main logo icon

Published on

September 19, 2026

|

18 min read

Best Medical Device Penetration Testing Companies (2026): FDA 524B, Health Canada and SaMD Testing Compared

Ranked guide to the best medical device penetration testing companies in 2026 for device makers, SaMD and digital health platforms, with what FDA section 524B, Health Canada, IEC 81001-5-1 and UL 2900 actually expect of a test report.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Medical device penetration testing is one of the few security purchases a regulator names outright. Section 524B of the Federal Food, Drug, and Cosmetic Act took effect on 29 March 2023 and requires anyone submitting a 510(k), PMA, PDP, De Novo or HDE for a cyber device to provide cybersecurity information, including a software bill of materials. FDA's premarket cybersecurity guidance, issued 3 February 2026, asks that a penetration test report carry five elements: tester independence and technical expertise, scope, duration, methods and results. Health Canada's Pre-market Requirements for Medical Device Cybersecurity, effective 26 June 2019, asks for structured penetration testing inside its verification and validation expectations. A device pentest is not one test: it spans embedded firmware, wireless interfaces, companion mobile applications, cloud backends and clinician web portals. The companies ranked here are Stingrai, NetSPI, Blue Goat Cyber, UL Solutions, NCC Group, MedSec, Meditology Services, Finite State, Praetorian, Software Secured and Qualysec. Every entry links to the vendor's own published page and was verified on 19 September 2026.

Since 29 March 2023, every premarket submission for a cyber device has had to carry cybersecurity information under section 524B of the Federal Food, Drug, and Cosmetic Act, including a postmarket vulnerability monitoring plan, processes that provide reasonable assurance the device and related systems are cybersecure, and a software bill of materials covering commercial, open source and off-the-shelf components (21 U.S.C. 360n-2). That statutory date is the reason medical device penetration testing stopped being an optional security exercise and became a line item that a reviewer reads.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider founded in 2021, headquartered in Toronto with a London office. On a device programme it takes the software half of the estate: the clinician portal tested authenticated as every role, the companion iOS and Android application against OWASP MASVS and MASTG down to Keychain and Keystore storage, certificate pinning and jailbreak or root detection, the REST and GraphQL backend the device talks to, and the AWS, Azure or Google Cloud tenancy behind it including cross-account role assumption and provisioning infrastructure. Two named penetration testers hold OSCE³, OSWE, OSEP, CREST CRT and CISSP between them, have published 18 CVEs, and include a researcher with 400+ Hall of Fame reports at Apple, Google and the US Department of Defense. Delivery is one-time or continuous through the PTaaS platform, with published pricing from US$3,000 per assessment for one web application and its APIs (pricing) and every other scope quoted.

This guide is for device manufacturers, Software as a Medical Device vendors and digital health platforms in the United States and Canada. If you run a hospital or a health plan rather than a device programme, the healthcare penetration testing ranking and the HIPAA-focused provider ranking are the right starting points. Every vendor entry below links to a page the vendor publishes itself, verified 19 September 2026.

Quick answer: who are the best medical device penetration testing companies in 2026?

The best medical device penetration testing companies in 2026 are Stingrai, NetSPI, Blue Goat Cyber, UL Solutions, NCC Group, MedSec, Meditology Services, Finite State, Praetorian, Software Secured and Qualysec. Stingrai is a CREST-accredited penetration testing service provider whose two named penetration testers per engagement cover the software half of a connected device programme: the clinician portal and backend APIs tested authenticated as every role for broken authorization and tenant isolation, the companion iOS and Android application against OWASP MASVS and MASTG, and the cloud tenancy from control plane to workload, delivered one-time or continuously through its PTaaS platform with retesting and an attestation letter included. NetSPI, Blue Goat Cyber and UL Solutions follow for published device-specific testing across firmware, wireless and hardware, FDA submission-shaped reporting, and UL 2900 laboratory evaluation respectively.

Chart of the five surfaces a medical device penetration test has to cover in 2026

What medical device makers are actually required to test

Four regimes shape a device penetration test, and only one of them is a statute. The difference decides whether your report satisfies a reviewer or draws a deficiency letter.

What does FDA section 524B require for medical device penetration testing?

Section 524B(b) requires the sponsor of a 510(k), PMA, PDP, De Novo or HDE for a cyber device to submit a plan to monitor, identify and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time; to design, develop and maintain processes providing reasonable assurance that the device and related systems are cybersecure, with postmarket updates and patches made available; and to provide a software bill of materials including commercial, open source and off-the-shelf components.

Section 524B(c) defines a cyber device as one that includes software validated, installed or authorized by the sponsor, has the ability to connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats. All three conditions apply together. A closed-loop insulin pump with a Bluetooth companion application and a cloud portal is a cyber device. A sterile single-use instrument with no software is not.

The statute never uses the words penetration testing. The guidance does. FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026 and superseding the guidance issued 27 June 2025 (FDA guidance page), asks that penetration test reports carry five elements:

Independence and technical expertise of testers; Scope of testing; Duration of testing; Testing methods employed; and Test results, findings, and observations.

It also asks manufacturers to state by whom the testing was performed, for example independent internal testers or external testers, and how independent those testers are from the developers who designed the device, noting that third parties may be necessary in some cases to achieve that independence. That paragraph is why a device maker's choice of penetration testing vendor is a regulatory decision and not only a security one.

What does Health Canada require for medical device cybersecurity?

Health Canada's guidance document Pre-market Requirements for Medical Device Cybersecurity came into effect on 26 June 2019 (Health Canada notice). It applies to devices that consist of or contain software and asks manufacturers to demonstrate, in the licence or licence amendment application, that the device is sufficiently secure against threats that could exploit a vulnerability.

Its cybersecurity testing expectations name security requirements testing, threat mitigation assessment, vulnerability scanning and penetration testing, and its verification and validation expectations name known vulnerability assessment, malware testing, fuzz testing and structured penetration testing. Third-party components attract an SBOM and a documented vulnerability assessment, all inside total product lifecycle security risk management rather than a one-time gate. One well-scoped test can serve both files if the report is written to the FDA's five-element specification, which is the stricter standard. Canadian buyers comparing benches will find the domestic landscape in the Canada penetration testing ranking.

Do IEC 81001-5-1 and UL 2900 require penetration testing?

They sit either side of the test rather than inside it. IEC 81001-5-1:2021, Health software and health IT systems safety, effectiveness and security, Part 5-1: Security, Activities in the product life cycle, was published in December 2021 (ISO catalogue entry). It layers security activities onto the IEC 62304 software lifecycle and the ISO 14971 risk framework, and the FDA recognises it as a consensus standard. It tells you the security verification activity has to exist and be planned. It does not tell you how to exploit a Bluetooth pairing flow.

UL 2900 is the product-level series, and UL Solutions runs a laboratory practice against it. Its medical device penetration testing service describes testing that starts from the threat model and covers vulnerability scanning and binary analysis, security control examination, protocol and packet analysis of communications, and cryptographic testing.

MDS2, the Manufacturer Disclosure Statement for Medical Device Security published as an ANSI and NEMA standard, is a disclosure form rather than a test. It is what a hospital's procurement team sends you, and it asks you to assert the device's security control characteristics. A penetration test is how you learn whether those assertions survive contact with an attacker before a customer does.

Where does HIPAA apply to a device maker?

HIPAA reaches a device programme through the data, not the hardware. If the companion application, the cloud backend or the clinician portal creates, receives, maintains or transmits protected health information on behalf of a covered entity, the manufacturer is operating as a business associate and the Security Rule applies to that system. The Security Rule at 45 CFR Part 164 Subpart C does not require penetration testing by name: it requires a risk analysis, a periodic technical and nontechnical evaluation, and maintenance of security measures, with testing as supporting evidence. Clause-level detail is in the HIPAA penetration testing requirements guide. FDA governs what you file before you ship. HIPAA governs how the cloud half of the product behaves once patient data flows through it.

Regime

Is penetration testing named?

What it governs

What the evidence looks like

FD&C Act section 524B

No. The statute names a postmarket plan, secure development processes and an SBOM

Premarket submissions for cyber devices since 29 March 2023

Cybersecurity information sufficient to show the device meets 524B(b)

FDA premarket guidance, 3 February 2026

Yes, explicitly

Submission content and the QMS behind it

A report carrying tester independence and expertise, scope, duration, methods and results

Health Canada, effective 26 June 2019

Yes, as structured penetration testing

Licence applications for software-containing devices

Testing evidence plus SBOM and vulnerability assessment for third-party components

IEC 81001-5-1:2021 and UL 2900

Process standard and product test series respectively

The development lifecycle, and product-level evaluation

Planned security verification activities, or laboratory evaluation results

HIPAA Security Rule

No

Cloud, portal and application layers when PHI is involved

Risk analysis and periodic evaluation, with testing as supporting evidence

What a medical device penetration test actually scopes

The single most common scoping error is buying one test when the product has five attack surfaces. A connected device is a distributed system, and the exploit path almost always crosses a boundary between two of these layers.

  • Embedded firmware and hardware interfaces. Firmware extraction and reverse engineering, secure boot and signature verification, anti-rollback controls, debug interfaces such as JTAG and UART, and stored secrets. The question is whether an attacker with physical access to one unit can recover a key that unlocks the fleet.

  • Wireless and radio interfaces. BLE pairing and bonding, Wi-Fi provisioning, NFC, Zigbee, cellular and proprietary radio. The question is whether a nearby attacker can pair, replay or inject without the authentication the design assumes.

  • Companion mobile applications. Credential handling, certificate pinning, local storage of health data, and the trust the application places in the device. Often the weakest link, because it ships faster than the firmware. Benches for this layer are compared in the mobile application penetration testing ranking.

  • Cloud backends and APIs. Tenant isolation between health systems, object level authorization on device and patient identifiers, enrolment and provisioning flows, and the update infrastructure that pushes signed images to the field. Broken object level authorization here turns one compromised account into a fleet-wide exposure.

  • Clinician web portals. Role separation between clinician, technician, administrator and patient, session handling, and the business logic in prescribing, dosing and alerting workflows, where a logic flaw has a clinical consequence rather than only a financial one.

Stingrai's AI agent, Snipe, covers the web application layer of that list, including the application's APIs. It is purpose-built to hunt broken object level authorization, IDOR and business logic flaws rather than only known-class issues, it performs white-box source review alongside black-box testing, it opens AutoFix pull requests, and it can gate pull requests so vulnerable code does not merge. Firmware, wireless, mobile and network scope is delivered by Stingrai's penetration testers, who work concurrently with Snipe on web engagements and direct where it looks.

How we ranked them

Eleven vendors were scored against six criteria specific to device programmes, and every claim traces to a page the vendor publishes itself, verified 19 September 2026.

  1. Published device or connected product testing. A page on the vendor's own site describing medical device, embedded, firmware or health software testing. Healthcare logo walls were scored down.

  2. Surface coverage. How many of the five layers above the vendor tests, and whether it tests them as one estate.

  3. Submission-shaped reporting. Whether a reviewer can read independence, scope, duration, methods and results without a translation layer.

  4. Regulatory literacy. Demonstrated working knowledge of section 524B, the premarket guidance, Health Canada, IEC 81001-5-1 or UL 2900, rather than generic compliance language.

  5. Manual depth relative to automation. Manual verification, especially for authorization and business logic, which scanners do not reach.

  6. Delivery model fit. Support for both a one-time submission-driven test and a continuous programme, with findings reaching engineers in their tracker.

Vendors whose product is regulatory documentation, SBOM management or asset visibility without offensive testing were not ranked here. Two are noted after the ranking.

Quick comparison: medical device penetration testing companies

Company

HQ

Delivery model

Device positioning

Best for

1. Stingrai

Toronto, Canada

Human-led, one-time or continuous PTaaS

CREST-accredited, with MASVS and MASTG mobile testing, role-based authorization testing on the portal and APIs, and cloud control plane to workload

The software half of a device estate, tested by named penetration testers

2. NetSPI

Minneapolis, USA

Platform-delivered PTaaS

Published medical device service across firmware, hardware, wireless, thick client and mobile

The hardware-inclusive premarket report

3. Blue Goat Cyber

Scottsdale, USA

Fixed-fee project

Premarket programme covering device, firmware, application and cloud plus submission documentation

Manufacturers without an internal regulatory security function

4. UL Solutions

Northbrook, USA

Laboratory evaluation

Device penetration testing against the UL 2900 series, starting from the threat model

A recognised laboratory name on the evaluation

5. NCC Group

Manchester, UK

Consultancy, Authorized Lab

Hardware and embedded practice naming FDA cybersecurity guidelines among its frameworks

Deep firmware, silicon and radio work

6. MedSec

Fort Lauderdale, USA

Consultancy

Medical device product security specialist serving manufacturers and hospitals

A device-only bench with hospital-side context

7. Meditology Services

Atlanta, USA

Consultancy

Healthcare-exclusive firm with a Medical Device and IoT Security practice alongside testing

Device plus provider-side assurance from one firm

8. Finite State

Columbus, USA

Platform plus services

Firmware and binary analysis with a penetration testing line for connected products

Teams already running SBOM and firmware analysis

9. Praetorian

Austin, USA

Platform-led continuous

Healthcare attack surface management naming IoMT exposure and FDA regulation

The deployed fleet and its cloud surface

10. Software Secured

Ottawa, Canada

Manual-first PTaaS

Healthcare and HIPAA testing across applications, APIs, cloud and IoT

SaMD vendors whose product is entirely software

11. Qualysec

Bhubaneswar, India

Project-based

Published FDA section 524B service across firmware, wireless, mobile, web, cloud and updates

An explicit 524B evidence crosswalk

1. Stingrai (top rated for device software and cloud scope)

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

Each engagement is staffed by two named penetration testers and reviewed by the team lead. The team has 18 published CVEs and includes a founding member of Uber's offensive security team who tests web, mobile and LLM systems, and a researcher with more than 400 Hall of Fame reports at Apple, Google, Facebook, Yahoo and the US Department of Defense. Testing is delivered through its PTaaS platform.

For a device programme, Stingrai's scope is the software estate around the device. The clinician web portal and the backend the device calls are tested authenticated as every role, hunting object level authorization, tenant isolation and business logic failures: whether a patient or device identifier in a request is checked against the session, whether one health system's fleet is addressable from another's token, whether a provisioning or firmware-update call can be replayed. The companion application is tested against OWASP MASVS and MASTG with static and dynamic analysis of the IPA and APK, Keychain and Keystore storage, certificate pinning and root or jailbreak detection bypass with Frida and objection, and exported components. The cloud backend is tested from control plane to workload, including cross-account role assumption, resource and bucket policies, instance metadata abuse and, on Azure, app registrations, service principals and Conditional Access gaps. That is the half of a device test that most often produces a finding with fleet-wide reach.

It covers web applications and APIs, mobile applications, AI and LLM systems, cloud environments, internal and external networks, phishing campaigns and red teaming.

  • HQ Toronto, Canada, with a London, UK office.

  • Delivery model human-led penetration testing, available as a one-time engagement or as a continuous programme through PTaaS. Both are standard offerings, not alternatives.

  • Named penetration testers clients work directly with the penetration testers on their engagement through the platform. Team certifications include OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, and the team has 18 published CVEs.

  • Retest included.

  • Portal the PTaaS platform carries live findings, direct communication with the penetration testers, and remediation tracking.

  • Pricing transparency published at stingrai.io/pricing.

  • Best for device makers and SaMD vendors who want the portal, companion application, backend API, cloud and network layers tested by named penetration testers, with a redactable report, attestation letter and retest record written to support their FDA section 524B, Health Canada, SOC 2, ISO 27001 or HIPAA files.

Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs, and nothing beyond it. On a device programme that means the clinician portal and the backend APIs. Snipe hunts broken authorization, IDOR and business logic flaws rather than stopping at known-class issues, reviews source code as well as running dynamic tests, opens AutoFix pull requests and can gate pull requests in CI. On Hybrid engagements Stingrai's penetration testers test at the same time as Snipe and direct its focus, and they deliver the mobile, network, cloud, social engineering and adversary simulation scope themselves.

CREST accreditation applies to Stingrai as a penetration testing service provider, and is separate from the individual CREST CRT certifications team members hold. Request a scoped quote for a device programme.


2. NetSPI

NetSPI publishes a dedicated medical device penetration testing page describing threat modelling combined with testing across firmware analysis, hardware survey, wireless configuration, network analysis, thick client and mobile applications, sensor data, privacy concerns and potential patient safety issues, with the stated goal of determining whether devices meet the current standards and recommendations of the FDA premarket cybersecurity guidelines.

HQ Minneapolis, USA. Delivery platform-delivered PTaaS, with retest and portal in the model. Pricing quoted.

Pros: one of the few benches with a published device-specific page rather than a generic IoT line, covering firmware, wireless, companion application and network in one engagement, with patient safety named as a testing consideration.

Cons: enterprise delivery suits programmes more than a single submission-driven test, and cloud backend testing is a separate service line, so confirm it is in the statement of work.

Best for: manufacturers assembling the hardware-inclusive report a premarket submission expects.


3. Blue Goat Cyber

Blue Goat Cyber publishes a medical device penetration testing service built around FDA submissions, covering device, firmware, application and cloud testing, wireless work across BLE, Wi-Fi, Zigbee, NFC and proprietary radio, and firmware extraction and reverse engineering. Its premarket programme is described as covering the secure product development framework, SBOMs, threat modelling, penetration testing and eSTAR documentation, with a separate deficiency response service for submissions already on hold.

HQ Scottsdale, USA. Delivery fixed-fee project work. Pricing fixed-fee model published, figures quoted.

Pros: the full premarket package from one firm, which suits manufacturers without an internal regulatory cybersecurity function, with predictable budgeting and a named deficiency response service.

Cons: submission-centric, so confirm the postmarket model and bench availability against your filing date.

Best for: small and mid-size manufacturers who want testing and submission documentation from the same team.


4. UL Solutions

UL Solutions publishes a medical device penetration testing service delivered against the UL 2900 series. The described methodology starts from the threat model to establish critical components and their exploitability, then runs vulnerability scanning and binary analysis, security control examination, protocol and packet analysis of device communications, and cryptographic testing. Its own framing is that security testing for medical devices goes far beyond simple vulnerability scanning.

HQ Northbrook, USA. Delivery laboratory evaluation. Pricing quoted.

Pros: a recognised laboratory name on the evaluation, with threat-model-first sequencing, which is the correct order for a device with safety-relevant functions.

Cons: laboratory evaluation is a different product from adversarial testing, so if you want a BLE weakness chained into a cloud account takeover, say so in scoping. Timelines run to laboratory rather than sprint pace.

Best for: manufacturers who want a recognised laboratory evaluating the device against a published product standard.


5. NCC Group

NCC Group's hardware and embedded systems security practice covers products from requirements through lifecycle support and states that, as an Authorized Lab, it can help devices meet guidelines from ETSI EN 303 645 to NIST IR 8425 to ioXt Alliance to FDA cybersecurity compliance guidelines. Its published research includes hardware-level analysis of medical devices, a useful signal that the bench has done the work rather than only sold it.

HQ Manchester, UK. Delivery consultancy, with Authorized Lab status. Pricing quoted.

Pros: genuine firmware and hardware depth, including the physical attacks that decide whether a fleet key is recoverable from a single unit, with FDA guidelines named explicitly.

Cons: no dedicated medical device service page, so clinical and regulatory framing comes from your scoping brief, and large-consultancy procurement can be slow to start.

Best for: complex connected hardware where the silicon, firmware and radio are the difficult part.


6. MedSec

MedSec is a medical device product security specialist working with manufacturers on building more secure devices and with hospitals on patient safety implementation, alongside a training practice. Medical device penetration testing is a published part of its manufacturer offering, and the two-sided practice means the bench sees both how a device is built and how it behaves once a health system deploys it.

HQ Fort Lauderdale, USA. Delivery consultancy. Pricing quoted.

Pros: device-only focus, so scoping starts from clinical use and safety consequence rather than a generic application template, informed by hospital deployment realities.

Cons: less published detail on submission documentation support than the submission-centric firms, and a smaller bench, so confirm capacity against a fixed filing date.

Best for: manufacturers who want a device-only bench with hospital-side context.


7. Meditology Services

Meditology is healthcare-exclusive and publishes both a penetration testing practice and a Medical Device and IoT Security practice. That combination is uncommon: most firms do provider-side testing or device-side testing, not both. For a manufacturer that also sells into health systems and answers their security questionnaires, one firm covering the device, the software and the provider-side expectations removes a translation layer.

HQ Atlanta, USA. Delivery consultancy. Pricing quoted.

Pros: device and IoT security alongside general technical testing inside a healthcare-only practice, with HITRUST certification services from the same firm and working knowledge of how your MDS2 responses will be read.

Cons: consultancy-led delivery, so pin down tester continuity in the statement of work, and less published hardware methodology detail than the device specialists.

Best for: programmes needing device testing and provider-side assurance work from one healthcare-only firm.


8. Finite State

Finite State pairs a firmware and binary analysis platform with a services line including penetration testing and red teaming, described as testing shipped firmware, binaries, interfaces and connected systems against realistic attack paths and delivering exploitability findings, remediation guidance and validation evidence. Medical devices are a named solution area, and the platform side covers the SBOM and vulnerability management work section 524B asks for.

HQ Columbus, USA. Delivery platform plus services. Pricing quoted.

Pros: testing sits on the same evidence base as the SBOM and firmware analysis, so a finding lands next to the component it came from, and exploitability rather than raw vulnerability counts is the stated output.

Cons: platform-first company, so confirm the manual proportion of the services engagement, and less published detail on wireless and companion mobile testing.

Best for: teams already running SBOM and firmware analysis who want testing on the same platform.


9. Praetorian

Praetorian's healthcare page is built around attack surface management and continuous threat exposure management, with continuous penetration testing and red teaming layered on top. It names HIPAA, HITRUST and FDA regulation as compliance drivers and cites IoMT density in hospital rooms as a primary threat vector. For a manufacturer the relevance is postmarket: the deployed fleet and its cloud infrastructure.

HQ Austin, USA. Delivery platform-led continuous testing. Pricing quoted.

Pros: continuous testing rather than a single snapshot, which matches how a shipped fleet changes, with discovery-first framing when the cloud footprint has outgrown the inventory.

Cons: no published premarket device testing service, so this is not the bench for a 510(k) report, and platform pricing suits programme budgets rather than a scoped submission test.

Best for: manufacturers whose problem is the deployed fleet rather than the submission.


10. Software Secured

Software Secured runs a manual-first PTaaS practice and publishes a healthcare penetration testing page covering applications, APIs and cloud with PHI-handling workflows in scope, alongside a HIPAA testing page. Its published service set spans web, API, mobile, cloud and IoT testing with findings mapped to OWASP, SANS and NIST references. For a SaMD vendor whose product is entirely software, that is the whole product.

HQ Ottawa, Canada. Delivery manual-first PTaaS with a North American bench and named testing leadership published on the site. Pricing quoted.

Pros: named testers, continuous delivery of findings to engineers, and a Canadian base that is convenient alongside a Health Canada filing.

Cons: no published hardware or firmware practice, so a connected device still needs a second bench for the embedded layer, and the healthcare framing is PHI oriented rather than submission oriented.

Best for: SaMD vendors and digital health platforms whose product is application, API and cloud.


11. Qualysec

Qualysec publishes an FDA section 524B service with the most explicit regulatory crosswalk of any vendor reviewed here. Described scope covers secure boot, firmware signatures, anti-rollback and update recovery, JTAG, UART and USB interfaces, Wi-Fi, Bluetooth, BLE, cellular and proprietary protocols, mobile and web authentication and authorization, cloud tenant isolation and administrative access, and update infrastructure from build systems through field installation. Deliverables are described as including threat-informed test plans, penetration test reports, remediation registers and crosswalks mapping evidence to regulatory requirements.

HQ Bhubaneswar, India, with a Bengaluru office. Delivery project-based. Accreditation the firm publishes CREST accreditation and ISO 27001 certification. Pricing quoted.

Pros: published scope maps onto all five device surfaces, the documentation crosswalk is a genuinely useful artifact for a regulatory team, and the cost structure sits below the North American and laboratory benches.

Cons: offshore delivery, which some manufacturers' data handling reviews will constrain, and less independent evidence of device programme outcomes, so ask for references in your device class.

Best for: cost-sensitive programmes wanting an explicit section 524B evidence crosswalk with the report.


Two firms worth knowing that are not penetration testing vendors

Category fit matters here, because a report that is not a penetration test report will not answer a reviewer asking for one. Medcrypt is a leading medical device cybersecurity name whose platform supports FDA readiness, vulnerability management, SBOM analysis, threat modelling and submission support across FDA, EU MDR and Health Canada. Asimily and similar connected-device risk platforms give hospitals inventory and risk scoring for deployed equipment, which tells you how your device will be judged in the field. Neither produces a penetration test report, and neither claims to. The error is on the buyer's side when a readiness engagement is booked expecting one.


How much does medical device penetration testing cost in 2026?

Device engagements price above a standard web application test because the scope is genuinely larger: a hardware bench, radio equipment, firmware reverse engineering time, and a report written for a reviewer rather than an engineering lead. The usual drivers are how many physical units you supply for destructive testing, how many radios the device speaks, whether source code is provided, and whether the cloud backend and companion application sit in the same engagement.

Indicative 2026 bands for a single device programme, based on published vendor pricing models and typical market scoping:

Scope

US$ band

C$ band

SaMD or clinician portal web application and APIs only

US$3,000 to US$15,000

C$4,000 to C$20,000

Companion mobile application plus backend APIs

US$12,000 to US$30,000

C$16,000 to C$40,000

Full connected device: firmware, wireless, mobile, cloud

US$35,000 to US$90,000

C$47,000 to C$120,000

Continuous programme across a shipped fleet

US$650 per month and up

C$875 per month and up

Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs. The same tiers run as subscriptions from US$650 per month and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee, and retesting is included. Device programmes, multi-application estates and network scope are quoted individually on the pricing page. Wider market context sits in the United States ranking.


A buyer checklist for device penetration testing

Take this into the vendor call and ask for written answers.

  1. Which of the five surfaces are in scope? Get the excluded ones written down too.

  2. How many physical units do you need, and will they survive? Hardware testing consumes devices, so budget for it.

  3. Will the report carry the five FDA elements? Ask for a redacted sample showing all five.

  4. What is the independence statement? Your vendor should be able to write that paragraph for you.

  5. Who are the named penetration testers, and what do they hold? Names and certifications, not a bench average.

  6. Is retesting included, and for how long after the report? A fix you cannot evidence as verified is not one a reviewer will credit.

  7. Is there a postmarket model? Section 524B asks for an ongoing plan, which a one-time test does not satisfy by itself.

  8. Can the same evidence serve the FDA, Health Canada and your customers' security questionnaires? If not, you are buying the same test twice.

The paperwork lives in two documents: the penetration testing statement of work template for scope, rules of engagement and acceptance criteria, and the penetration testing RFP template for the vendor-facing questions.


Frequently Asked Questions

Who are the best medical device penetration testing companies in 2026?

The best medical device penetration testing companies in 2026 are Stingrai, NetSPI, Blue Goat Cyber, UL Solutions, NCC Group, MedSec, Meditology Services, Finite State, Praetorian, Software Secured and Qualysec. Stingrai is a CREST-accredited penetration testing service provider whose two named penetration testers per engagement cover the software half of a connected device programme: the clinician portal and backend APIs tested authenticated as every role for broken authorization and tenant isolation, the companion iOS and Android application against OWASP MASVS and MASTG, and the cloud tenancy from control plane to workload, delivered one-time or continuously through its PTaaS platform with retesting and an attestation letter included. NetSPI, Blue Goat Cyber and UL Solutions follow for published device-specific testing across firmware, wireless and hardware, FDA submission-shaped reporting, and UL 2900 laboratory evaluation respectively. Every entry links to the vendor's own published page and was verified on 19 September 2026.

What does FDA section 524B require for medical device penetration testing?

Section 524B of the Federal Food, Drug, and Cosmetic Act took effect on 29 March 2023 and requires the sponsor of a 510(k), PMA, PDP, De Novo or HDE for a cyber device to submit a postmarket vulnerability monitoring plan, to maintain processes providing reasonable assurance the device and related systems are cybersecure with postmarket updates and patches available, and to provide a software bill of materials covering commercial, open source and off-the-shelf components. The statute does not use the phrase penetration testing. FDA's premarket cybersecurity guidance, issued 3 February 2026, does: it asks that penetration test reports include the independence and technical expertise of testers, the scope of testing, the duration of testing, the testing methods employed, and the test results, findings and observations.

What does Health Canada require for medical device cybersecurity?

Health Canada's guidance document Pre-market Requirements for Medical Device Cybersecurity, effective 26 June 2019, applies to medical devices that consist of or contain software. Its cybersecurity testing expectations name security requirements testing, threat mitigation assessment, vulnerability scanning and penetration testing, and its verification and validation expectations name known vulnerability assessment, malware testing, fuzz testing and structured penetration testing. Third-party software components attract a software bill of materials and documented vulnerability assessment, inside total product lifecycle security risk management rather than a single premarket gate.

What does a medical device penetration test actually scope?

Five surfaces. Embedded firmware and hardware interfaces, covering secure boot, signature verification, anti-rollback, debug interfaces and stored secrets. Wireless and radio interfaces, covering BLE pairing and bonding, Wi-Fi provisioning, NFC, cellular and proprietary protocols. Companion mobile applications, covering credential handling, local storage of health data and the trust placed in the device. Cloud backends and APIs, covering tenant isolation, object level authorization on device and patient identifiers, enrolment flows and update infrastructure. Clinician web portals, covering role separation and the business logic in prescribing, dosing and alerting workflows. The exploit path usually crosses a boundary between two of them, which is why they should be tested as one estate.

How much does medical device penetration testing cost in 2026?

Cost tracks scope. A SaMD or clinician portal web application with its APIs typically runs US$3,000 to US$15,000, a companion mobile application with backend APIs US$12,000 to US$30,000, and a full connected device covering firmware, wireless, mobile and cloud US$35,000 to US$90,000. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering exactly one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. Device programmes are quoted individually on the pricing page.

Does a Software as a Medical Device product need the same test as a physical device?

No, it needs the subset that applies. SaMD has no firmware and no radios, so the engagement collapses to the application, API, cloud and identity layers, plus the mobile client where one exists. The report specification does not change: an FDA reviewer reading a SaMD submission still wants tester independence, scope, duration, methods and results. Because SaMD ships continuously, a single annual snapshot ages faster than it does on a hardware product, which is why SaMD vendors often run a continuous programme alongside the submission-driven test.

How often should a device manufacturer run a penetration test?

There is no fixed statutory cadence. The premarket test is driven by the submission, and the postmarket obligation under section 524B(b) is continuous by nature: a plan to monitor, identify and address vulnerabilities and exploits in a reasonable time. In practice, manufacturers test before each submission, retest after any change that alters the attack surface such as a new radio, a new cloud service or an authentication change, and run a continuous programme against the cloud and portal layers, because those change weekly while the firmware changes annually.

0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X