The most expensive mistake in medical device cybersecurity is not missing a vulnerability. It is fixing one that never needed to be fixed. A rushed patch on a validated system carries real cost: regression testing, field updates, disrupted clinical workflows, and in the worst cases a recall that protected nobody because the finding was never exploitable to begin with.
And yet the patch everything reflex persists. Teams remediate every reported CVE because fixing feels safer than explaining. I think that instinct gets the risk exactly backwards.
A common misconception is that FDA expects every vulnerability remediated. The guidance is consistently risk based. What reviewers require is evidence: that you understand the vulnerability, how it applies to your specific device, and why remediation is or is not necessary. Choosing not to fix is a legitimate regulatory outcome when the reasoning holds up.
Section 524B put premarket and postmarket vulnerability management squarely in scope. It did not mandate that every CVE be patched. What it demands is a process, and proof the process ran.
The problem is that most vulnerability data cannot carry that burden. CVSS base scores are generic by design. Scanner output knows nothing about your architecture. An engineer's hallway opinion that the component is not reachable is worth exactly nothing in an audit unless it is tied to the product and written down.
In an audit, an unsupported claim is indistinguishable from wishful thinking.
We built ELTON to make non-remediation defensible. Every vulnerability is evaluated against a digital twin of the product, constructed from the QMS documentation you already maintain: components, data flows, trust boundaries, assets, and security controls. The twin turns each finding into a set of answerable questions.
When the answers show exploitation is not feasible, ELTON documents that conclusion with rationale traced to the architecture. Not adjectives. A chain of reasoning a reviewer can follow from claim to component.
Adjusted ratings only help if the reviewer trusts the method behind them. So ELTON applies the CVSS rubric recognized under FDA's Medical Device Development Tool program (MITRE's rubric, MDDT Q171974) at scale. A downgraded finding is the outcome of a documented methodology reviewers are trained to recognize, not an argument against their expectations.
That shifts the entire conversation. Instead of debating severity labels, you are walking through evidence and method together. Reviews move faster when both sides trust the instrument.
Defensible non-remediation only works if it lives inside the quality system. ELTON generates documentation that drops into design history files, risk management files, and postmarket cybersecurity records, with every decision traceable to its inputs, analysis, and outputs. Because each commercial release gets its own twin, the justification stays pinned to the exact configuration under review. VEX output carries the same conclusions in machine-readable form for the customers and regulators who ask.
The practical effect is focus. Across products we see a small fraction of findings, call it the 1%, that genuinely require a fix, and the job is to prove why the other 99% do not. Emergency patch cycles become rare. Engineering time goes to the vulnerabilities that actually move risk.
I have watched manufacturers burn entire quarters, and occasionally pull product from the field, over findings that were never reachable on the shipped device. Nobody was safer afterward. Fixing everything is not diligence, it is unexamined fear with a budget, and FDA never asked for it. They asked for evidence. Give them that instead.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.