Why ELTON · FDA-Qualified MDDT

A rating methodology the FDA has already qualified.

Every CVSS argument in a review cycle has the same weak spot: the score is somebody’s opinion. ELTON rates with the MITRE Rubric for Applying CVSS to Medical Devices, qualified under FDA’s MDDT program as Q171974. The methodology walked into review long before your submission did.

What qualification means

Under the MDDT program, FDA evaluates a tool for a stated context of use and agrees its output can be relied on within that scope. Reviewers can accept rubric-based ratings without re-arguing the method itself.

The MDDT program

Qualification is FDA’s word, not ours.

The Medical Device Development Tools program exists so industry does not have to re-argue methods inside every submission. A sponsor proposes a tool, FDA evaluates it against a specific context of use, and qualification means data produced by that tool is accepted within that scope.

The MITRE Rubric for Applying CVSS to Medical Devices went through that process and holds qualification Q171974. It adapts CVSS to clinical reality: how the device is deployed, what an attacker can actually reach, and what a compromise means for the patient on the other end of it.

One thing we will not do is inflate that. Qualification covers the rating methodology, not the ELTON platform as a whole. FDA has not endorsed our product, and no vendor can honestly claim that kind of blanket blessing. What you get is narrower and more useful: every score ELTON produces rests on a method FDA has already reviewed for exactly this job.

Rubric over opinion

Ten analysts, ten scores. One rubric, one answer.

Hand the same CVE to ten experienced people and you get ten ratings, each defensible in the room and none defensible on paper. A rubric replaces taste with rules.

Rules-based

The rubric asks concrete decision questions about vector, access, interaction, and clinical impact. The score falls out of the answers, not out of seniority.

Traceable

Every answer is recorded. When a reviewer asks why the score is a 5.9, the response is the decision trail, not a shrug and a resume.

Repeatable

The same finding rated next quarter, or by a different analyst, lands on the same number. Consistency is what makes a rating program auditable.

At scale, in context

ELTON runs the rubric on every finding, with the twin as witness.

Applying a rubric to one CVE is easy. Every finding, every release, reasoning written down, is where humans run out of hours. ELTON runs the full backlog, rationale attached: which questions were asked, what the twin says, what evidence supports each answer.

One CVE through the qualified rubric NVD generic score 9.8 MDDT RUBRIC · Q171974 Is the vulnerable service reachable?No Attack vector in deployment?Adjacent Privileges and interaction required?High / Yes Clinical impact if compromised?Limited each answer sourced from the digital twin, each answer recorded Device-contextual score 5.9 rationale trail attached defensible in review: questions, answers, evidence for every single rating
The score that leaves is not the score that entered, and the difference is documented.

Context moves the number. A generic 9.8 assumes network reachability and no controls. When the digital twin shows the path is blocked, the score drops, rationale on the record. A defensible re-rating, not a quiet downgrade, and it feeds straight into finding the 1%.

Scoring is not standing still either. CVSSv4 changes the math and the vocabulary, and we are building that path now. See CVSSv4 migration, and how ratings connect to executed evidence in Proof Over Probability.

How ratings are made

From submission evidence to a defensible score, in six moves.

Every CVSS 4.0 decision is computed from the device’s documented architecture. Same inputs, same score, every run. This is the full path a rating takes, and every stop on it is traceable.

01

Ingest the submission evidence

ELTON starts from documentation you already produce for FDA review: architecture views and data flow diagrams, SBOM, threat model, risk management report, security controls, and cybersecurity testing reports. No new paperwork, no questionnaires.

Architecture viewsDFDsSBOMThreat modelRisk mgmt reportSecurity controlsPentest reports
02

Build the property graph, the digital twin

The documentation becomes a machine-readable graph. Components become nodes carrying trust level, assets with CIA sensitivity, countermeasures, and deployment configurability. Data flows become directed edges typed Network, Adjacent, Local, or Physical. Every element is tagged to the document it came from, and every manual edit is logged.

Trust zonesAssets + CIACountermeasuresInterface typesSource tagsEdit log
03

Bind the vulnerability to a component

Each finding attaches to the exact component it lives on, whether it arrives from a pentest report, an SBOM scan, the public CVE feed, or a user entry. The vulnerability carries SSVC context and an on-component exposure indicator before any path analysis begins. The unit of analysis is always one vulnerability on one component in one device design.

Pentest findingSBOM scanCVE feedUser-addedSSVCExposure indicator
04

Trace attack paths from every entry point

For each initial access point in the threat model (Wi-Fi, Bluetooth, USB, the user interface, a debug port), ELTON derives the feasible paths an attacker can take to reach the component and the propagation paths after compromise. Traversal respects trust boundaries and directionality, so infeasible paths never inflate a score. Each entry point is scored as its own scenario.

Wi-FiBluetoothUSBUIDebug portPre-compromise corridorPost-compromise spread
05

Apply deterministic CVSS 4.0 rules

Each metric is computed by rules that extend the FDA-qualified rubric (Q171974) to v4.0. Exploitability metrics read the entry interface, trust levels traversed, countermeasures, configurability, and user interaction. Impact metrics read asset sensitivity on the vulnerable component and everything downstream. If no feasible path exists, the scenario is marked non-exploitable. No questionnaires, no judgment calls.

AVACATPRUIVC / VI / VASC / SI / SA
06

Emit the score with its evidence

Every entry point gets a complete vector, score, and metric-level justification naming the components, interfaces, trust levels, and assets that drove it, cited back to your submission documents. The canonical score is the highest-severity feasible scenario; the others are retained as context. Change the architecture and the score changes with it. Nothing else moves it.

Vector per entry pointCanonical scoreMetric citationsDoc referencesAudit trail
Get started

Score with the method FDA reviewed.

Pick your ugliest CVE. We will re-rate it through the qualified rubric against your device twin and show you the decision trail a reviewer would read.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo