Group 682 (1)

Conference Exclusive - EUR 13K-33K - 3 Fixed-Price Tiers

Cybersecurity Baseline Assessment

 Know your attack surface. Prove it to regulators.

Fixed price. 3–8 weeks. FDA & MDR aligned.

FDA's 2023 Cybersecurity Guidance and MDCG 2019-16 now require structured, documented security evidence for every connected medical device. Most companies don't know what they're missing until a regulator, procurement team, or notified body asks — and they can't deliver.



Security risks we identify & remediate:

  • No SBOM — unknown vulnerable components inside your device
  • Missing threat model — no documented attack surface analysis
  • Unpatched CVEs — live vulnerabilities with no monitoring process
  • Regulatory gap — cybersecurity evidence not submission-ready
Cybersecurity baseline assesment

Class A - Low Risk SaMD

EUR 13,000/ Standard Fee

EUR 10,400 excl. VAT

  • Conference Special Price (-20%)

Class B - Medium Risk SaMD

EUR 21,000/Standard Fee

EUR 16,800 excl. VAT

  • Conference Special Price (-20%)

Class C - High Risk SaMD

EUR 33,000/Standard Fee

EUR 26,400 excl. VAT

  • Conference Special Price (-20%)
The security risks your ogranisation faces right now

No SBOM — no visibility into what is inside your device

Without a Software Bill of Materials you cannot answer the question regulators and procurement teams now ask first: what components are in your device, and are any of them vulnerable? FDA 2023 and MDCG 2019-16 both require an SBOM maintained over the full product lifecycle.

No threat model — no documented attack surface analysis

STRIDE and MITRE ATT&CK-based threat modelling are expected by FDA, notified bodies, and enterprise procurement teams. Without a formal threat model, your security posture is undocumented and cannot be presented as regulatory submission evidence.

Unmonitored CVEs are a live, compounding liability

New vulnerabilities in open-source and third-party components are disclosed every day. Without a CVE monitoring programme tied to your SBOM, you cannot detect when a shipped component becomes exploitable or demonstrate a documented post-market response process.

Cybersecurity evidence is not submission-ready — auditors know it

FDA's 2023 Guidance requires a Cybersecurity Management Plan in every 510(k) and PMA. MDR requires equivalent evidence for connected devices. Ad-hoc pen test screenshots and informal security notes are not a substitute — reviewers know the difference.

What every engagement delivers

STRIDE Threat Model Report

Structured threat model using STRIDE and MITRE ATT&CK for ICS/healthcare. Covers your full attack surface, threat actors, entry points, and control gaps. Formatted for direct inclusion in FDA 510(k)/PMA and MDR technical files.

SBOM Creation (SPDX / CycloneDX)

Machine-readable Software Bill of Materials listing all third-party and open-source components with version and licence data. Aligned with FDA's 2023 requirement to submit an SBOM with every new medical device application.

CVE Monitoring Programme Setup

Automated CVE monitoring pipeline tied to your SBOM — tooling, alert thresholds, and a documented response workflow. Enables ongoing post-market cybersecurity vigilance you can demonstrate to FDA and notified bodies.

Remediation Priority Roadmap

Risk-ranked security findings with CVSS-based exploitability scores, remediation actions, effort estimates, and a sequenced 90-day action plan to reach a fully defensible, regulator-ready security baseline.

Conference pricing ends 30 days after the event. Lock in your assessment.

Fixed-price tiers by software class

Class A Low Risk SaMD

EUR 13,000 / Standard Fee

EUR 10,400Conference -20%

Included Scope & Delivarables

  • FDA / MDCG Compliance Gap Report
  • Full STRIDE Threat Modelling Matrix
  • Automated SBOM Generation & Setup (SPDX / CycloneDX)
  • Initial Vulnerability Scan & CVE triage

CLASS B Medium Risk SaMD

EUR 21,000 / Standard Fee

EUR 16,800Conference -20%

Included Scope & Deliverables

  • All Class A deliverables, plus:
  • STRIDE threat mapping to existing software architecture
  • Formal vulnerability management process drafting
  • Security test case generation

CLASS C High Risk SaMD

EUR 33,000 / Standard Fee

EUR 26,400Conference -20%

Included Scope & Deliverables

  • All Class B deliverables, plus:
  • Advanced threat modelling of complex cloud / device boundaries
  • SAST / DAST toolchain integration
  • Formal Post-Market Vulnerability Management Plan

Our Partners

Trusted by industry leaders
Smartqare_logo-BW

''Thaumatec was the only company that fulfilled the requirement of in-depth know-how of embedded software development and the proper QMS according to ISO13485 and IEC62304.''

Co-founder, SmartQare
LOGO_Propeaq_Blue

 

''Thanks to the HealthTech Innovation accelerator, I am able to scale my product, by making it a smart device, and address new use cases - like improving the biorhythm of people with Parkinson’s disease.''

Founder & CEO Chrono Eyewear

Engagement details

Typical timeline

Week 1  Kick-off, asset inventory, architecture review
 
Week 2  STRIDE threat modelling, SBOM generation
 
Week 3  CVE scan, vulnerability triage, monitoring setup
 
Week 4  Findings report and roadmap delivered
Class B: 5–6 wks  ·  Class C: 7–8 wks

Who this is for

→ Connected medical devices — FDA 510(k) or PMA→ SaMD / SiMD with MDR or IVDR obligations
→ CISOs preparing for procurement security audits
→ Companies with no existing threat model or SBOM
→ FDA pre-Sub meeting preparation

Conference terms & contact

All prices are fixed fees excluding VAT. Conference pricing valid when contract is signed within 30 days of event date.


Every engagement includes:
60-min discovery call  ·  Written scope  ·  Senior QA/RA review

office@thaumatec.com

www.thaumatec.com
ISO 27001  ·  ISO 13485  ·  FDA 2023  ·  MDCG 2019-16