Section 524B made cybersecurity a premarket requirement for every cyber device. These are the companies that do the testing, the SBOMs, the threat models and the postmarket monitoring for device makers who do not have a security team.
Sunnyvale, CA · Unknown
Provides asset discovery and risk management for IoMT, IoT and OT devices, including vulnerability prioritization, device patching and segmentation orchestration. Founded by Shankar Somasundaram, who previously ran IoT security at Symantec.
Scottsdale, AZ · Est. 2014 · Bootstrapped
Consultancy that handles premarket cybersecurity for device makers: penetration testing of hardware, firmware, apps and cloud, plus threat modeling, SBOMs and the documentation that goes into 510(k), De Novo and PMA submissions. Founded by Christian Espinosa.
Boston, MA · Unknown
Runs a risk management network that health systems use to assess vendors, products and medical devices, covering third-party, enterprise and AI governance risk. The vendor catalog covers tens of thousands of products, so device makers are assessed through it.
New York, NY · Est. 2017 · Unknown
Runs a platform that inventories connected medical and IoT devices on hospital networks, then tracks their vulnerabilities, flags threats and supports network segmentation. Customers include RWJBarnabas Health and several NHS trusts.
Columbus, OH · Est. 2017 · Unknown
Analyzes device firmware and binaries to generate SBOMs and find vulnerabilities, and automates the security evidence manufacturers file for FDA and other regulators. Serves medical device, automotive, energy and industrial makers.
Solana Beach, CA · Est. 2016 · Series B · $36.4M raised
Sells software and services that medical device manufacturers use to handle product security: SBOM and vulnerability management through Helm, encryption and key management through Guardian, plus threat modeling and premarket submission support.
Fort Lauderdale, FL · Unknown
Provides device cybersecurity services across the product lifecycle: threat modeling, penetration testing, SBOMs, vulnerability scanning and postmarket plans for regulatory submissions. In March 2026 it launched BRIDGE, a platform for passing security advisories from manufacturers to hospitals. Led by CEO Michelle Jump.
Unknown
Sells embedded runtime protection and observability for connected devices, using integrity verification built into device firmware rather than a network agent. Medtronic is a named customer.