You already have a threat model and hazard analysis. We check whether they will hold up to FDA review and drive a penetration test, focusing only on cybersecurity-related hazards.
A gap assessment reviews the threat model and the cybersecurity-related hazards you already have against Section 524B and the February 3, 2026 FDA guidance. We check that every threat that could hurt a patient traces into your ISO 14971 file, then give you a rated gap list. We don't review non-security hazards.
Your threat model, the cybersecurity-related rows of your hazard analysis, and the documents behind them: Instructions for Use, software architecture and any data flow diagrams. Drafts are fine.
Scope and trust boundaries, the four architecture views, STRIDE coverage of every interface, the Threat Table, named controls, and stated assumptions.
Whether each threat that could hurt a patient traces to a hazard and harm in your ISO 14971 file, with severity taken from your safety scale and exploitability scored separately.
Acceptance criteria set before scoring, controlled vs uncontrolled residual risk, and whether a reviewer can follow one line from threat to control to test to residual risk.
Each gap ranked by priority, with what to fix and why it matters for FDA review. A call to walk through it, then you fix it yourselves or we close it for you.
For how the threat model and the ISO 14971 file fit together, read ISO 14971 and AAMI SW96. For the full method we check against, see our risk methodology. Building your own first? Download our free threat model template (Excel). For what a complete threat model contains, see the threat model template.
We look at hazards where a deliberate attacker could cause patient harm, such as a spoofed dose command or a tampered result. Mechanical, electrical, biocompatibility and use-error hazards stay with your safety team. Severity comes from your existing safety scale; we don't redefine it.
Fix the gaps yourselves, or have us close them. Once both documents are ready, they drive our medical device penetration testing. No threat model yet? Start with threat modeling instead.
Tell us about your device and what documents you have. We'll set up a short scoping call and quote a fixed fee.