTT scope.
- API authZ matrix (up to ~30 endpoints)
- IAM + KMS + storage configuration review
- PHI data-flow trace
- HIPAA technical-safeguard validation
- One round of re-test
Multi-Tenant SaaS
$30k - $60k
Most connected-device platforms: multi-tenant, device-to-cloud channel, ~50-150 API endpoints, IoT Core / IoT Hub in scope.
- Full tenant-isolation matrix
- Device-channel + MQTT topic ACL testing
- Cross-tenant PHI exposure probing
- IaC review (Terraform / CDK / Bicep) where available
- Two rounds of re-test
Multi-Cloud / Enterprise
$60k - $120k+
Multi-cloud or hybrid deployments, enterprise IDP federation, complex data-residency requirements, or high-volume IoT fleets.
- Per-cloud configuration audit
- Federated identity + SSO boundary testing
- Data-residency and cross-region PHI flow review
- Dedicated senior cloud + healthcare lead
What drives the price
- Number of clouds in scope (AWS / Azure / GCP)
- Number of API endpoints and microservices
- Multi-tenancy model (shared schema, schema-per-tenant, account-per-tenant)
- Device-channel protocol (HTTPS, MQTT, AMQP, custom)
- Test environment (production with safeguards vs. staging clone)
- Whether infrastructure-as-code is available for review
- PHI volume and data-residency constraints
Production testing is supported with PHI-safe test accounts and rate-limit coordination. We never exfiltrate real PHI.
SaMD Penetration Testing FAQs
SaMD Penetration Testing - scoped, fixed-fee, FDA-ready.
Your SaMD has no circuit board, so the attack surface is the cloud, the APIs, the apps and the identity system. We test all of it as one engagement, scoped from your threat model, and deliver a report built for an FDA premarket submission.
