Pick the interfaces your device actually exposes - from Wi-Fi and BLE to NFC, RFID, USB-OTG, JTAG, and CAN. Get the threats reviewers expect to see in the threat model, the pen-test scoping that proves them out, and the evidence each interface adds to your premarket submission.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Interfaces the device actually exposes
Include service-only ports, paired accessories, and anything physically present even if disabled in software.
Wireless
Wired / physical
Cloud / app
Update / service
What you'll see after you submit
Common misconceptions
Myth: If it's just NFC for pairing, it doesn't need a threat model entry.
Reality: Tap-to-configure NFC is one of the most common ways malicious configuration lands on a device. Reviewers expect it in the threat register with signed-payload mitigations.
Myth: RFID is a logistics concern, not a cybersecurity concern.
Reality: If the device authenticates a consumable, accessory, or clinician using RFID, it is a safety-relevant security control and must be modeled.
Myth: A USB-C port that 'only charges' has no attack surface.
Reality: USB-C role detection can be coerced. Without hardware-level data-line isolation, the port is a data path.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
Add asset-level threats + ISO 14971 linkage.
Read Threat Model StarterTurn this profile into an effort estimate.
Read Pen Test Scope EstimatorRun the test against every interface on this profile.
Read Medical device penetration testingGet the evidence into the submission cleanly.
Read FDA premarket cybersecurity