Product Security Readiness Checklist
Before launching a connected or regulated medical device, ensure you've addressed these key security elements. This checklist helps you verify that your product security documentation is complete and ready for FDA submissions, audits, and market release.
This Checklist Covers
Why Product Security Readiness Matters
The FDA's Premarket Cybersecurity Guidance requires manufacturers to demonstrate that cybersecurity has been addressed throughout the product lifecycle. Reviewers expect to see threat models, risk assessments, SBOMs, and plans for managing vulnerabilities post-market. Having these elements documented and traceable isn't just about compliance—it's about demonstrating that security is built into your product, not bolted on.
Architecture & Threat Modeling
Document your product's architecture and systematically identify potential security threats.
In Product Security Hub: Use the Architecture view to create diagrams, the Components tab to define component types, and the Threats tab to apply threats from the built-in catalog.
Security Requirements
Define what security controls your product must implement and document how they're addressed.
In Product Security Hub: The Requirements tab auto-generates requirements based on your components. Use AI Generate to draft "How Will This Be Met" descriptions.
Risk Assessment
Evaluate and document residual cybersecurity risks after security controls are applied.
In Product Security Hub: The Risks tab provides CVSS scoring with AI-assisted justification generation. Use "PM Scoring" for your product-specific assessment.
Software Bill of Materials (SBOM)
Maintain a complete inventory of software components with the details required by FDA.
In Product Security Hub: Import CycloneDX SBOMs via the SBOMs tab, or create components manually. Export in CycloneDX JSON or human-readable Excel.
Vulnerability Management
Scan for known vulnerabilities and document your assessment and response for each.
In Product Security Hub: The Vulnerabilities tab shows scan results with severity filtering. Use KEV Check to flag actively exploited CVEs. Document analysis in Vulnerability Details.
Documentation for Submission
Prepare the evidence package for FDA premarket submissions and customer security reviews.
In Product Security Hub: Export from My Product Dashboard (Excel/JSON with 7 tabs) or use SBOM-specific exports. Architecture diagrams export via draw.io.
Post-Market Planning
Establish processes for ongoing security monitoring and incident response after launch.
In Product Security Hub: Use product versioning to maintain separate security documentation for each release. Nightly KEV checks help identify newly exploited vulnerabilities.
Quick Reference: FDA Cybersecurity Submission Elements
Based on the FDA's Premarket Cybersecurity Guidance, your submission should demonstrate:
Ready to check off your list?
Product Security Hub helps you build, document, and maintain all the security artifacts you need for FDA submissions and customer security reviews.