← All resourcesIndustry Frameworks

Industry frameworks & playbooks worth knowing

Not government-mandated regulations, not formal published standards — these are voluntary, industry-consensus frameworks from bodies like HSCC and MDIC that shape how manufacturers actually implement security in practice.

DocumentPublisherYearDescription
From Metrics to Meaning: Transforming Medical Device Cybersecurity into a Strategic Risk NarrativeHealth-ISACSep 2026White paper on translating device cybersecurity metrics into risk narratives that resonate with executive leadership, connecting operational measurements to enterprise-level risk decisions.
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security ResearchersCISA & OthersJul 2026Joint guidance from CISA, NSA, Japan’s JPCERT/CC, the Netherlands’ NCSC-NL, and the UK’s NCSC-UK on designing and running a coordinated vulnerability disclosure (CVD) program for external researchers — a clear vulnerability disclosure policy, and processes for triage, remediation, and CVE assignment, plus considerations for using third-party intermediaries such as national CSIRTs.
Validating Medical Device Cybersecurity Through Penetration TestingMDICJun 2026A five-step framework for scoping, executing, and acting on medical device penetration test results, addressing the industry's lack of a consistent, widely accepted approach.
Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving TechnologiesMITREApr 2026FDA-commissioned discussion paper examining how AI/ML, cloud integration, digital twins, and post-quantum cryptography are reshaping risk analysis methodologies for connected medical devices.
Considerations for Managing Challenges in Software Bill of Materials (SBOM) Data NormalizationMITREApr 2026Follow-up to MITRE's 2024 SBOM data normalization white paper, continuing to address interoperability and normalization challenges across the medical device SBOM ecosystem.
Model Contract-Language for MedTech Cybersecurity v2 (MC2v2)Co-authored by our teamHSCCNov 2025Template cybersecurity contract language for agreements between device manufacturers and healthcare delivery organizations.
2025 MDIC Cybersecurity Benchmark ReportMDICOct 2025Annual industry benchmarking of cybersecurity maturity across the total product lifecycle — organization, risk management, supplier management, design & development, V&V, and maintenance.
Exploring the Cybersecurity Roles of Manufacturers and Healthcare Organizations During the Medical Device LifecycleHealth-ISACFeb 2025Maps how cybersecurity responsibilities shift between manufacturers and healthcare delivery organizations across four device lifecycle phases, framed around maintaining cyber resilience through coordinated hand-offs. Follow-on to the 2023 shared-responsibility RACI paper.
Data Normalization Challenges and Mitigations in Software Bill of Materials (SBOM) ProcessingMITREOct 2024White paper for medical device manufacturers on SBOM data normalization — interoperability gaps across SBOM standards, missing or imprecise element definitions, and multi-format ingestion challenges, with recommended mitigations.
Medical Device and Health IT Joint Security Plan v2 (JSP2)Co-authored by our teamHSCCMar 2024FDA-recognized document for implementing a Secure Product Development Framework (SPDF); a total-product-lifecycle reference guide for secure-by-design and secure-by-default medical device and health IT development, and a major refresh of the original 2019 JSP.
Playbook for Threat Modeling Medical DevicesMDICFeb 2024Developed with FDA, MITRE, and Adam Shostack & Associates from 2020-21 threat modeling bootcamps; presents general threat modeling principles and methodologies rather than a single prescriptive approach.
Next Steps Toward Managing Legacy Medical Device Cybersecurity RisksMITRENov 2023FDA-commissioned white paper on near-term solutions for managing legacy medical device cybersecurity risk, with specific considerations for less-resourced healthcare delivery organizations such as rural and safety-net hospitals.
MedTech Vulnerability Communications Toolkit (MVCT)HSCCOct 2023Plain-language templates for communicating device vulnerabilities to clinicians, patients, and other non-security audiences, building on FDA's 2021 best-practices guide.
Improving Medical Device Security by Moving from Shared to Defined ResponsibilityHealth-ISACJul 2023A method for building RACI matrices that assign every task needed to develop, deploy, and operate a medical device to either the manufacturer or the healthcare delivery organization, with templates for common deployment scenarios including MDM-managed and software-only devices.
Health Industry Cybersecurity: Managing Legacy Technology Security (HIC-MaLTS)Co-authored by our teamHSCCMar 2023Modular, actionable guidance for manufacturers and healthcare delivery organizations on managing cybersecurity risk in legacy medical technology as a shared responsibility.
Medical Device Cybersecurity Regional Incident Preparedness and Response PlaybookMITRENov 2022Framework developed with FDA to help healthcare delivery organizations plan for and respond to medical device cybersecurity incidents, protecting device effectiveness and patient safety.
Discussion Paper: Strengthening Cybersecurity Practices Associated with Servicing of Medical DevicesFDAJun 2021CDRH discussion paper seeking early industry input on shared cybersecurity responsibility across privileged access, vulnerability identification, prevention/mitigation, and product lifecycle challenges in device servicing.
Best Practices for Communicating Cybersecurity Vulnerabilities to PatientsFDA2021FDA guidance on designing clear, timely, patient-centered communications when a device cybersecurity vulnerability needs to be disclosed to patients and caregivers.
Rubric for Applying CVSS to Medical DevicesMITREOct 2020Developed under FDA contract as an FDA-qualified Medical Device Development Tool (MDDT); extends CVSS scoring with medical-device-specific guidance, including the patient safety dimension CVSS v3.x lacks.

Not sure which frameworks apply to your program?

We'll help you decide which voluntary frameworks are worth adopting alongside your regulatory obligations.

Schedule a Consultation