Medical device penetration testing: compare offers and prices
By The PenTest Index · Sources checked October 9, 2026
Medical device penetration testing is a hands-on attack on your device and everything it connects to (firmware, radios, apps and cloud) to show what an attacker could do. Buy the test that names every part in writing. One specialist publishes $30,000 to $55,000 for a typical Class II connected device. Most firms only quote, and FDA's guidance asks for the original report.
Below: which kind of test fits you, five offers side by side, and a brief you can send so every quote answers the same question.
Which test fits your product?
Start with what you make and why you need the test. These are different purchases.
| Your situation | Start here | What could change it |
|---|---|---|
| You make a connected physical device | A device test covering hardware, firmware, radios, apps and cloud | An earlier test may already cover some parts. Check its scope and versions first |
| Your product is software only (often called SaMD, software as a medical device) | An app, API and cloud test, with the report items FDA lists | Don't pay for hardware work your product doesn't have |
| You run devices in a hospital | A review of how the device sits on your network, with separately approved device testing if needed | The maker's own security papers may already answer your question. Jump to the hospital section |
| One finding or one missed interface needs checking | A narrow test or a retest | It doesn't replace a full test when you need one |
| You already have a security team or pentest vendor | Run them through the report check | Buy only what's missing |
These are our suggested routes. They don't decide whether your product is a regulated device or whether a submission will be accepted.
Already know your scope? Compare the offers.
Which offers deserve a closer look?
Shortlist by what each offer says it covers, then get the real scope in writing. The same company can sell a one-interface test, a full device test and an ongoing platform as three separate things.
We read each provider's own pages on October 9, 2026. Everything below is what the provider publishes. We have not bought these services or read a delivered report. Companies are A to Z within each group. This is not a ranking.
Testing services
| Offer | What the provider says it covers | Published price (US dollars) and conditions | Still open |
|---|---|---|---|
| Blue Goat Cyber, medical device penetration testing | Mostly manual testing of hardware, firmware, radios, companion app, APIs and cloud. Report plus a signed attestation letter | From $15,000 for one interface, assuming a simple device, a reasonable timeline and no travel. $30,000 to $55,000 for a typical Class II connected device. $55,000 to $95,000+ for large platforms. The page says "Ranges are typical, not quotes." Stated timing: 3 to 5 weeks for most jobs, 6 to 8 for large ones | Retest is worded two ways on the same page: "unlimited re-tests of fixed issues inside the fixed fee" and "retesting of every high and critical finding." Ask which applies |
| MedSec, medical device penetration testing | Embedded systems, firmware, web and mobile apps, APIs, wireless, hardware interfaces, update mechanisms and cloud. Says its reports are built to be submitted as the original third-party report | No price, timeline or retest terms on the page we read | Price, dates, retest terms, who is assigned |
| Secureworks, Medical Device Test | Network services, hardware and debug ports. Firmware is reverse engineered if testers obtain it during the test. The size row we could read: "Small: 1 medical device." You get one week to comment on the report | No price or retest terms on the page. This catalog route uses Service Units and requires an existing or simultaneous purchase of Taegis MDR, Elite Threat Hunting, Taegis MDR Essentials or Taegis MDR Enhanced | Whether your app and cloud are included, how to order, retest terms. A comment period is not a retest |
| UL Solutions, Medical Device Penetration Testing Services | Threat model analysis, vulnerability scanning and binary analysis, security-control testing, protocol analysis, cryptographic testing | No price, timeline, retest or report terms on the page | Everything project-specific |
View Blue Goat Cyber's device testing offer
View MedSec's device testing service
Read Secureworks' Medical Device Test description
View UL Solutions' medical device testing
A platform subscription with testing added on
| Offer | What you are buying | Published price (US dollars) and conditions | Still open |
|---|---|---|---|
| Medcrypt, MSI platform plus a penetration test add-on | A yearly security platform with 15 advisory hours. The test is an add-on. Medcrypt says "We contract and manage the test through vetted partners" | $35,000 per product line, per year, annual term, invoiced annually. The test costs extra, and its price is given in writing before you sign. Medcrypt says adding a test brings "a typical first-year contract to somewhere between $50,000 and $60,000" | Who does the testing, the test's own price and scope, retest terms |
Review Medcrypt's platform and testing terms
Two prices here are not two quotes for the same thing. Blue Goat's range is for a test. Medcrypt's figure is for a year of platform, with a test on top. Don't average them, and don't treat either as the market rate.
Our read, using one example device
Say you make a wearable heart monitor. It has firmware, Bluetooth, one phone app, a cloud API and over-the-air updates. You want one test, not a subscription. Your engineers expect fixes to be ready six weeks after the report, including medium-severity ones. This device is made up.
For that buyer, we would ask Blue Goat Cyber and MedSec for full-device proposals. Both publish coverage that matches this kind of product. Add UL Solutions if you already work with them on other product testing. If you already have a Secureworks agreement, ask them before buying anywhere new. Medcrypt belongs on the list only if you also want the platform.
That is a reason to ask for proposals. It is not approval of any provider. Here is how each offer does against the example's must-haves:
| Offer checked against | Finding | Send this question |
|---|---|---|
| Blue Goat's from-$15,000 single-interface offer, against "test the whole device" | Mismatch. It covers one interface. This device has five parts | "Please quote the full list of parts, not the single-interface scope." |
| Blue Goat's connected-device offer, against "retest medium fixes at week six" | Unresolved. The two retest wordings don't settle severity or deadline | "Does the fixed fee cover retesting every fixed finding, including medium, on a new build six weeks after the report?" |
| MedSec, against "covers these parts" | Supported, for shortlisting. Its published list names each part. Price and retest are unknown | "Please map our parts list to your scope and name the testers." |
| Secureworks Small, against "test the whole device" | Unresolved. One device is stated. App and cloud are not named | "Does this order include our app, API and update service?" |
| UL Solutions, against "test the whole device" | Unresolved. Capabilities are listed. Your scope is not | "Please name each part you will test and the report we receive." |
| Medcrypt platform alone, against "one test, no subscription" | Mismatch. The platform is a yearly commitment and the test is extra | "Can we buy the test without the annual platform?" |
"Supported" means that one condition is backed by what the provider published. It says nothing about test quality, and a written proposal can change any finding.
What should medical device penetration testing include?
It should include every way data gets into or out of your product, each one named in the quote. "One device" on a price sheet does not tell you whether the app or the cloud is covered.
Fill this in before you talk to anyone. It turns your product into a list a provider can price.
| Part | What to write down | Question that makes quotes comparable |
|---|---|---|
| Device and firmware (the software running on the device) | Hardware revision, firmware build, service and debug ports | Which versions and ports are tested? Do you assume we hand over the firmware? |
| Radios and cables | Bluetooth, Wi-Fi, cellular, USB, anything else the product really uses | Which are tested, and with what limits? |
| Apps | Each phone, desktop or browser app | Is each one included or priced separately? |
| APIs and cloud | Versions, user roles, customer accounts | Do you test whether one role or customer can reach another's data? |
| Updates and recovery | How updates reach the device and how it recovers from a bad one | Is the update path in scope? |
| Connections to other systems | Hospital records systems, other devices | Which are covered, and who can approve testing them? |
| Test units | How many, how they differ from the release version, whether one can be destroyed | Will the report state limits caused by the units we supplied? |
A vulnerability scan is not the same purchase. A scan is a tool checking for known flaws. A penetration test is people trying to break in. FDA's guidance lists them as separate kinds of testing. More on that difference in penetration testing vs vulnerability scanning.
Copy a brief that asks every provider the same question
Send one brief to each firm and their answers line up. Send five different emails and you get five quotes for five different jobs.
Copy this into your own document and fill in the brackets. If you don't know something, write "unknown." That is a useful answer.
Medical device penetration testing brief
Why and for whom: We need testing for [submission / release / customer request]. The report will go to [FDA / notified body / hospital customer / internal]. Our regulatory lead has identified [pathway, or unknown].
Product: [Name], hardware revision [ ], firmware or software build [ ]. Our test units differ from the release version in these ways: [ ].
Parts in scope: [device hardware and ports], [firmware], [radios and wired interfaces], [apps], [APIs and roles], [cloud], [update path], [connections to other systems]. Mark each one in, out with a reason, or unknown.
What we can give you: [number of test units], [firmware or source code], [architecture diagram], [threat model], [software bill of materials], [test accounts], [test environment]. Tell us what is missing and how it limits the test.
Test conditions: Location [ ]. Shipping or on-site needs [ ]. Physical work allowed on units [ ]. When to stop [ ]. No devices connected to patients and no live patient data are in this scope.
Team and report: Name the testers, their device experience and how they are independent of our developers. Describe the full report: scope, dates, methods, tested versions, findings with evidence, and limits.
Dates: Earliest start, days of testing, first findings, report date, and updated report date after retest.
Retest: Which findings and builds qualify, how many rounds, the deadline and what starts it, any added fee, and how the report is updated.
Full cost: Itemize the test, any required platform or advisory fee, travel, hardware, retest and extra reporting. State currency, minimum term, billing dates and renewal.
What we already have: [earlier reports, current vendor, internal testing]. Tell us what can be reused.
Please send back: scope by part, exclusions, team, a redacted sample report from a similar job, a dated schedule and an itemized quote.
This brief is for buying. It is not permission to test. Testing needs a separate signed agreement covering the exact targets and activities.
Still working out the general questions, like who needs the report and by when? Find My PenTest Match is our free scope checklist. You can copy or print it, and it asks for no contact details. It is a general checklist: it does not list device testing firms, so use the brief above for the device details.
Does the FDA require a penetration test?
FDA's guidance recommends one, and for covered cyber-device submissions, the law requires you to show the device is reasonably secure. Those are two different sources, and vendor pages often blur them.
The current guidance is Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, final, issued February 3, 2026. It replaced the June 27, 2025 edition. Every page is headed "Contains Nonbinding Recommendations," and the guidance says "should" means recommended, not required. The binding part is section 524B of the FD&C Act. As FDA quotes it, sponsors of covered premarket submissions for a "cyber device" must submit a plan for handling vulnerabilities after launch, keep processes that give "reasonable assurance that the device and related systems are cybersecure," and provide a software bill of materials. Penetration testing is not named in those quoted duties.
Think of the guidance as the inspector's written advice and the statute as the building code. You can do it another way, but you still have to meet the code. In practice, plan to include a test.
We read the testing section (V.C) of the guidance PDF on October 9, 2026 and set it beside what you will hear while shopping:
| What you'll hear | What the FDA text says | What to do with it |
|---|---|---|
| "FDA requires penetration testing" | FDA "recommends" four kinds of security testing "be considered for inclusion": security requirements, threat mitigation, vulnerability testing and penetration testing | Plan for it. Don't buy anything sold as "FDA-approved." FDA doesn't approve tests or testers |
| "We recommend white-box testing for medical devices, and so does the FDA" (Blue Goat Cyber's service page) | The testing section does not use the words white box, gray box or black box. It does list "closed box testing of known vulnerability scanning" as one item under vulnerability testing | Treat it as the vendor's advice. It may be good advice. Ask what access each quote assumes |
| "Ten required testing activities" (Blue Goat Cyber's blog, June 2, 2026) | Four kinds of testing. Vulnerability testing has sub-items. All of it is "should" | The list is real. "Required" is the vendor's word |
| "Actual tester-days, not calendar duration" (same blog) | The text says only "Duration of testing" | Still worth asking for both dates and days |
| "It has to be an outside firm" | "In some cases it may be necessary to use third parties." The report should say who tested and how independent they were from the developers | An independent internal team is named as an option |
| "A summary letter is enough" | "For any third-party test reports, manufacturers should provide the original third-party report" | Plan to submit the full report |
Two more points from the same guidance:
What counts as a cyber device? All three must be true: it includes software validated, installed, or authorized by the sponsor as a device or in a device; it can connect to the internet; and it has features validated, installed, or authorized by the sponsor that could be open to cyber threats. FDA reads "can connect" widely. Its examples include Wi-Fi, Bluetooth, USB and serial ports. And the guidance as a whole is not limited to networked devices. Your regulatory lead should make this call, not a vendor's quiz.
How often after launch? FDA says testing should happen "at regular intervals commensurate with the risk (e.g., annually)." Annually is its example, not a fixed rule.
FDA decides what is enough for your submission. No test report guarantees clearance. For the edition history and what changed in 2026, see our FDA cybersecurity guidance tracker.
Selling into Europe too? Agree the evidence with your regulatory team and notified body. The EU's device cybersecurity guidance is MDCG 2019-16. We did not review it for this page, so don't assume an FDA-shaped report covers it.
What should the report show?
FDA's guidance says a penetration test report should include five things. Agree on them before testing starts, and check a sample report for them before you sign.
| FDA's five items (Section V.C) | Ask the firm | Look for in the sample report |
|---|---|---|
| Independence and technical expertise of testers | "Who will test, what device work have they done, and how are they separate from our developers?" | Named testers and an independence statement |
| Scope of testing | "List every part you will test and every part you won't." | An in-scope and out-of-scope list by part and version |
| Duration of testing | "What dates, and how many days of work?" | Dates and effort stated |
| Testing methods employed | "Which methods and tools, for which part?" | Named methods and tools |
| Test results, findings and observations | "Do findings include evidence and steps to reproduce? Are retest results added?" | Evidence for each finding and its status after retest |
Two jobs stay with you, whoever you hire. The guidance asks the manufacturer for its own assessment of every finding, including why any fix was put off. For fixes pushed to a later release, it asks for a plan with timing.
This check also answers "can our current vendor do it?" If they can show device work in a sample report and cover these five items, you may not need a new firm.
Want an outside view of good practice? The industry group MDIC has published a five-step approach to device penetration testing: scoping, choosing a supplier, running the test, deciding what to do about findings, and reporting. MDIC asks for your details before you can download the full paper. For general report quality, see how to assess a penetration test report.
How much does it cost, and what changes the quote?
Two providers publish numbers, and they price different things. Blue Goat Cyber lists from $15,000 for one interface, $30,000 to $55,000 for a typical Class II connected device and $55,000 to $95,000 or more for large platforms. Medcrypt lists $35,000 per product line per year for its platform, with the test on top. The other three quote on request. All checked October 9, 2026.
You will meet four kinds of price. Keep them apart:
- A starting price: the least you could pay, with conditions. Blue Goat's $15,000 assumes a simple device, a reasonable timeline and no travel.
- A range: one firm's guide for a type of job, not a promise.
- A quote: a price for your scope. This is the only one you can sign.
- A subscription: a yearly fee for something bigger than a test.
Blue Goat says these things move its price: how many interfaces are in scope, whether source code and a threat model (a written list of likely attacks and defenses) are available, how many units can be tested to destruction, and how complex the cloud side is.
Before comparing totals, make sure each quote settles the same six lines:
| Line | What must be in writing |
|---|---|
| The test itself | Parts, versions, methods, days of work |
| Access and logistics | Test units, firmware or source, shipping, travel |
| Extra systems | Any added app, API, customer account or connection |
| Reporting | Full report, walkthrough call, updated report |
| After the report | Retest terms, and help answering FDA questions if you want it |
| Commitment | Currency, payment dates, minimum term, anything that renews |
A missing line is not a zero. It is an unknown, and the total isn't finished until it's filled in.
One more promise to read carefully. Blue Goat states: "If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost." Its terms limit that promise to cybersecurity deficiencies in its own deliverables. It is not a promise FDA will accept anything. Ask whether it applies if you buy only the test.
For how pentest pricing works in general, see penetration testing cost. Holding two quotes already? Compare scope and retest terms before price, using our quote comparison guide.
Which retest terms need to be in writing?
Four things: which fixes qualify, how many rounds, the deadline, and what starts the clock. "Retest included" on its own tells you none of them.
A retest means the testers check that your fixes worked. Here is why wording matters. If the fee covers "every high and critical finding," a medium-severity finding you fixed may not get checked. If it covers "fixed issues," it may. Ask this:
"Is retest of every fixed finding, at every severity, included in the fee? Until what date, and is that the date to request it or to finish it?"
When should you start?
Count back from the day you need the finished report, and include time to fix what the testers find.
Here is a made-up example. Say you plan to submit on June 1, 2027. A firm states up to 5 weeks for the test. You allow 4 weeks for fixes, 1 week for retest and 2 weeks of slack. That is 5 + 4 + 1 + 2 = 12 weeks, so testing starts by about March 9, 2027. The 5 weeks is Blue Goat's stated upper figure for most jobs. The other numbers are ours, for illustration. Some steps can overlap, so your real plan may be shorter.
A stated testing time is not a booked start date. Ask each firm for its earliest confirmed start and its report date, in writing.
Testing a device in a hospital?
Start with the question you need answered, and agree safe conditions before anyone touches a device. Hospital testers worry about knocking over equipment in clinical use, and they are right to.
- Gather the model, version and the maker's security papers. Ask the maker for its MDS2 form for your exact product and version. MDS2 is a standard disclosure form published by NEMA, in which makers describe a device's security features.
- Decide what is still unanswered after reading them.
- If hands-on testing is needed, use a spare unit on a separate network.
- Put approval, limits, monitoring and who can call a stop in writing.
A general network pentest agreement does not automatically cover medical devices. Never test a device connected to a patient. And a maker's product test doesn't prove every hospital setup is safe.
How we checked
We compare specific offers against stated buying needs and show our sources. For this page we read FDA's guidance and each provider's public pages on October 9, 2026. We did not buy a test, talk to these providers or read a delivered report. The example device is made up. We don't perform, authorize or certify testing. Read how we check offers and how we make money.
Sources, all checked October 9, 2026
- FDA guidance page: edition, date, status
- FDA guidance PDF: Sections I to VII.C.1, including the testing section V.C
- Blue Goat Cyber, medical device penetration testing: scope, prices, timing, retest wording
- Blue Goat Cyber, FDA penetration testing requirements and cost article: claims quoted above
- Medcrypt pricing: platform price, term, testing add-on
- MedSec, medical device penetration testing: coverage and report statements
- Secureworks, Medical Device Test: scope, size row, report review period
- UL Solutions, medical device penetration testing services: listed services
- MDIC, medical device penetration testing: five-step approach