Class A - Low Risk SaMD
EUR 10,400 excl. VAT
- Conference Special Price (-20%)
.png)
Conference Exclusive - EUR 13K-33K - 3 Fixed-Price Tiers
Know your attack surface. Prove it to regulators.
Fixed price. 3–8 weeks. FDA & MDR aligned.
FDA's 2023 Cybersecurity Guidance and MDCG 2019-16 now require structured, documented security evidence for every connected medical device. Most companies don't know what they're missing until a regulator, procurement team, or notified body asks — and they can't deliver.
STRIDE and MITRE ATT&CK-based threat modelling are expected by FDA, notified bodies, and enterprise procurement teams. Without a formal threat model, your security posture is undocumented and cannot be presented as regulatory submission evidence.
New vulnerabilities in open-source and third-party components are disclosed every day. Without a CVE monitoring programme tied to your SBOM, you cannot detect when a shipped component becomes exploitable or demonstrate a documented post-market response process.
FDA's 2023 Guidance requires a Cybersecurity Management Plan in every 510(k) and PMA. MDR requires equivalent evidence for connected devices. Ad-hoc pen test screenshots and informal security notes are not a substitute — reviewers know the difference.
Structured threat model using STRIDE and MITRE ATT&CK for ICS/healthcare. Covers your full attack surface, threat actors, entry points, and control gaps. Formatted for direct inclusion in FDA 510(k)/PMA and MDR technical files.
Machine-readable Software Bill of Materials listing all third-party and open-source components with version and licence data. Aligned with FDA's 2023 requirement to submit an SBOM with every new medical device application.
Automated CVE monitoring pipeline tied to your SBOM — tooling, alert thresholds, and a documented response workflow. Enables ongoing post-market cybersecurity vigilance you can demonstrate to FDA and notified bodies.
Risk-ranked security findings with CVSS-based exploitability scores, remediation actions, effort estimates, and a sequenced 90-day action plan to reach a fully defensible, regulator-ready security baseline.
EUR 13,000 / Standard Fee
EUR 21,000 / Standard Fee
EUR 33,000 / Standard Fee
Our Partners

''Thaumatec was the only company that fulfilled the requirement of in-depth know-how of embedded software development and the proper QMS according to ISO13485 and IEC62304.''
Co-founder, SmartQare
''Thanks to the HealthTech Innovation accelerator, I am able to scale my product, by making it a smart device, and address new use cases - like improving the biorhythm of people with Parkinson’s disease.''
Founder & CEO Chrono Eyewear
→ Connected medical devices — FDA 510(k) or PMA→ SaMD / SiMD with MDR or IVDR obligations
→ CISOs preparing for procurement security audits
→ Companies with no existing threat model or SBOM
→ FDA pre-Sub meeting preparation
All prices are fixed fees excluding VAT. Conference pricing valid when contract is signed within 30 days of event date.
Every engagement includes:
60-min discovery call · Written scope · Senior QA/RA review
office@thaumatec.com
www.thaumatec.com
ISO 27001 · ISO 13485 · FDA 2023 · MDCG 2019-16