The FDA rejected or questioned a justification for an unfixed pentest finding
You could not produce test cases per interface (USB, Wi-Fi, Bluetooth)
No documented postmarket vulnerability management plan
Testing history did not cover all in-scope components
No recurring annual penetration testing in the postmarket plan
A fix or mitigation shipped without on-device proof