LIVE FEED
CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response
Sunday, August 16, 2026 Issue #1  ·  Est. 2025
Independent brief for device makers
Free Resource Library

SOPs & Templates

Working documents for medical device cybersecurity, not slideware. Procedures, work instructions, and fill-in templates for risk assessment, threat modeling, SBOM, and postmarket vulnerability management. Register once with a work email and every file below unlocks.

Unlocked. Every document below is ready to download.

Medical Device Cybersecurity Program

The governing procedure the rest of the library hangs off of.

SOP Word · 812 KB

Medical Device Cybersecurity

The procedure that ties the whole program together: roles, lifecycle gates, and how security work maps to your design controls and risk management file.

🔒 Unlock to download ↓ Download Word

Cybersecurity Risk Assessment

Rate what a flaw would actually do to a patient, and decide what has to be fixed before release.

SOP Word · 786 KB

Cybersecurity Risk Assessment

How to run a security risk assessment on a device: scope the system, rate exploitability against patient harm, and decide what blocks release.

🔒 Unlock to download ↓ Download Word
Template Excel · 67 KB

Cybersecurity Risk Assessments

The worksheet that goes with the assessment procedure. Threats, scoring, and residual risk in one place a reviewer can follow.

🔒 Unlock to download ↓ Download Excel

Cybersecurity Risk Management

Plan the program up front, then show what you did at the end.

Template Word · 56 KB

Cybersecurity Risk Management Plan

A fill-in plan for how you will identify, evaluate, and control security risk across the product lifecycle.

🔒 Unlock to download ↓ Download Word
Template Word · 61 KB

Cybersecurity Risk Management Report

The end-of-project record of what you found, what you fixed, and the risk you accepted, ready for a submission or an auditor.

🔒 Unlock to download ↓ Download Word

Threat Modeling and Architectural Views

The part of a submission reviewers push back on most.

SOP Word · 92 KB

Threat Modeling and Architectural Views

A repeatable method for threat modeling, including the architectural views FDA expects and how to turn findings into requirements.

🔒 Unlock to download ↓ Download Word
Template Word · 115 KB

Threat Model and Architectural Views

Captures data flows, trust boundaries, and threats so the model reads the same way from one product to the next.

🔒 Unlock to download ↓ Download Word

Software Bill of Materials

Build an SBOM that answers the lifecycle questions, not just the component list.

Work Instruction Word · 45 KB

Software Bill of Materials

Step by step: what to include, how to handle third-party and open-source components, and where teams usually slip.

🔒 Unlock to download ↓ Download Word
Template Word · 39 KB

Software Bill of Materials Report

A report shell for presenting your SBOM and its analysis alongside a submission.

🔒 Unlock to download ↓ Download Word
Template Excel · 13 KB

Software Bill of Materials End of Support and Level of Support

Track end-of-support and level-of-support dates per component, so you can answer the questions reviewers now ask.

🔒 Unlock to download ↓ Download Excel

Vulnerability Management and Metrics

Prove the postmarket program is doing something.

Work Instruction Word · 41 KB

Vulnerability Metrics Tracking

How to run postmarket vulnerability monitoring: intake, triage, and the metrics that show the program works.

🔒 Unlock to download ↓ Download Word
Template Excel · 18 KB

Vulnerability Metrics Tracking

A tracker for vulnerabilities and their metrics, so postmarket reporting is a lookup instead of a scramble.

🔒 Unlock to download ↓ Download Excel

These templates are a starting point, not legal or regulatory advice. Adapt them to your quality system and your device. Provided free by MedDevice Cyber.

Questions & Answers

Are the SOPs and templates really free?

Yes. Register once with a work email and all 12 documents unlock, in editable Word and Excel formats. The same registration adds you to the daily brief, and you can unsubscribe anytime.

What does the library cover?

A governing medical device cybersecurity program SOP, cybersecurity risk assessment, risk management planning and reporting, threat modeling with the architectural views FDA expects, SBOM work instructions and report templates, and postmarket vulnerability metrics tracking.

Can we adapt the documents to our quality system?

That is the intent. They are working starting points written for device makers, meant to be edited into your QMS and your device context. They are a baseline, not legal or regulatory advice.