Library

FDA Cybersecurity SOPs & Templates.

Browse every document and download the raw DOCX or XLSX. Proven across 1,000+ cybersecurity submissions.

Questions

Common questions about the SOP and template library.

Which document should I start with?

Start with the Medical Device Cybersecurity SOP. It is the master document, the full lifecycle process from planning through postmarket, phase by phase, and every other document in the library hangs off it. It runs 36 sections and 266 paragraphs of process language.

What is in the Cybersecurity Risk Assessment SOP?

The Cybersecurity Risk Assessment SOP is the scoring methodology document. It covers threat identification and severity of harm, inherent and residual exploitability scoring, mitigations and completeness of risk control, then benefit-risk analysis and overall residual risk evaluation. Two appendices hold the CVSS exploitability versus severity of harm mapping and the calculations table.

What is in the threat modeling SOP?

The Threat Modeling and Architectural Views SOP builds the model from a system level architectural view and diagram, then architecture decomposition, users, data flows and asset allocation. It adds cybersecurity use cases, an updatability and patchability view, a multi-patient harm view, and STRIDE per element threat analysis.

Is there a workbook for tracking SBOM end of support?

The SBOM End-of-Support and Level-of-Support workbook is an XLSX with columns for component, level of support, end of support, and justification. Justification is the column reviewers ask about when a component sits past its date. It is built for direct attachment to the SBOM Report.

What is in the cybersecurity risk assessments workbook?

The risk assessments workbook holds five assessment sheets: threat model, vulnerabilities, cybersecurity testing, secure code analysis, and unresolved anomalies. Around them sit architecture decomposition, asset descriptions and mapping, hazardous situations, mitigations, the risk acceptance table, and the lookup tables that keep scoring consistent. Twelve sheets in total.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationFind the 1%Remediation OptimizationELTON TestLink™SBOM, VEX & ReportingCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI PentestingFDA-Compliant RatingsVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo