Threat Modeling for Medical Devices
Threat modeling is the foundation of every credible cybersecurity submission - and the section reviewers scrutinize most. This hub collects our threat modeling service, FDA-aligned methodology, the 12 gaps we see most often, and how STRIDE maps to AAMI SW96 risk management. A submission-grade threat model produces traceable artifacts at four layers: a system and data-flow decomposition that names every trust boundary, asset, and external interface; a STRIDE-per-element analysis that enumerates spoofing, tampering, repudiation, information disclosure, denial-of-service, and elevation-of-privilege threats against each component; a risk evaluation that scores likelihood and harm severity using the device's intended-use and use-environment context, including multi-patient and fleet-level harm scenarios reviewers now expect under the FDA February 2026 final guidance; and a mitigation traceability matrix that maps every accepted threat to a security control, a verification test, and a residual-risk entry in the ISO 14971 risk file. Threat models that skip the trust-boundary map, treat the device as a single black box, or omit multi-patient harm are the single most common driver of first-cycle cybersecurity Additional Information letters. AAMI SW96 is now the bridge reviewers expect between the security threat analysis and the safety risk file, and a threat model that doesn't carry threats into the SW96 risk register reads as incomplete regardless of how thorough the STRIDE work is.
The short answer
A submission-grade medical device threat model decomposes the whole system into data flows and trust boundaries, applies STRIDE per element, rates each threat using intended use and use environment (including multi-patient and fleet-level harm), and traces every threat to a control, a verification test, and a residual-risk entry in the ISO 14971 file through ANSI/AAMI SW96:2023. The FDA's February 2026 guidance treats the threat model as the spine of the submission, and incomplete trust-boundary coverage is the most common driver of first-cycle deficiency letters.
Services
- Medical Device Threat Modeling
Comprehensive threat modeling per FDA Section V.A.1 - covering supply chain, deployment, environment of use, and decommission risks for the full device system.
- Secure MedTech Product Design
Architecture review, control selection, and secure development guidance from concept through V&V - aligned with FDA's Secure Product Development Framework.
- Full-Service FDA Premarket Cybersecurity
Full-service, end-to-end: we deliver 100% of the artifacts FDA reviewers expect for 510(k), De Novo, PMA, PDP, and HDE submissions under §524B, plus IDE applications under 21 CFR 812 and the FDA's February 3, 2026 premarket guidance - traceable, complete, and current.
In-depth guides
- ISO 14971 vs AAMI TIR57: Hazard Analysis Meets Cybersecurity RiskHow safety hazard analysis and security risk analysis run in parallel and converge at the patient-harm column, with a side-by-side mapping table.
- 12 Critical Threat-Modeling Gaps in SubmissionsA practical, ungated guide to the threat modeling gaps that trigger FDA cybersecurity questions in 510(k), De Novo, and PMA submissions - and exactly how to close them before reviewers find them.
- The SPDF PlaybookA practical, ungated guide to building a Secure Product Development Framework (SPDF) that FDA accepts, the eight pillars, the artifacts each one produces, and a pre-submission readiness checklist you can score yourself against.
- STRIDE Threat Modeling for Medical DevicesMaster STRIDE threat modeling for medical devices. Learn to identify risks, meet FDA premarket requirements, and secure your MedTech ecosystem. Read our guide.
- FDA-Grade Medical Device Threat Model: Template & Worked ExampleStep-by-step template to build a threat model FDA reviewers will accept - architecture views, STRIDE, safety mapping, control traceability, and a worked example.
- AAMI TIR57 vs TIR97: Medical Device Risk Management GuideCompare AAMI TIR57 vs TIR97. Learn how these cybersecurity risk management standards differ and how to apply them for FDA premarket and postmarket compliance.
- IEC 81001-5-1 Security Risk Assessment GuideLearn how to implement IEC 81001-5-1 security risk assessments for FDA compliance. Expert guidance on medical device lifecycle security mapping.
- FDA Security Control Categories: What Reviewers Expect Per CategoryThe 8 security control categories every cyber device must cover, and the evidence FDA expects for each one.
Standards & guidance
Defined entries from our MedTech Cybersecurity Standards Glossary.
- ANSI/AAMI SW96Medical Device Security Risk ManagementThe consensus standard for medical device security risk management - asset, threat, vulnerability, likelihood, severity, and residual risk acceptability.
- AAMI TIR57Principles for Medical Device Security - Risk ManagementThe MedTech-specific extension of ISO 14971 for cybersecurity. Defines how to identify cybersecurity assets, threats, and vulnerabilities, then estimate, evaluate, and control the resulting risk.
- ISO 14971Medical Device Risk ManagementThe umbrella risk-management standard for medical devices. Defines hazard identification, risk estimation, risk evaluation, risk control, and residual risk evaluation. Cybersecurity risks must be reconciled here so a security control never silently introduces a safety hazard.
- SPDFSecure Product Development FrameworkA documented framework that shows security activities are integrated across the device lifecycle - not bolted on at the end. Includes secure requirements, threat modeling, secure coding, V&V, vulnerability management, and post-market response.
- FDA 2026 GuidanceFDA Premarket Cybersecurity Guidance (Feb 3, 2026)The FDA's final premarket cybersecurity guidance, effective February 3, 2026. Defines the seven-section cybersecurity submission format reviewers now enforce at Technical Screening, replacing the 2023 draft. Operationalizes Section 524B of the FD&C Act.
From the blog
- Threat Modeling Connected & Implantable DevicesMedical device threat modeling steps: scoping, data flow diagrams, STRIDE, ISO 14971 harm scoring, and what FDA reviewers expect in a submission package.
- FMEA vs Threat Modeling for Medical DevicesFMEA covers random and systematic failure modes; threat modeling covers adversarial action.
- Home Use vs Hospital Device Cybersecurity RequirementsHome use vs hospital device cybersecurity: which controls the HDO environment provides, which the device must carry itself, and how the FDA reviews each case.
Related FDA deficiencies
The deficiency letters reviewers most often write on submissions in this topic area. Each links to the full response playbook.
- Incomplete Threat Model
Reviewers say your STRIDE/attack-tree analysis misses interfaces, trust boundaries, or post-market threat surfaces.
Response playbook - Missing Cybersecurity Risk Assessment
Reviewers cannot find a cybersecurity risk assessment distinct from the ISO 14971 safety risk file, or the integration is unclear.
Response playbook - Missing Security Architecture Views
Your submission is missing one or more of the architecture views FDA 2026 expects (global system, multi-patient, updateability).
Response playbook - Insufficient Penetration Testing Evidence
Reviewers find your penetration test scope too narrow, methodology unclear, or testers insufficiently independent.
Response playbook
Threat Modeling for Medical Devices - frequently asked questions
Get FDA cleared without the cybersecurity headaches.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.
