Most cybersecurity deficiencies that look like a cryptography problem are really a key management problem: a device that can verify a signature but can never be issued a second key, an update channel with no rollback protection, or a certificate whose expiry falls inside the device's service life. This hub gathers what we publish on authentication and access control, code and data integrity, secure update infrastructure, key exchange, and post-quantum planning. Use it to decide what has to be fixed in hardware before tape-out, what can still change in firmware later, and what evidence belongs in the premarket package versus the postmarket file.
The short answer
Cryptography in a medical device covers four jobs a reviewer will look for separately: authenticating who is talking to the device, protecting data in transit and at rest, proving that firmware and stored data have not been altered, and signing the updates you ship after clearance. Section 524B and the February 3, 2026 final guidance do not name algorithms, but they do expect each control to trace to a threat in your security risk file and to a key that has a documented lifecycle.
Architecture review, control selection, and secure development guidance from concept through V&V - aligned with FDA's Secure Product Development Framework.
Full-service, end-to-end: we deliver 100% of the artifacts FDA reviewers expect for 510(k), De Novo, PMA, PDP, and HDE submissions under §524B, plus IDE applications under 21 CFR 812 and the FDA's February 3, 2026 premarket guidance - traceable, complete, and current.
Hardware, firmware, mobile, and cloud - tested by operators with both red-team and medical-device experience. Reports built for FDA reviewers.
Defined entries from our MedTech Cybersecurity Standards Glossary.
The deficiency letters reviewers most often write on submissions in this topic area. Each links to the full response playbook.
Reviewers cannot find evidence that your QMS implements a Secure Product Development Framework integrated with design controls.
Response playbookYour VM plan lacks defined triage timelines, a coordinated vulnerability disclosure path, or a documented patch-deploy mechanism.
Response playbookReviewers want test evidence that secure boot, signed updates, and root-of-trust controls function as claimed.
Response playbookYour post-market plan lacks monitoring, patching commitments, customer communications, or end-of-support handling.
Response playbook30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ devices supported.