Security testing for medical devices is still bought the way it was bought fifteen years ago. Scope a project. Get a quote. Wait for the bench to free up. Receive a PDF. Then the product ships two more releases and the PDF describes a device that no longer exists.
Regulators have moved past that model even if procurement hasn't. FDA's premarket and postmarket guidance both expect periodic testing plus continuous vulnerability management: SBOM monitoring, defensible ratings, documented dispositions across the lifecycle. A point-in-time engagement, however good, can't carry a continuous obligation.
ELTON sells testing as a subscription. One fixed annual price covers every testing class, every release, all year. No scoping call per test, no per-engagement quotes, no change order when a release lands early. Testing stops being a project you procure and becomes a function you subscribe to, which is what the regulation was implicitly asking for all along.
The delivery model is what makes that price workable. The subscription is not a bench of consultants on retainer. The ELTON platform runs the testing: attack surface analysis of exposed interfaces, exploitation of findings and chains, known vulnerability scanning with static and dynamic analysis, fuzzing and malformed-input testing against the device's protocols. Continuously, against the current release, with exploitability verified on the real device rather than assumed from a version string.
Each class produces different evidence, and reviewers ask for all of it. Attack surface work shows you know what's exposed. Exploitation shows what an attacker can actually reach. Scanning proves the known-vulnerability baseline is covered. Fuzzing shows how the device behaves when inputs go wrong. One subscription keeps all four running instead of forcing you to pick which one this year's budget covers.
The methodology inside the platform didn't come from nowhere. It's anchored in PTES and ISSAF and encodes what our team learned across 2,000+ device tests. The difference is that it no longer sleeps between engagements.
One-off findings with one-off scores rarely describe real risk. The platform overlays results onto the device's digital twin and maps how issues chain: an initial access vector, a privilege escalation, a bypassed control, an outcome. So a finding that looks minor alone gets rated for the path it enables.
Ratings follow the FDA-recognized MITRE CVSS rubric, applied the way FDA expects. Discovery effort doesn't discount severity, because an exploit is assumed reusable once found. Attack vector is judged without crediting the hospital's firewall. And attack complexity stays low unless exploitation genuinely requires rare conditions.
Pentesting was never the product. Evidence was.
Findings don't land in a PDF. They land in the platform, tied to components and controls, where ratings update as new CVEs arrive and patches change the attack surface. When you need a submission-ready report, premarket or postmarket, it's generated from current state, with methodology, scope, and results documented the way reviewers ask for them. That format has carried more than 600 regulatory submissions, and the same evidence base serves FDA, EU MDR, Health Canada, and PMDA expectations without a separate lift per market.
Coverage that matches your release cadence instead of your procurement calendar. A test program that's already running when an auditor asks what testing happened this year. Metrics like time-to-triage that generate themselves. And a budget line that's flat and predictable instead of a negotiation for every engagement.
I spent years on the services side of this industry, quoting engagement after engagement, and I watched the gaps between tests become the place where risk actually lived. The fix wasn't more engagements. It was removing the concept of an engagement entirely. Continuous obligations deserve continuous instruments, and a subscription to a platform is that idea taken seriously.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.