Health & Pharma

Post-Market Cybersecurity for Medical Devices

Vulnerability scans for 20 product versions in six months

Three specialists in front of a screen with a lock symbol and security graphics
20product versions in six months

Project

Health & Pharma · Cyber & Compliance

  • Medical technology manufacturer for ophthalmology, software quality management
  • Cybersecurity monitoring for around 20 product versions in four device families
  • Post-market surveillance according to MDR and FDA, work according to the client’s software SOP
  • Project: 6 months
  • approx. €250,000
  • Fixed-scope contract, fixed price in three packages, monthly acceptance

Challenge

  • MDR and FDA require cybersecurity monitoring over the entire product lifecycle
  • Scans and monitoring documents for many existing products tie up internal software QM
  • Every piece of evidence must be documented and auditable per product and version

Solution

  • Vulnerability scans of the software components (Black Duck) and network interfaces (Nessus)
  • Evaluation of existing assessments, information bases and change logs
  • Drafting of the monitoring documents according to the client SOP, acceptance in the monthly status review

Result

  • 20 product versions accepted in three work packages
  • Evidence base for the post-market review according to MDR and FDA
  • Duration shortened at the client’s request, fixed price and order budget kept

Cyber & Compliance

Your next step

Get in touch now!

Whether you have a concrete project, need initial guidance or have other questions: tell us briefly what it is about.

Discuss your project