If a tool produces evidence that goes into an FDA submission, that tool lives inside your quality system. Which means the FDA can ask whether it was validated for its intended use, the same way any other software tool in an ISO 13485 QMS has to be.
This is easy to overlook with security tooling, because scanners and pentest scripts feel like utilities rather than quality-system software. But the output of those tools is now regulatory evidence. An unvalidated tool producing your vulnerability ratings is a gap an auditor can pull on.
The moment a tool's output is defensible evidence, the tool itself becomes something you have to defend.
This is one reason we built ELTON to be pre-validated for use inside an ISO 13485 QMS, and backed the rating methodology with an FDA-recognized MDDT. It moves the validation burden off the manufacturer's plate for the part that matters most, the ratings that regulators will scrutinize.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.
One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.
If a tool produces evidence that goes into an FDA submission, that tool lives inside your quality system. FDA can ask whether it was validated for its intended use, the same way any other software tool in an ISO 13485 QMS has to be. Where the output lands is what pulls the tool in.
Because scanners and scripts feel like utilities rather than quality-system software. They sit with the engineering tools, not with document control. But the output of those tools is now regulatory evidence, and an unvalidated tool producing your vulnerability ratings is a gap an auditor can pull on.
The moment a tool's output becomes defensible evidence, the tool itself becomes something you have to defend. The trigger is not the category of tool. It is the destination of its output, which is why the same scanner can be a utility in one workflow and quality-system software in another.
The ratings. Severity scores drive the fix or no-fix decision and the risk acceptance record behind it, so they are what regulators scrutinize. A rating produced by an unvalidated tool leaves that decision resting on an assumption nobody examined.
Partly, by using tooling that arrives pre-validated for use inside an ISO 13485 QMS. ELTON was built that way, with the rating methodology backed by an FDA-recognized MDDT, which moves the burden off the manufacturer for the part that matters most.