Case Study: Helping a Medical Device Company Respond to FDA Cybersecurity Feedback

When FDA Cybersecurity Requirements Become a Roadblock

Submitting a medical device to the FDA is a significant milestone. However, many organizations discover that preparing the device itself is only part of the challenge.

Increasingly, FDA reviewers are looking closely at cybersecurity documentation, software architecture, risk management activities, vulnerability assessments, and evidence that connected systems have been designed with security in mind.

Recently, Promenade Software supported a medical device company after FDA eSTAR reviewer feedback identified missing cybersecurity documentation required to support its regulatory submission. Although the product development was substantially complete, the submission lacked several cybersecurity artifacts needed for continued FDA review.

The challenge was clear: quickly generate the required cybersecurity artifacts, address identified risks, and help position the submission for continued FDA review.

Assessing the Gap

Our first step was evaluating the FDA feedback and identifying the documentation needed to support the client’s connected medical device platform.

The system included a cloud-hosted environment, web-based applications, software components, and connected technologies that required comprehensive cybersecurity documentation and risk analysis.

Working closely with the client, we performed a gap assessment to identify missing cybersecurity deliverables and prioritize activities based on FDA expectations.

Developing the Required Cybersecurity Documentation

Working collaboratively with the client, Promenade Software developed a comprehensive. These documents were developed specifically to address FDA cybersecurity expectations and provide clear evidence of the client’s cybersecurity controls, risk management processes, and ongoing security strategy.

Beyond Documentation: Independent Security Testing

Documentation alone is only part of the cybersecurity story.

To further strengthen the submission, the client elected to perform independent penetration testing of the platform.

The penetration testing identified several areas for improvement, providing valuable insight into potential vulnerabilities and opportunities to strengthen the overall security posture of the system.

At the same time, Promenade Software conducted an SBOM vulnerability assessment to identify known software component vulnerabilities and evaluate potential risks associated with third-party dependencies.

Remediating Findings and Reducing Risk

Once the penetration test and SBOM analysis were complete, our team worked closely with the client to address identified findings.

Our goal was not simply to close findings, but to improve the overall cybersecurity posture of the platform while maintaining usability and system performance.

By combining remediation activities with updated documentation, we helped the client be able to demonstrate a more comprehensive cybersecurity strategy aligned with FDA expectations.

Supporting a Secure Cloud-Based Platform

Because the application operates within a cloud environment, cybersecurity considerations extend beyond the software itself.

Promenade Software also supported the application’s cloud infrastructure through CypherMed Cloud, helping ensure that the architecture, access controls, monitoring, logging, and security configurations aligned with the client’s overall cybersecurity strategy.

As connected medical devices, Software as a Medical Device (SaMD) solutions, and cloud-connected healthcare platforms continue to grow, organizations must consider cybersecurity across the entire ecosystem,not just within the application itself.

How Promenade Software Helps

Promenade Software helps medical device companies navigate the growing cybersecurity requirements associated with FDA submissions, connected medical devices, cloud-hosted healthcare platforms, and Software as a Medical Device (SaMD) solutions.

Our team supports clients with:

  • Medical device software development
  • FDA cybersecurity documentation
  • SBOM generation and vulnerability assessment
  • Penetration test and vulnerability  remediation

Organizations that proactively address these requirements often experience a smoother regulatory review process and are better positioned to manage cybersecurity risks throughout the product lifecycle.

Whether you’re preparing an FDA submission, responding to reviewer feedback, or strengthening the cybersecurity posture of an existing product, Promenade Software can help accelerate the process while reducing risk.

Need help on this topic?
Contact Us
Roxana Greenman, PhD

Roxana is Chief Operating Officer at Promenade Software, Inc. She has over 30 years of experience leading integrated teams from concept through delivery of complex projects, proactively anticipating roadblocks, and paving a path for client success. Having worked for NASA Ames Research Center, Lawrence Livermore National Laboratory, Hyundai AutoEver Telematics America, and small business organizations in the technology sector, she has gained an extensive knowledge in product development and technical and operational management. Roxana is passionate about helping customers in their quest for innovation and reaching their goals.

Roxana holds a Ph.D. in Aeronautical and Astronautical Engineering from Stanford University.

linkedin logo
SUBSCRIBE TO
NEWSLETTER
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
ABOUT
PROMENADE SOFTWARE

Promenade Software, Inc. specializes in software development for medical devices and other safety-critical applications.
Promenade's Quality Management System is ISO 13485 certified. Our Cloud systems are  SOC2 Type II certified.