← All resourcesIndustry Frameworks
Industry frameworks & playbooks worth knowing
Not government-mandated regulations, not formal published standards — these are voluntary, industry-consensus frameworks from bodies like HSCC and MDIC that shape how manufacturers actually implement security in practice.
| Document | Publisher | Year | Description |
|---|---|---|---|
| From Metrics to Meaning: Transforming Medical Device Cybersecurity into a Strategic Risk Narrative | Health-ISAC | Sep 2026 | White paper on translating device cybersecurity metrics into risk narratives that resonate with executive leadership, connecting operational measurements to enterprise-level risk decisions. |
| Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers | CISA & Others | Jul 2026 | Joint guidance from CISA, NSA, Japan’s JPCERT/CC, the Netherlands’ NCSC-NL, and the UK’s NCSC-UK on designing and running a coordinated vulnerability disclosure (CVD) program for external researchers — a clear vulnerability disclosure policy, and processes for triage, remediation, and CVE assignment, plus considerations for using third-party intermediaries such as national CSIRTs. |
| Validating Medical Device Cybersecurity Through Penetration Testing | MDIC | Jun 2026 | A five-step framework for scoping, executing, and acting on medical device penetration test results, addressing the industry's lack of a consistent, widely accepted approach. |
| Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies | MITRE | Apr 2026 | FDA-commissioned discussion paper examining how AI/ML, cloud integration, digital twins, and post-quantum cryptography are reshaping risk analysis methodologies for connected medical devices. |
| Considerations for Managing Challenges in Software Bill of Materials (SBOM) Data Normalization | MITRE | Apr 2026 | Follow-up to MITRE's 2024 SBOM data normalization white paper, continuing to address interoperability and normalization challenges across the medical device SBOM ecosystem. |
| Model Contract-Language for MedTech Cybersecurity v2 (MC2v2)Co-authored by our team | HSCC | Nov 2025 | Template cybersecurity contract language for agreements between device manufacturers and healthcare delivery organizations. |
| 2025 MDIC Cybersecurity Benchmark Report | MDIC | Oct 2025 | Annual industry benchmarking of cybersecurity maturity across the total product lifecycle — organization, risk management, supplier management, design & development, V&V, and maintenance. |
| Exploring the Cybersecurity Roles of Manufacturers and Healthcare Organizations During the Medical Device Lifecycle | Health-ISAC | Feb 2025 | Maps how cybersecurity responsibilities shift between manufacturers and healthcare delivery organizations across four device lifecycle phases, framed around maintaining cyber resilience through coordinated hand-offs. Follow-on to the 2023 shared-responsibility RACI paper. |
| Data Normalization Challenges and Mitigations in Software Bill of Materials (SBOM) Processing | MITRE | Oct 2024 | White paper for medical device manufacturers on SBOM data normalization — interoperability gaps across SBOM standards, missing or imprecise element definitions, and multi-format ingestion challenges, with recommended mitigations. |
| Medical Device and Health IT Joint Security Plan v2 (JSP2)Co-authored by our team | HSCC | Mar 2024 | FDA-recognized document for implementing a Secure Product Development Framework (SPDF); a total-product-lifecycle reference guide for secure-by-design and secure-by-default medical device and health IT development, and a major refresh of the original 2019 JSP. |
| Playbook for Threat Modeling Medical Devices | MDIC | Feb 2024 | Developed with FDA, MITRE, and Adam Shostack & Associates from 2020-21 threat modeling bootcamps; presents general threat modeling principles and methodologies rather than a single prescriptive approach. |
| Next Steps Toward Managing Legacy Medical Device Cybersecurity Risks | MITRE | Nov 2023 | FDA-commissioned white paper on near-term solutions for managing legacy medical device cybersecurity risk, with specific considerations for less-resourced healthcare delivery organizations such as rural and safety-net hospitals. |
| MedTech Vulnerability Communications Toolkit (MVCT) | HSCC | Oct 2023 | Plain-language templates for communicating device vulnerabilities to clinicians, patients, and other non-security audiences, building on FDA's 2021 best-practices guide. |
| Improving Medical Device Security by Moving from Shared to Defined Responsibility | Health-ISAC | Jul 2023 | A method for building RACI matrices that assign every task needed to develop, deploy, and operate a medical device to either the manufacturer or the healthcare delivery organization, with templates for common deployment scenarios including MDM-managed and software-only devices. |
| Health Industry Cybersecurity: Managing Legacy Technology Security (HIC-MaLTS)Co-authored by our team | HSCC | Mar 2023 | Modular, actionable guidance for manufacturers and healthcare delivery organizations on managing cybersecurity risk in legacy medical technology as a shared responsibility. |
| Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook | MITRE | Nov 2022 | Framework developed with FDA to help healthcare delivery organizations plan for and respond to medical device cybersecurity incidents, protecting device effectiveness and patient safety. |
| Discussion Paper: Strengthening Cybersecurity Practices Associated with Servicing of Medical Devices | FDA | Jun 2021 | CDRH discussion paper seeking early industry input on shared cybersecurity responsibility across privileged access, vulnerability identification, prevention/mitigation, and product lifecycle challenges in device servicing. |
| Best Practices for Communicating Cybersecurity Vulnerabilities to Patients | FDA | 2021 | FDA guidance on designing clear, timely, patient-centered communications when a device cybersecurity vulnerability needs to be disclosed to patients and caregivers. |
| Rubric for Applying CVSS to Medical Devices | MITRE | Oct 2020 | Developed under FDA contract as an FDA-qualified Medical Device Development Tool (MDDT); extends CVSS scoring with medical-device-specific guidance, including the patient safety dimension CVSS v3.x lacks. |
Not sure which frameworks apply to your program?
We'll help you decide which voluntary frameworks are worth adopting alongside your regulatory obligations.
