Services / Medical device & SaMD

Medical-device & SaMD web application test

For software as a medical device and connected-device portals: a full application and API test, documented so the results drop straight into your cybersecurity file.

What's included

  • Everything in the web application & API test
  • Test plan and test specification written before testing, so the work is traceable
  • Findings mapped to your security risk management (ISO 14971-aligned) and threat model
  • Evidence structured for FDA premarket cybersecurity documentation and EU MDR Annex I security requirements
  • Commentary on residual risk in language a reviewer or auditor expects
  • One retest of fixed findings, included

Scope

  • The web application, its APIs and its administrative interfaces
  • Device-adjacent interfaces in scope where they are reachable over the web
  • Mapping of findings to your security risk management file

Who it's for

  • SaMD and connected-device manufacturers preparing an FDA submission
  • Manufacturers answering notified-body or auditor questions on security testing
  • Device companies whose hospital customers require independent testing

What you get

  • Test plan and test specification (pre-test)
  • Technical report with traceable test cases and evidence
  • Summary suitable for inclusion in a submission or technical file
  • Retest letter confirming what has been fixed

Report delivered within 5 working days of testing ending. One retest of fixed findings included, within 60 days.

deliverables/ What lands in your inbox
report/
  technical-report.pdf      findings, evidence, fixes
  management-summary.pdf    for the board or a customer
  findings.csv              straight into your tracker
retest/
  retest-letter.pdf         after you've fixed things

How the engagement runs

01

Scope

A short call about the application, its roles and what would hurt most if it broke. You get a fixed-price proposal and dates.

02

Authorise

Rules of engagement, authorisation and an NDA if you want one. Testing starts only once these are signed.

03

Map

Reconnaissance and mapping: every route, role, parameter and API call that makes up the attack surface.

04

Test

Manual testing against the OWASP guides, supported by tooling. Critical findings are reported the moment they are confirmed, not held for the report.

05

Report

Findings with evidence, reproduction steps, CVSS ratings and fix guidance written for developers, plus a summary for everyone else.

06

Retest

Once you have fixed things, a retest confirms it, and you get a letter you can show customers or auditors.

Questions

Does this guarantee our submission will be accepted?

No, and be wary of anyone who says it will. What it gives you is independent test evidence, structured and traceable, that supports the security documentation a submission or technical file needs.

Can you work alongside our regulatory consultant?

Yes. The report is written so a regulatory reviewer can use it directly. MD QMS Ltd. also does regulatory and cybersecurity documentation work if you need the wider file built.

request a scope

Get a fixed price for your application

A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.

Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days