MDIC Releases Cybersecurity Best Practices for Medical Device Penetration Testing
New resource provides best practices for scoping, executing, and documenting penetration testing for medical devices
WASHINGTON, DC – The Medical Device Innovation Consortium (MDIC), a unique public-private partnership in which FDA, CMS, and NIH work alongside medical device stakeholders to accelerate patient access to innovative technologies, has published Validating Medical Device Cybersecurity Through Penetration Testing, a new resource that describes best practices for penetration testing of connected medical devices. This consensus document was developed in close collaboration with cybersecurity experts from the FDA’s Center for Devices and Radiological Health (CDRH) and security leaders from medical device manufacturers.
As medical devices become increasingly interconnected through cloud services, Bluetooth, hospital networks, and digital interfaces, the risk of cy

berattacks continues to grow. While federal law now requires manufacturers to address cybersecurity throughout the product lifecycle of a cyber device, the industry has lacked a consistent, widely accepted approach to penetration testing, leaving manufacturers to navigate a patchwork of vendor-specific methods with little common ground for evaluation and comparison.
This MDIC Penetration Testing resource addresses the gap directly. Written at a strategic, actionable level, the paper provides step-by-step documentation across the full penetration testing process. It covers scoping an assessment, selecting and managing qualified testing vendors, executing tests, evaluating and remediating findings, and communicating results to regulators and customers. The document will help manufacturers of all sizes build effective cybersecurity programs and avoid common pitfalls that leave devices vulnerable to preventable attacks or may delay regulatory submissions.
“This paper is exactly the kind of work MDIC was created to do. When regulators and industry sit at the same table and solve problems together, the result is something everyone can trust and put to use immediately,” said Andrew Fish, President and CEO of MDIC. “Connected devices transform patient care, but only if we can ensure they’re secure. This resource from MDIC gives manufacturers a clear, practical roadmap for penetration testing, filling a vacuum and setting a benchmark we hope the entire industry can organize around.”
“CDRH is committed to advancing cybersecurity across the medical device ecosystem. As devices become more complex and connected, collaboration between stakeholders is key to strengthening patient safety,” said Suzanne Schwartz, MD, MBA, Director of the Office of Strategic Partnerships and Technology Innovation at CDRH. “Resources like the penetration testing best practices document are one part of a broader security landscape, helping stakeholders to better understand and implement strong cybersecurity penetration testing that could ultimately support safer devices for patients.”
The publication arrives at a critical moment for the industry. Federal cybersecurity requirements for medical devices that have the ability to connect to the internet have been in effect for three years. Premarket submissions may be delayed or rejected because manufacturers have not adequately addressed cybersecurity in their design and development processes. At the same time, even well-resourced companies have experienced ransomware attacks and security breaches, underscoring the need for a more systematic approach. By establishing a consensus methodology, this MDIC publication will help raise the baseline for penetration testing practices across the sector and give manufacturers and testing vendors a shared reference point for cybersecurity validation.
Validating Medical Device Cybersecurity Through Penetration Testing is available for download at mdic.org. For more information on MDIC’s cybersecurity program and other initiatives, visit https://mdic.org/our-work/cybersecurity/.
—
About MDIC
The Medical Device Innovation Consortium (MDIC) is a public-private partnership that brings together FDA, CMS, and other agencies with medical device manufacturers, clinicians, and patients to advance the science behind device innovation, manufacturing, regulation, and coverage. Working across three core areas — Quality, Evidence, and Digital Health — MDIC develops research, toolkits, and actionable frameworks that help manufacturers navigate regulatory approval, maintain the highest quality standards, and build the evidence base payers need to make coverage decisions. MDIC demonstrates that when regulators, payers, patients, and industry solve problems together, innovation accelerates and patients benefit. For more information, visit mdic.org.
Disclaimer: FDA employees participated as members of MDIC’s Cybersecurity Working Group. The contents of this paper represent the views of the authors and do not necessarily represent the views of, and are not an endorsement by, the U.S. Food and Drug Administration (FDA)/Department of Health and Human Services (HHS) or the U.S. Government. The views, findings, and interpretations contained in this document do not constitute FDA guidance, position on this matter, or legally enforceable requirements.