Intelligence

FDA cybersecurity, the AI vulnerability era, and how to stay defensible.

Field notes from a team that has taken more than 600 vulnerability reports through FDA review. Guidance, regulation, and where medical device security is going. 38 articles and counting.

AI & Threat Landscape

The AI vulnerability explosion: automate or drown

AI collapsed the cost of finding vulnerabilities to almost nothing. CVE volume is going exponential. Here is the response.

May 19, 2026 · 3 min read
Compliance & Regulation

What eSTAR requires in 2026

With final cybersecurity guidance in effect and QMSR taking hold, a cyber device submission carries nine distinct deliverables through eSTAR.

March 25, 2026 · 3 min read
Compliance & Regulation

Preparing for CVSSv4: why manufacturers must act now

The 2027 CVSSv4 expectation is closer than it looks, and it rewards exactly the chained analysis most programs do not do yet.

February 11, 2026 · 3 min read
ELTON

Why FDA requires vulnerability chaining, and how ELTON delivers it

Attackers chain unimpressive bugs into critical outcomes. FDA 2025 guidance expects your analysis to follow the path, not the score.

January 21, 2026 · 3 min read
ELTON

How ELTON helps manufacturers avoid unnecessary fixes, recalls, and fire drills

The most expensive mistake in device security is fixing a vulnerability that never needed it. The patch everything reflex has risk backwards.

January 16, 2026 · 3 min read
ELTON

How ELTON works: from discovery to continuous monitoring

Model, discover, verify, prove, monitor. One loop from QMS documentation to evidenced dispositions, kept current for every release.

January 16, 2026 · 3 min read
Compliance & Regulation

QMSR: FDA replaced 21 CFR Part 820 with ISO 13485, and what it means for cybersecurity

A major quality-system shift, but it does not change your cybersecurity obligations. Here is what actually changed.

January 15, 2026 · 3 min read
Case Study

Case study: responding to FDA Additional Information (AI) requests

Nearly 100 unresolved SBOM CVEs, an FDA AI letter, one response window. Evidence, not opinion, carried the submission.

November 12, 2025 · 3 min read
ELTON

ELTON's leadership and credibility in medical device cybersecurity

A decade of device pentesting, 2,000+ tests, 600+ submissions. Credibility in this field is accumulated, not claimed.

November 10, 2025 · 3 min read
Compliance & Regulation

What happens when the FDA flags a cybersecurity deficiency

An AI letter starts a 180-day clock. What the FDA's cybersecurity deficiencies actually say, and how to answer them with evidence that agrees.

November 7, 2025 · 3 min read
Compliance & Regulation

Do legacy medical devices still require cybersecurity monitoring and annual testing?

Cleared before 2023? If it still ships, the obligations still run. Commercial status, not clearance date, decides what you monitor and test.

November 7, 2025 · 3 min read
Penetration Testing

Postmarket testing: why every release needs its own

One annual pentest stretched across versions is evidence for none of them. Every release needs its own testing record. Automation makes it viable.

November 7, 2025 · 3 min read
Compliance & Regulation

"We did a pentest" no longer satisfies medical device regulators

Regulators moved from isolated findings to completeness, traceability, and defensibility across the full lifecycle. One point-in-time pentest cannot show that.

November 6, 2025 · 3 min read
Compliance & Regulation

Meeting China's CFDA Cybersecurity Law (CSL) requirements

China's 2018 CFDA guidelines ask for five artifacts. All five are views of one system model. Build the model and the paperwork falls out.

October 28, 2025 · 3 min read
Compliance & Regulation

EU-MDR recertification: what MDCG expects on cybersecurity

Devices CE marked years ago now face cybersecurity questions nobody asked at design time. The recertification gap is continuity, not testing.

October 28, 2025 · 3 min read
Compliance & Regulation

How ELTON supports CAPA for cybersecurity vulnerabilities

A vulnerability is a quality event. How findings flow through 21 CFR 820.100 CAPA with evidence, and what changes under QMSR and ISO 13485.

October 27, 2025 · 3 min read
ELTON

FDA-qualified CVSS scoring: how ELTON operationalizes the MITRE rubric

A 9.8 on NVD is not a 9.8 on your device. Inside the FDA-qualified MITRE CVSS rubric, and how ELTON runs it automatically.

October 21, 2025 · 3 min read
Compliance & Regulation

Common FDA cybersecurity AI deficiency questions

FDA AI letters recycle the same questions: threat models, testing evidence, SBOMs, scoring. All are traceability complaints in disguise.

August 29, 2025 · 3 min read
Compliance & Regulation

How ELTON protects you in an FDA cybersecurity audit

Audits test records, not intentions. Why fragmented programs fail and how a system of record makes the answer predate the question.

August 27, 2025 · 3 min read
ELTON

Subscription security testing, platform delivered

Fixed annual price. Every testing class. No per-engagement quotes. Continuous testing, delivered by the platform instead of a bench.

August 27, 2025 · 3 min read
ELTON

Why medical device manufacturers choose ELTON for vulnerability management

Static reports go stale the day they're signed. Continuous, context-scored vulnerability management is now the FDA's baseline expectation.

August 27, 2025 · 3 min read
ELTON

Automating FDA cybersecurity compliance with ELTON

We automate the FDA's 524B vulnerability testing and management work, premarket and postmarket. The claim is bounded on purpose.

August 26, 2025 · 3 min read
ELTON

Context is the missing piece in medical device vulnerability management

The same CVE deserves different ratings on different devices. The difference is the path an attacker has to walk through yours.

August 26, 2025 · 3 min read
Compliance & Regulation

Understanding the FDA Secure Product Development Framework (SPDF)

The SPDF isn't a checklist. It's five practices spanning the lifecycle, and vulnerability testing and management are two of the pillars.

August 26, 2025 · 3 min read
Compliance & Regulation

Meeting Japan's medical device cybersecurity requirements

Japan adopted IEC 62304 and IEC 81001-5-1 as JIS T 2304 and JIS T 81001-5-1. One process, one evidence trail, and it travels.

August 26, 2025 · 3 min read
Quality System SOPs

Example SOP: Cybersecurity risk assessment

A working risk assessment SOP: score exploitability with CVSS, pull harm from ISO 14971, mitigate, rescore, and defend the residual.

August 26, 2025 · 6 min read
Quality System SOPs

Example SOP: Medical device cybersecurity

One SOP to govern the lifecycle: planning, threat modeling, SBOM, testing, traceability, and postmarket vulnerability response.

August 26, 2025 · 5 min read
Quality System SOPs

Example SOP: Postmarket vulnerability management

Monitor, assess, respond, patch, re-test. A postmarket vulnerability SOP with the clocks FDA expects you to commit to.

August 26, 2025 · 4 min read
Quality System SOPs

Example SOP: Vulnerability metrics tracking

Four numbers prove your program runs: total vulnerabilities, percent patched, time to patch release, and time to install.

August 26, 2025 · 3 min read
Vulnerability Research

Function-level reachability sounds great, but falls short in practice

Dynamic dispatch, IPC, and closed binaries break static certainty. A not reachable verdict without runtime proof is a claim, not evidence.

August 4, 2025 · 3 min read
Vulnerability Research

Path-based vulnerability analysis reflects the real-world threat model for medical devices

Attackers don't read your source. They probe what's exposed. Path-based analysis asks the same question they do: can I get there?

August 4, 2025 · 3 min read
Compliance & Regulation

The FDA's 2025 cybersecurity guidance update: what changed and what didn't

1,300 redlines, few new obligations. The 2025 revision clarifies scope, SBOM format, and risk modeling. What changed was the ambiguity.

July 30, 2025 · 3 min read
Compliance & Regulation

Meeting FDA vulnerability metrics with ELTON

Your Vulnerability Management Plan named seven metrics. The FDA reads it as a contract. Manual collection dies within two release cycles.

July 30, 2025 · 3 min read
ELTON

Understanding is predictability: a better model for vulnerability management

The question is no longer whether you know every vulnerability. It is whether you already know how a new one would be rated, and can justify why.

July 22, 2025 · 3 min read
Compliance & Regulation

Meeting FDA cybersecurity guidance for AI-enabled device software

The FDA names seven AI-specific threats. Only one lives at runtime. Most programs test one-seventh of what is being asked.

April 30, 2025 · 3 min read
ELTON

Why every product release is its own cybersecurity lifecycle

The same CVE in three releases can carry three different ratings, and all three are correct.

December 12, 2024 · 3 min read
Compliance & Regulation

When does a vulnerability require patching?

Interpreting the FDA's 2016 postmarket guidance: most SBOM findings do not require a patch, if you can evidence why.

October 8, 2024 · 3 min read
Compliance & Regulation

Why manufacturers must validate their cybersecurity tools

If a tool produces evidence for an FDA submission, it lives inside your quality system, and the FDA can ask whether it was validated.

August 27, 2024 · 3 min read
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo