Medcrypt Security Intelligence is the compliance platform your device runs on: build the premarket documentation, check it against what FDA actually flags, then keep it current for as long as the device is on the market. Software, SBOM and vulnerability management, and a standing advisory retainer with our former FDA reviewers, in one subscription.
Only need SBOM and vulnerability management? Helm is available on its own. Talk to an expert to discuss pricing.
Readiness check
Free
See where your cybersecurity documentation actually stands before you commit to anything. A scored gap report across the domains FDA reviews, in about ten minutes.
Run the free readiness checkMSI
$35,000 per product line / year
The full compliance platform for one product line, plus 15 hours a year with our regulatory experts. Premarket documentation, submission audit, SBOM and vulnerability management, and postmarket monitoring that continues after you clear.
Penetration testing available as a scoped add-on.
Talk to an expertEnterprise
Custom
For manufacturers covering multiple product lines or business units. Volume pricing per product line, portfolio-level visibility, your own internal requirements layered alongside ours, and deployment options that satisfy your AI governance policy.
Talk to an expert| Compare in detail | Readiness checkFree | MSI$35,000 / product line / yr | EnterpriseCustom |
|---|---|---|---|
| Platform | |||
| Product lines covered | — | 1 | Multiple |
| Free readiness check | |||
| Users | Unlimited | Unlimited | Unlimited |
| Check your work | |||
| eSTAR readiness check | |||
| Cybersecurity maturity assessment | Basic | Full | Full |
| FDA submission audit | — | ||
| Gap assessment report | — | ||
| Deficiency letter (AINN) response | — | ||
| Build it right | |||
| Guided threat modeling | — | ||
| Cybersecurity risk assessment | — | ||
| Requirements workbench | — | ||
| Regulatory intelligence search | — | ||
| Document generation | — | Beta | Beta |
| Postmarket | |||
| Helm SBOM and vulnerability management | — | ||
| Continuous vulnerability monitoring | — | ||
| MedISAO membership | — | ||
| Expert services | |||
| Expert advisory hours | — | 15 hrs / year included | Custom volume |
| Penetration testing | — | Add-on | Add-on, custom scope |
| Additional advisory hours | — | Add-on | Add-on |
| Expert submission review | — | Add-on | Add-on |
| Deficiency response support | — | Add-on | Add-on |
| Enterprise controls | |||
| Portfolio compliance dashboard | — | — | |
| Custom requirements layer | — | — | |
| Configure your own model | — | — | |
| Self-hosted deployment | — | — | |
| SSO / SAML | — | — |
Pricing FAQs
One product line on the MSI platform for a year, with unlimited users. That covers the premarket modules (threat modeling, risk assessment, requirements, submission audit, deficiency response), regulatory intelligence, the postmarket side (Helm for SBOM and vulnerability management, continuous monitoring, MedISAO membership), and 15 hours a year with our regulatory experts. Annual term, invoiced annually.
No. Most customers add a penetration test because their submission needs one, which brings a typical first-year contract to somewhere between $50,000 and $60,000. But if you already have a pen test partner, or don't need one, the platform is $35,000 on its own.
Because compliance work scales with devices, not headcount. A regulatory lead and three engineers working the same submission shouldn't cost more than one person doing it alone. Add as many users as you need.
It's the one add-on, scoped to the device. A single-purpose embedded device and a connected imaging platform with a web interface are different tests, and pricing them the same would mean overcharging one and under-testing the other. We contract and manage the test through vetted partners, and you get the scope and the price in writing before anything is signed.
Because the honest answer depends on your device. We'd rather scope it properly in a 30-minute call than publish a number that turns out to be wrong for you in either direction.
For most teams working a single submission, yes. That's why it's the standard allocation rather than something you have to negotiate. Teams responding to a deficiency letter usually want more up front, and additional hours are available. The free readiness check will tell both of us roughly where you'll land before anyone commits.
Some customers keep their existing scanner and use MSI for everything around it: the submission audit, threat modeling, the risk assessment, and the deficiency response. Helm is included either way, and most teams consolidate once they see the SBOM feeding the same submission the rest of their documentation lives in.
It's live and customers use it, but the drafts it produces need expert review before they go in a submission. We'd rather say that here than have you find out later.
FDA is what the platform covers today. EU MDR, Health Canada, PMDA, and NMPA content are in active development on a shared requirements layer. Ask us where a specific market stands.
The subscription continues and the work shifts rather than stops. New vulnerabilities land in your components, your SBOM has to stay current, monitoring and disclosure obligations run for as long as the device is on the market, and EU MDR expects an annual cadence. The same threat models and risk assessments you built for the submission become the things you maintain, in the place you already built them.
Yes, and it's a common starting point. Run a legacy device through the platform and you get an honest read on where its documentation and vulnerability posture actually stand, which is usually the input to deciding whether to update it, keep supporting it, or plan its retirement.
Run the free readiness check and see your gaps scored against what FDA actually reviews. No commitment, no call required. If you'd rather talk it through with someone who used to review these submissions, we can do that instead.