Penetration Testing
Hands-on adversarial testing in which qualified independent testers attempt to exploit a device's security controls.
Definition
Penetration testing (pen testing) is hands-on adversarial security testing in which qualified, sufficiently independent testers attempt to exploit a medical device's security controls - network services, web/API interfaces, wireless protocols, physical interfaces (USB, JTAG, UART), companion apps, and back-end cloud - to uncover weaknesses that automated scanners miss. A pen test produces an evidence package: methodology, findings (with reproduction steps), severity ratings, and remediation recommendations.What this means in practice
Pen testing is most valuable when scoped against a current threat model and run before V&V freeze so findings can be designed-out rather than risk-accepted. Mature MedTech teams budget for an annual external pen test plus targeted retests after major changes. Findings flow into CAPA and re-test verification.- •Hiring a generic pen-test firm with no medical-device experience - they'll miss the device-specific attack surface.
- •Scoping the test too narrowly (only the web UI) and missing the wireless, hardware, or backend channels.
- •Treating the pen-test report as a one-time deliverable instead of feeding remediation into CAPA and re-test.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
Automated security testing - SAST analyzes source code at rest, DAST exercises a running application.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
More in Cybersecurity
· Same categoryA documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Where this term appears across MedTech Terms.
Mentioned in recent activity
1 entryLatest in MedTech
Recent regulatory actions, publications, and trials matched to this term. Updated daily.
-
510(k)2026-06-05Fastep COVID-19 Antigen Pen Home Test; Fastep COVID-19 Antigen Pen Test
Assure Tech., LLC
Primary references
3 sources- 1
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 2
NIST SP 800-115 Technical Guide to Information Security TestingVerifiedNISTcsrc.nist.gov
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.