Skip to main content
    Penetration Testing
    Pen Testing · 2026

    Penetration Testing in 2026

    Device, network, wireless, and protocol penetration testing for medical devices - what to scope, who to trust, and how to report it.

    FDA expects penetration testing as part of a credible cybersecurity submission, but the quality of pen tests varies wildly. These episodes cover scoping device pen tests, hardware and firmware analysis, wireless and Bluetooth attacks, web and API testing for cloud companions, and how to translate findings into evidence reviewers will accept. Hosted by practitioners who break devices for a living.

    This page rounds up every Penetration Testing conversation we've published in 2026 on The Med Device Cyber Podcast. Each episode pairs an experienced practitioner - a regulator, a startup founder, a security researcher, or a quality lead - with our hosts, who've personally led FDA premarket and postmarket cybersecurity submissions for connected medical devices. The result is a working library of frameworks, war stories, and reviewer-tested patterns you can apply to your own 510(k), De Novo, or PMA program.

    Use the 2026 archive below to get a sense of how pen testing expectations are evolving this year - what the FDA is asking for in deficiency letters, which engineering practices the field is converging on, and where reasonable people still disagree. If you want a longer-running view, browse the full Penetration Testing topic page for every episode we've ever published on the subject, or jump to the complete 2026 catalog to see what else aired alongside these episodes.