DFD3 data flow diagrams with trust boundaries, STRIDE per element, CIA attack trees, and an eSTAR-ready Threat Table where every row traces to a control, a test, and a patient harm. Security architecture views are a separate deliverable.
The short answer
Medical device threat modeling is the structured analysis of how an attacker could compromise a device's safety, effectiveness, or data - documented so an FDA reviewer can audit it. A reviewer-ready package decomposes the system into a DFD3 data flow diagram with trust boundaries, enumerates threats with STRIDE per element, scores each threat on exploitability and patient-safety impact rather than CVSS alone, and traces every threat to a control, a test case, and an ISO 14971 harm. The threat model is the input to the cybersecurity risk assessment and the vulnerability assessment, and it is a separate eSTAR attachment from the security architecture views.
275+ devices supported. No cybersecurity-related rejections to date.
Generic cyber risk workshops miss what FDA reviewers care about. A useful medical device threat model must decompose the system, identify threats across the total product lifecycle, and show how controls protect safety and effectiveness.
Missing elements, trust boundaries, entry points, or lifecycle threat sources leave reviewers unable to trace cybersecurity risk to patient safety.
Security architecture views are a separate eSTAR attachment. Supplying them in place of a threat model - or the reverse - is a named deficiency pattern.
Threats with no control, no test case, and no link to a patient consequence read as narrative, not evidence.
The threat model identifies and classifies what can go wrong. It is the anchor artifact other deliverables consume - it is not the security architecture views, and it is not the cybersecurity risk assessment.
Threat models are scoped to the data flows and trust boundaries reviewers expect to see. Every element below is enumerated and each STRIDE category exercised against it before a control is proposed.
Layers shown outermost (top) to innermost (bottom). Dashed rows are part of the surrounding system but out of scope for this view.
A clear path from system decomposition to a submission-ready threat model.
30-minute call to understand your device, intended use, connectivity, submission path, and current cybersecurity evidence.
We build the DFD3 diagram: elements, data flows, trust boundaries as closed shapes, and numbered entry points with named protocols and versions.
STRIDE per element plus three CIA attack trees, with clinical, engineering, quality, and regulatory teams aligning on threats, controls, and patient harm.
You receive the eSTAR-ready Threat Table with test-case IDs and Threat IDs that hand residual risk to the cybersecurity risk assessment.
Every medical device threat modeling engagement ships with the artifacts FDA reviewers expect to see - traceable, complete, and aligned with current guidance.
Recalls, CISA ICS-MA advisories, and disclosed research that shape what reviewers ask about - and what this engagement is built to cover.
CDRH deficiency letters in this period consistently call out threat models that fail to enumerate trust boundaries, miss the update channel as an element, or stop at network and ignore internal buses. The 2026 final guidance is more explicit on each.
"Blue Goat's knowledge of regulatory requirements versus cybersecurity challenges was highly valuable and readily apparent as we were guided by and worked alongside their team towards the development of a comprehensive and compliant cybersecurity plan for our new medical device. Especially helpful for our company as we are a startup. Their team and competencies nicely filled our resource needs. Thank you Blue Goat!"

See how this service applies to your specific MedTech segment.
Curated reading for teams working on threat modeling - grouped by format so you can jump to what you need.
Long-form reference reading - architecture, frameworks, and end-to-end how-tos.
Shorter posts on the specific gotchas, deficiencies, and reviewer expectations we see most.
Pressure-test the work yourself before you scope an engagement. No signup, results are yours to keep.
DFD3 data flow diagrams with trust boundaries, STRIDE per element, CIA attack trees, and an eSTAR-ready Threat Table where every row traces to a control, a test, and a patient harm. Security architecture views are a separate deliverable.