DIY Cybersecurity Regulatory Kit
Required. Affordable. Easy to use.
DIY Cybersecurity Regulatory Kit for Medical Device Submissions
These cybersecurity processes should be implemented during product development so that the required evidence and documentation are generated as your device is developed, not created when you are preparing your submission.
Our DIY Cybersecurity Regulatory Kit provides practical resources to help you implement these processes and prepare the supporting cybersecurity artifacts required for your FDA eSTAR submission. The kit combines FDA eSTAR aligned cybersecurity templates, comprehensive training, and expert guidance to help your team understand what FDA expects and put those requirements into practice.
Following FDA cybersecurity guidance involves more than demonstrating that security controls exist. You need a structured process for identifying, evaluating, addressing, testing, documenting, and managing cybersecurity risks throughout the full device lifecycle. Our kit is designed to help you approach that process with greater structure and a clearer understanding of both the cybersecurity activities you need to perform and the evidence you need to produce for regulatory submission.
Save over $150k and 12 months in FDA preparation.
What's included in our DIY Cybersecurity Regulatory Kit?
SOAR® Training
Monthly Q&A Sessions
Full DHF Templates
Peace of Mind
What Cybersecurity Information Does FDA Expect?
Depending on your device and its risks, activities may cover secure product development, threat modeling, cybersecurity architecture, risk assessments, security testing, vulnerability management, software components, and plans for addressing vulnerabilities after the device reaches the market.
If you are preparing an eSTAR submission, understanding the FDA eSTAR cybersecurity requirements early can help you identify relevant cybersecurity controls, testing, and associated documentation and supporting information before submission. eSTAR requires applicable cybersecurity information and supporting artifacts, so waiting until submission preparation to address cybersecurity can uncover gaps in activities or evidence that should have been generated during development and testing.
Teams can also underestimate when cybersecurity requirements may apply. Cybersecurity considerations are not limited to devices that are obviously wireless or continuously connected. Evaluating your device's software, connectivity, interfaces, and potential cybersecurity risks early helps your team understand the requirements that may apply before development is complete.
This makes cybersecurity preparation part of your development process rather than something your team must organize at the last minute. Waiting can impact your timeline by 6 months.
Turn Cybersecurity Expectations Into an Implementable Process
The combination of eSTAR aligned cybersecurity templates, comprehensive training, and expert guidance gives your team a structured framework for implementing cybersecurity requirements and developing the supporting SaMD cybersecurity documentation needed for regulatory submission.
For software driven SiMD and SaMD products, the kit can also help provide structure when implementing cybersecurity controls alongside your broader software development, design control, and risk management processes. Rather than determining what FDA expects at the end of development, your team can use the framework to build cybersecurity controls, activities, and evidence into the product lifecycle.
What Is Included in Our DIY Cybersecurity Regulatory Kit?
- Complete Cybersecurity Template & Artifact Kit: You receive access to 10 customizable cybersecurity templates designed around current FDA cybersecurity guidance, terminology, and eSTAR documentation expectations. The templates provide a structured framework for implementing key cybersecurity controls and activities and documenting the resulting evidence throughout development. Rather than determining from scratch what FDA expects, your team can work through the applicable processes and build the artifacts needed to support the cybersecurity section of your eSTAR submission.
- 12 Months of SOAR® Training Access: Our kit includes a 12 month subscription to SOAR® Training with a comprehensive 90 minute on-demand cybersecurity course covering key FDA guidance, standards, and regulatory expectations applicable to medical device cybersecurity. The training helps your team understand not only what documentation is expected, but the cybersecurity concepts and processes behind the templates so they can be implemented appropriately. Because the course is available on demand, you can revisit the material as you work through your cybersecurity activities and submission preparation.
- One Live Expert Q&A Session: Cybersecurity requirements can raise questions that are specific to your device and development process. The kit includes one live Q&A session with a cybersecurity industry expert, giving your team an opportunity to ask questions and gain additional clarity as you implement the cybersecurity process and prepare your submission artifacts.
Together, the templates, training, and expert guidance give your team a practical framework for moving from cybersecurity requirements to implementation, evidence, and submission readiness.
Key Standards & Guidance
- 21 Code of Federal Regulations – Part 11 Electronic Records; Electronic Signatures
- 21 Code of Federal Regulations – Part 820 Quality System Regulation for Medical Devices and In Vitro Diagnostic Products
- AAMI TIR45:2012 - Guidance on the Use of AGILE Practices in the Development of Medical Device Software
- AAMI/ISO 80002-2:2017 - Medical device software— Part 2: Validation of software for medical device quality systems
- AAMI/ISO TIR24971:2020 - Medical devices — Guidance on the application of ISO 14971
- ANSI/AAMI HE75:2009 (R2018) Human Factors Engineering - Design Of Medical Devices
- FDA Content of Premarket Submissions for Software Contained in Medical Devices
- FDA Design Controls Guidance for Medical Device Manufacturers
- FDA General Principles of Software Validation
- FDA Guidance Applying Human Factors and Usability Engineering to Medical Devices
- FDA Off-The-Shelf Software Use in Medical Devices
- IEC 60601-1 Medical electrical equipment
- IEC 62304 – Medical Device Software – Software Life Cycle Processes
- IEC 62366-1:2015 Medical Devices - Part 1: Application Of Usability Engineering To Medical Devices
- IEC 82304 – Health Software - Part 1: General requirements for product safety
- IEC/TR 80002-1:2009 - Medical device software – Part 1: Guidance on the application of ISO 14971 to medical device software
- IEC/TR 80002-3:2014 - Medical device software -- Part 3: Process reference model of medical device software life cycle processes (IEC 62304)
- IEEE 610.12-1990 - IEEE Standard Glossary of Software Engineering Terminology
- ISO 9001:2015 Quality management systems — Requirements
- ISO 13485:2016 Medical Devices – Quality Management Systems
- ISO 14971:2019 - Medical devices – Application of risk management to medical devices
- ISO/IEC/IEEE 29148-2018 - Systems and software engineering -- Life cycle processes -- Requirements engineering
- REGULATION (EU) 2017/745 – Medical Device Regulation
- REGULATION (EU) 2017/746 – In Vitro Diagnostic Regulation
Supporting FDA and EU Regulatory Preparation
Our Cybersecurity Regulatory Kit is designed around current FDA cybersecurity expectations and eSTAR requirements while also incorporating applicable cybersecurity standards and guidance used for European and international regulatory preparation. This gives teams a broader cybersecurity framework rather than developing an FDA only set of submission documents.
Our resources can support teams working through EU MDR cybersecurity compliance considerations as well as FDA preparation. The same underlying cybersecurity processes and evidence can support multiple regulatory markets, although the specific requirements and submission expectations may differ.
Your team should always identify the regulations, standards, cybersecurity controls, and documentation applicable to your specific device, intended use, risks, and target markets.
Build Cybersecurity Into Development and Prepare for Submission
A defined cybersecurity framework, including a cybersecurity management plan and a cybersecurity architecture document, can help your team implement the required cybersecurity controls and activities during development, identify what evidence needs to be generated, and organize the resulting artifacts for regulatory submission.
Rather than waiting until eSTAR preparation to determine what cybersecurity information FDA expects, your team can use the kit throughout development to address cybersecurity requirements and build the supporting evidence as the product is developed.
With 10 eSTAR aligned cybersecurity templates, a comprehensive 90 minute SOAR® cybersecurity training course, and one live expert Q&A session, Grassroots Dx provides practical tools and educational support to help you move from cybersecurity requirements to implementation and submission readiness.
Explore our DIY Cybersecurity Regulatory Kit and see how these resources can support your medical device development, cybersecurity process, and FDA eSTAR preparation.
Frequently asked questions
What does the FDA expect for medical device cybersecurity?
Current FDA cybersecurity guidance addresses cybersecurity across design, risk management, security testing, vulnerability management, and lifecycle activities. Cybersecurity should be considered during product development so that applicable requirements, controls, testing, and evidence are addressed as the device is developed and can support the regulatory submission. Applicable cyber devices must also meet Section 524B requirements.
What are the FDA eSTAR cybersecurity requirements?
What does the DIY Cybersecurity Regulatory Kit include?
The kit includes 10 customizable cybersecurity templates, a comprehensive 90 minute on-demand SOAR® cybersecurity training course, and one live expert Q&A session. The templates provide a structured framework for implementing cybersecurity activities and developing supporting evidence for regulatory submission.
Do FDA cybersecurity requirements apply if my medical device is not wireless?
Potentially. Cybersecurity considerations are not limited to devices that are obviously wireless or continuously connected. Teams should evaluate their device's software, connectivity, interfaces, and technological characteristics to determine which cybersecurity requirements apply. Evaluating this early in development can help prevent cybersecurity activities or evidence from being overlooked.
Is the kit suitable for SaMD cybersecurity documentation?
The kit is designed to help SiMD and SaMD teams implement cybersecurity processes and prepare supporting regulatory documentation. Teams should determine which SaMD cybersecurity documentation requirements apply to their particular software and submission.
Can the kit support European regulatory preparation?
Yes. The kit is designed to support FDA as well as European and international cybersecurity regulatory preparation. Manufacturers pursuing EU MDR cybersecurity compliance should still evaluate the requirements applicable to their specific device and target markets.
What is included with SOAR® Training?
What is the expert Q&A session for?
The kit includes one live Q&A session with a cybersecurity industry expert. The session gives teams an opportunity to ask questions and gain additional clarity as they implement their cybersecurity processes and prepare supporting submission artifacts.
