
Submitting a medical device to the FDA is a significant milestone. However, many organizations discover that preparing the device itself is only part of the challenge.
Increasingly, FDA reviewers are looking closely at cybersecurity documentation, software architecture, risk management activities, vulnerability assessments, and evidence that connected systems have been designed with security in mind.
Recently, Promenade Software supported a medical device company after FDA eSTAR reviewer feedback identified missing cybersecurity documentation required to support its regulatory submission. Although the product development was substantially complete, the submission lacked several cybersecurity artifacts needed for continued FDA review.
The challenge was clear: quickly generate the required cybersecurity artifacts, address identified risks, and help position the submission for continued FDA review.

Our first step was evaluating the FDA feedback and identifying the documentation needed to support the client’s connected medical device platform.
The system included a cloud-hosted environment, web-based applications, software components, and connected technologies that required comprehensive cybersecurity documentation and risk analysis.
Working closely with the client, we performed a gap assessment to identify missing cybersecurity deliverables and prioritize activities based on FDA expectations.
Working collaboratively with the client, Promenade Software developed a comprehensive. These documents were developed specifically to address FDA cybersecurity expectations and provide clear evidence of the client’s cybersecurity controls, risk management processes, and ongoing security strategy.

Documentation alone is only part of the cybersecurity story.
To further strengthen the submission, the client elected to perform independent penetration testing of the platform.
The penetration testing identified several areas for improvement, providing valuable insight into potential vulnerabilities and opportunities to strengthen the overall security posture of the system.
At the same time, Promenade Software conducted an SBOM vulnerability assessment to identify known software component vulnerabilities and evaluate potential risks associated with third-party dependencies.
Once the penetration test and SBOM analysis were complete, our team worked closely with the client to address identified findings.
Our goal was not simply to close findings, but to improve the overall cybersecurity posture of the platform while maintaining usability and system performance.
By combining remediation activities with updated documentation, we helped the client be able to demonstrate a more comprehensive cybersecurity strategy aligned with FDA expectations.

Because the application operates within a cloud environment, cybersecurity considerations extend beyond the software itself.
Promenade Software also supported the application’s cloud infrastructure through CypherMed Cloud, helping ensure that the architecture, access controls, monitoring, logging, and security configurations aligned with the client’s overall cybersecurity strategy.
As connected medical devices, Software as a Medical Device (SaMD) solutions, and cloud-connected healthcare platforms continue to grow, organizations must consider cybersecurity across the entire ecosystem,not just within the application itself.
Promenade Software helps medical device companies navigate the growing cybersecurity requirements associated with FDA submissions, connected medical devices, cloud-hosted healthcare platforms, and Software as a Medical Device (SaMD) solutions.
Our team supports clients with:

Organizations that proactively address these requirements often experience a smoother regulatory review process and are better positioned to manage cybersecurity risks throughout the product lifecycle.
Whether you’re preparing an FDA submission, responding to reviewer feedback, or strengthening the cybersecurity posture of an existing product, Promenade Software can help accelerate the process while reducing risk.