Product Security Hub Logo
Back to Resources
Checklist 10 min read

Product Security Readiness Checklist

Before launching a connected or regulated medical device, ensure you've addressed these key security elements. This checklist helps you verify that your product security documentation is complete and ready for FDA submissions, audits, and market release.

This Checklist Covers

Threat Modeling Risk Assessment SBOM Requirements Vulnerability Management Submission Documentation Post-Market Planning

Why Product Security Readiness Matters

The FDA's Premarket Cybersecurity Guidance requires manufacturers to demonstrate that cybersecurity has been addressed throughout the product lifecycle. Reviewers expect to see threat models, risk assessments, SBOMs, and plans for managing vulnerabilities post-market. Having these elements documented and traceable isn't just about compliance—it's about demonstrating that security is built into your product, not bolted on.

1

Architecture & Threat Modeling

Document your product's architecture and systematically identify potential security threats.

In Product Security Hub: Use the Architecture view to create diagrams, the Components tab to define component types, and the Threats tab to apply threats from the built-in catalog.

2

Security Requirements

Define what security controls your product must implement and document how they're addressed.

In Product Security Hub: The Requirements tab auto-generates requirements based on your components. Use AI Generate to draft "How Will This Be Met" descriptions.

3

Risk Assessment

Evaluate and document residual cybersecurity risks after security controls are applied.

In Product Security Hub: The Risks tab provides CVSS scoring with AI-assisted justification generation. Use "PM Scoring" for your product-specific assessment.

4

Software Bill of Materials (SBOM)

Maintain a complete inventory of software components with the details required by FDA.

In Product Security Hub: Import CycloneDX SBOMs via the SBOMs tab, or create components manually. Export in CycloneDX JSON or human-readable Excel.

5

Vulnerability Management

Scan for known vulnerabilities and document your assessment and response for each.

In Product Security Hub: The Vulnerabilities tab shows scan results with severity filtering. Use KEV Check to flag actively exploited CVEs. Document analysis in Vulnerability Details.

6

Documentation for Submission

Prepare the evidence package for FDA premarket submissions and customer security reviews.

In Product Security Hub: Export from My Product Dashboard (Excel/JSON with 7 tabs) or use SBOM-specific exports. Architecture diagrams export via draw.io.

7

Post-Market Planning

Establish processes for ongoing security monitoring and incident response after launch.

In Product Security Hub: Use product versioning to maintain separate security documentation for each release. Nightly KEV checks help identify newly exploited vulnerabilities.

Quick Reference: FDA Cybersecurity Submission Elements

Based on the FDA's Premarket Cybersecurity Guidance, your submission should demonstrate:

Security risk management process
Threat modeling methodology
Cybersecurity risk assessment
Security controls and mitigations
Software bill of materials (SBOM)
Vulnerability analysis and management
Post-market cybersecurity plan
Interoperability and update mechanisms

Ready to check off your list?

Product Security Hub helps you build, document, and maintain all the security artifacts you need for FDA submissions and customer security reviews.