top of page

Medical Device Penetration Testing that Stands Up to FDA Scrutiny

Writer: MedSec
MedSec
Sep 1
5 min read

For medical device manufacturers, penetration testing sits at an uncomfortable intersection of engineering, patient safety, cybersecurity, and regulatory evidence. A test can be technically impressive and still leave the manufacturer with gaps. The scope may be too narrow. The tester may not understand how a safety-critical device is actually used. The report may describe vulnerabilities without giving engineering teams enough context to reproduce and address them. Or the final work product may require substantial cleanup before it can support a submission.


Challenge: Not all Penetration Tests are Created Equal

Medical devices are not ordinary IT assets. A connected product may span embedded firmware, custom hardware, mobile applications, cloud services, APIs, wireless protocols, hospital networks, third-party components, and specialized clinical workflows. A weakness in one part of that ecosystem can create consequences somewhere else, including consequences that affect the safety or effectiveness of the device or the lives of the patients it is supporting.


That makes penetration testing a test of the entire medical device ecosystem, not simply a scan of an endpoint. FDA’s February 2026 premarket cybersecurity guidance recommends penetration testing that identifies and characterizes security issues by discovering and exploiting vulnerabilities. It also calls for penetration test reports that document the independence and technical expertise of the testers, scope, duration, methods, and the resulting findings and observations. When a third party performs the test, FDA recommends that the manufacturer provide the original third-party report in the submission.


The June 2026 Medical Device Innovation Consortium (MDIC) best-practices paper goes further in explaining what good execution looks like. It emphasizes attack-surface-based scoping, the use of qualified and sufficiently independent testers, appropriate open-box or closed-box approaches, early planning, clear rules of engagement, and reports detailed enough for the manufacturer to understand what was attempted, what succeeded, what did not, and what should happen next.


These expectations expose a common problem for manufacturers: penetration testing is easy to procure as a generic cybersecurity service, but difficult to execute well in a medical device context. An automated vulnerability scan performed using an off-the-shelf tool masquerading as a “penetration test” is not equivalent to a manual penetration test performed by an experienced researcher. A checklist-driven assessment can miss device-specific attack paths. A strong generalist tester may still lose valuable time learning an unfamiliar architecture or fail to connect a technical exploit to a safety-relevant use case. And a thin report can create more work for the manufacturer at exactly the point when development and submission timelines are already tight.


Solution: Test the Device the Way a Real Adversary Would

MedSec’s penetration testing service is built specifically for medical devices and the supporting systems surrounding them. The engagement begins with the system architecture and the intended use of the product, then uses that context to determine where a capable attacker would look for leverage. Depending on the device, this can include embedded systems, firmware, web and mobile applications, APIs, cloud infrastructure, wireless communications, hardware interfaces, authentication paths, update mechanisms, or interactions with external networks and systems.


The goal is to use the available testing window intelligently. For highly complex products, providing threat models, architecture documentation, SBOM information, known-vulnerability dispositions, and other design material can help an experienced tester spend less time rediscovering the system and more time challenging its security assumptions. MDIC describes this open-box approach as particularly useful when the objective is to find problems in device business logic or to use limited penetration-testing time efficiently.


Just as important, the work does not end when an exploit is demonstrated. Findings need enough evidence and context to be reproducible. The manufacturer needs to understand the access obtained, controls bypassed, affected components, practical impact, and remediation considerations. Positive observations matter too. When controls resist attempted techniques, documenting that resilience gives the manufacturer a more complete picture of the device’s security baseline.


This is where deep medical device experience changes the value of the engagement. MedSec’s testing team has expertise across extensive medical device categories and technologies that include embedded systems, SaMD, infusion pumps, robotics, implantable devices, defibrillators, physiological monitors, imaging systems, insulin delivery systems, endoscopy devices, immunodiagnostic devices, and wireless communication devices, to name a few. The team is expected to understand both how attackers work and how medical devices are designed, validated, and used in order to properly exploit them.



Success: A Report the Engineering Team Can Use and the Submission Team Can Defend

The immediate success measure for a penetration test is straightforward: did the engagement identify meaningful weaknesses while there was still time to address them? The broader measure is whether the resulting evidence helps the manufacturer demonstrate that the device was tested with appropriate rigor.


That second measure is especially important in a premarket submission. FDA reviewers are not only looking for a list of findings. They are looking for evidence that the test was appropriately scoped, that the testers had suitable independence and expertise, that the methods were credible, and that the manufacturer understood and dispositioned the results. A well-constructed report gives the reviewer a coherent account of what was tested and why the results support confidence in the device’s security posture.


MedSec’s penetration test reports submitted in support of FDA review have consistently proceeded without substantive penetration-testing deficiencies. This outcome reflects a practical and high-quality standard for the work product: the report should support the submission rather than become another issue the manufacturer must solve.


For manufacturers, that translates into fewer handoffs between technical, quality, and regulatory teams. Engineering receives findings that are actionable. Cybersecurity and risk teams receive evidence they can disposition within the security risk management process. Regulatory teams receive an original third-party report designed with FDA’s stated content expectations in mind. And the reviewer receives a clearer basis for confidence that the device was meaningfully challenged before submission.


Differentiation: Deep Technical Testing With Regulatory Context Built In

Penetration testing quality is heavily dependent on the people performing the work. MDIC’s 2026 penetration testing best-practices whitepaper advises manufacturers to evaluate supplier expertise in the technologies used by the device, familiarity with attacker methodologies, experience with regulated products, and the quality of prior reporting. It also notes that broad device architectures may require more than one specialist to cover the full attack surface.


MedSec’s differentiation is the combination of senior-level technical depth in medical devices and a report-quality process informed by direct FDA cybersecurity policy experience. The testing team is expected to understand how real attackers work across embedded, application, cloud, wireless, network, firmware, and hardware components. The quality review is expected to understand what a regulator will look for when that work reaches a submission. This combination of deep technical expertise and regulatory context helps turn MedSec’s penetration testing service into credible evidence of device resilience, rather than a stand-alone security exercise.


That regulatory perspective is also grounded in active industry participation. MedSec experts were among the contributors to MDIC’s 2026 penetration-testing best-practices paper, alongside representatives from major medical device manufacturers and FDA. The value is not that MedSec can predict the questions a reviewer will ask. The value is that the company works in the same technical and policy details that shape what good medical device penetration testing looks like.


For a manufacturer, the objective is ultimately simple: challenge the product hard enough to learn something before an adversary does, then document the work well enough that the people responsible for product security, patient safety, and regulatory review can trust the evidence. That is the bar a medical device penetration test should be designed to meet, and one that MedSec can support.



References: U.S. Food and Drug Administration, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Feb. 3, 2026); Medical Device Innovation Consortium, Validating Medical Device Cybersecurity Through Penetration Testing: Best Practices (June 2026).

 
 
 

Comments


bottom of page