Buy the GCP R3 course & get a FREE eBook— your complete ICH-GCP R3 reference guide. Book Now →

  • Preclinical & Laboratory Foundations Learning Path
  • Phase I – First-in-Human Trials Learning Path
  • Phase II & III – Efficacy & Pivotal Trials Learning Path
  • Clinical Trials Foundation PathNew
  • Regulatory Submission & Approval

About

Medical device cybersecurity is a critical component of product safety, effectiveness, and regulatory compliance. As connected medical devices become increasingly integrated into healthcare systems, manufacturers must proactively identify, assess, and mitigate cybersecurity risks throughout the product lifecycle. Regulatory authorities, including the US FDA and the European Union, require manufacturers to incorporate cybersecurity into product design, development, regulatory submissions, and postmarket activities to ensure the continued safety and performance of medical devices.
This Medical Device Cybersecurity (Premarket and Postmarket, FDA and EU) Training Course & Certification provides comprehensive knowledge of cybersecurity fundamentals, threat landscapes, security-by-design principles, cybersecurity risk management, threat modelling, secure product development, software bill of materials (SBOM), vulnerability management, FDA Section 524B requirements, EU MDR cybersecurity expectations, premarket documentation, verification and validation, postmarket surveillance, coordinated vulnerability disclosure, security patch management, incident response, and lifecycle cybersecurity governance. Upon successful completion, learners receive a certification demonstrating their understanding of medical device cybersecurity requirements and industry best practices for FDA and EU regulatory compliance.

Who Should Enrol?

  • Medical Device Software Engineers and Cybersecurity Professionals
  • Quality Assurance and Quality Management Professionals
  • Regulatory Affairs and Compliance Professionals
  • Risk Management and Product Security Specialists
  • Software Verification, Validation, and Test Engineers
  • Medical Device Product Managers and Development Teams
  • IT Security, Digital Health, and Connected Device Professionals
  • Anyone involved in the design, development, regulation, maintenance, or cybersecurity of medical devices
📢 Every purchase also includes our FREE companion Medical Device Cybersecurity (Premarket and Postmarket, FDA and EU) eBook, designed to help you apply principles in real-world inspection readiness settings.

What you will learn

Understand the principles of medical device cybersecurity, evolving cyber threats, regulatory expectations, and security-by-design concepts throughout the medical device lifecycle.

Learn how to implement cybersecurity risk management, threat modelling, secure software development, vulnerability assessment, SBOM management, and cybersecurity verification activities.

Develop knowledge of FDA and EU cybersecurity requirements, premarket submission expectations, postmarket surveillance, coordinated vulnerability disclosure, and security update management.

Gain practical understanding of cybersecurity governance, documentation, incident response, regulatory compliance, and best practices for maintaining secure and resilient medical devices throughout their lifecycle.

Course Syllabus

  1. The connected-device reality
  2. The CIA triad — applied to devices
  3. Core vocabulary
  4. Who attacks medical devices, and why
  5. The connected-device attack surface
  6. Classes of harm from a device compromise
  7. Real-world lessons (illustrative)
  8. Security by design — the core mindset
  9. Defence in depth and security by default
  10. Shared responsibility across the ecosystem

  1. US legal architecture
  2. Section 524B(c) — is your device a 'cyber device'?
  3. Section 524B(b) — the four requirements in detail
  4. How the 2025 premarket guidance expects you to comply
  5. FDA security architecture views
  6. The security risk management report (FDA)
  7. EU MDR — where cybersecurity lives
  8. MDCG 2019-16 Rev.1 — the EU cybersecurity guidance
  9. Adjacent EU regimes you must track
  10. FDA postmarket management guidance
  11. International harmonisation — IMDRF
  12. Cardavia across two markets

  1. What the SPDF is
  2. IEC 81001-5-1:2021 — the security lifecycle standard
  3. SPDF lifecycle activities at a glance
  4. Security requirements — deriving them properly
  5. Security by design in the architecture
  6. Secure coding and build integrity
  7. Design review and security gates
  8. Competence, culture and roles
  9. Cardavia builds its SPDF

  1. Security risk vs safety risk — revisited
  2. ANSI/AAMI SW96:2023 — what it gives you
  3. Threat modeling — the core technique
  4. STRIDE — a threat taxonomy
  5. Assessing security risk — exploitability and impact
  6. CVSS — useful, but handle with care
  7. Selecting and verifying mitigations
  8. The threat model as a living artifact
  9. Cardavia's threat model in action

  1. What an SBOM is
  2. Minimum elements of an SBOM
  3. SPDX vs CycloneDX
  4. Generating and maintaining the SBOM
  5. Third-party components — SOUP / OTS
  6. Component support and end-of-life
  7. Continuous vulnerability monitoring
  8. Cardavia manages its components

  1. Security architecture views (FDA)
  2. Trust boundaries and segmentation
  3. Core security control families
  4. Designing for updateability
  5. Security testing — the toolbox
  6. Planning and scoping security testing
  7. Interpreting results and residual anomalies
  8. Cardavia architects and tests its controls

  1. The FDA premarket cybersecurity package
  2. Structuring the security risk management report
  3. Cybersecurity labeling — telling operators what to do
  4. Customer security documentation
  5. Mapping to EU MDR technical documentation
  6. Common submission deficiencies to avoid
  7. Cardavia assembles its submission

  1. The postmarket programme — NIST CSF frame
  2. Coordinated vulnerability disclosure (CVD)
  3. Vulnerability intake and triage
  4. Controlled vs uncontrolled risk
  5. Patching and updates in the field
  6. Incident response
  7. Reporting and information sharing
  8. Legacy devices and end of support
  9. Cardavia runs its postmarket programme

  1. 📘 Bonus:Medical Device Cybersecurity (Premarket and Postmarket, FDA and EU) eBook (Free with purchase)

Our Certified Customers

novartis
NHS
takeda
roche
baxter

Learner Rating & Reviews

4.7
Average Rating
536 global ratings
87.0%
5.0%
3.0%
3.0%
2.0%
RC

Working with Whitehall training for the last two years of partnership has been a very successful experience – I have fast access to all the GCP course...

SM

I have finalised the demo for the ICH-GCP E6 R3 refresher course. Overall, I liked the content and the interface. I also want to thank Whitehall Train...