Pharma & life sciences

FDA specifies what a penetration test report must contain. Cracken runs the test that fills it.

The portal, the cloud back end and the plant network behind a connected-device programme.

Authorised operations against the network-facing side of a connected-device programme: the portals that manage the devices, the cloud back end that receives their telemetry, and the lab and plant networks they sit on. Portal and directory findings are reproduced by a second operation before they are recorded.

Definition

What is fda premarket medical device penetration testing?

FDA premarket medical device penetration testing is the exploit-driven testing a manufacturer submits with a 510(k), De Novo, or PMA. The FDA guidance issued 3 February 2026 fixes the report contents: tester independence and expertise, scope, duration, methods, and results. Vulnerability scanning is a separate item in the same guidance and does not stand in for it.Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Final guidance, supersedes the 27 June 2025 edition, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)

Take the portal first

Runs injection, auth bypass, IDOR and file-upload attacks at the portal that manages the devices.

Follow the telemetry into the tenant

Turns a portal foothold into the role it can assume and the store of device and study data that role reads.

Reach the lab and plant network

Tests whether segmentation around validated lab and manufacturing systems holds — up to the network interface, not the controller.

Evidence in the form FDA lists

Scope, duration, methods and results come out of the operation ledger as the run happens. Independence stays your statement to make.

APT10 / Cloud Hopper (China MSS) — compromised managed service providers, then rode trusted access into client networks to steal intellectual property.

Cloud Hopper began at a service provider. Your side of that path is the side you can authorise.

APT10 broke managed service providers and rode their trusted access into client networks. Cracken runs the stages that sit inside your authorisation, and names the ones it does not run.

  1. 1Partner compromise
    Attacker

    Breaks your CRO, CDMO, or MSP first.

    With Cracken

    Not run. A partner's estate is a separate target that needs the partner's written authorisation and a scope of its own.

  2. 2Trusted pivot
    Attacker

    Rides the partner's connection into your network.

    With Cracken

    A Tentacle on an authorised host in the segment that access lands in maps which hosts answer and which paths leave it.

  3. 3Persistence and harvest
    Attacker

    Settles in and harvests credentials.

    With Cracken

    Enumerates the domain from an ordinary account and works the credential paths it implies.

  4. 4Collection
    Attacker

    Locates trial data, formulas, and device telemetry.

    With Cracken

    Cloud Pentest follows the foothold into the tenant and names the role it can assume and the store of device and study data that role reads.

  5. 5Exfiltration
    Attacker

    Moves the research out as ordinary traffic.

    With Cracken

    The run ends at the proven path and what it reaches.

One run

The portal, the cloud behind it, and the plant network are in reach.

A connected-device programme: one device management portal, the cloud account that receives its telemetry, and one internal segment. Domains, hostnames and principals are illustrative.

Written from the execution plan of the playbooks that run today — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest. A run covers the target you authorise, under the policy you set.

  1. 01
    What ran

    The Domain Recon playbook runs against the domains the programme publishes: passive DNS, certificate transparency, and host intelligence, merged into one asset set with provenance on every record. Nothing is sent to the target.

    T1590 Gather Victim Network Information
    What it established

    The public surface of the programme — subdomains, certificates, resolving hosts, and the open ports, services and known CVEs on each public IP, including the ones that never reached the asset register. A domain outside the realm allowlist stops the run.

  2. 02
    What ran

    One sub-operation per surface per attack class against the portal that manages the devices: injection, auth bypass, IDOR, file upload, API logic. Each candidate goes to a separate operation that starts in fresh context and tries to reproduce it.

    T1190 Exploit Public-Facing Application
    What it established

    Which exploits actually fire. A candidate is recorded only after an independent operation reproduces it and captures the signal. The rest are killed, with the reason written down.

  3. 03
    What ran

    The Cloud Pentest playbook works the account that receives device telemetry, starting from the access the portal foothold provides: identities, roles, trust relationships, and the storage the data lands in.

    T1078.004 Valid Accounts: Cloud Accounts
    What it established

    How far one web foothold reaches into the tenant — which role it can assume, and which bucket or database of device and study data that role can read.

  4. 04
    What ran

    A Tentacle is installed on an authorised host in the segment where the lab and manufacturing systems sit. From there: host discovery, service and version enumeration, a read of the firewall rules and ACLs meant to contain the segment, then an attempt to cross into the next one.

    T1046 Network Service Discovery
    What it established

    Whether segmentation holds in practice, and where the attempt was stopped. Every command, result and artifact lands in the operation ledger; hosts and the paths between them go to the Cybergraph, where technique edges carry their ATT&CK IDs.

  5. 05
    What ran

    The AD Pentest playbook enumerates the domain from an ordinary user account and works the credential paths that enumeration implies, toward the accounts that administer validated systems.

    T1087.002 Account Discovery: Domain Account
    What it established

    The shortest credential path from a standard account to systems under change control — reported as a proven path, or as attempts that returned no signal, which are written up separately from findings.

What this did not prove: No step touched device firmware, radio stacks, embedded controllers or a PLC on a line — this run was scoped to the portal, the cloud account behind it and one internal segment, and stopped at the device's network interface. The run fills the penetration-test section of a submission. It does not stand in for the security risk assessment around it.

MITRE ATT&CK v19.0, April 2026

A model that stops at "potentially exploitable" proves nothing.

Commercial models decline the offensive half of this work. Cracken's own research cut cyber refusal from 100% to 7% on a 1T-parameter model while explicit-content refusal held at 100%.

Fire the exploit, not the caveat

Injection, auth bypass, IDOR and file upload run against the authorised portal until one fires, and a separate operation in fresh context reproduces it before it is recorded.

Walk the credential path to the end

Enumeration from an ordinary domain account, then the credential paths that enumeration implies, up to the accounts that administer validated systems.

?

Push at the boundary, not at the ACL

The lab and plant segment is tested by attempting the crossing, not by reading the rule meant to prevent it.

The research and manufacturing estate is the least-tested part of the network. Test the path into it before someone else does.
Questions

What runs, how far it goes, and what the reviewer gets.

Does this produce the penetration test report FDA asks for in a premarket submission?

It produces most of what the guidance lists. FDA's guidance on cybersecurity in medical devices, issued 3 February 2026, states: "Penetration testing. · The testing should identify and characterize security-related issues via tests that focus on discovering and exploiting security vulnerabilities in the product. Penetration test reports should be provided and include the following elements: · Independence and technical expertise of testers; · Scope of testing; · Duration of testing; · Testing methods employed; and · Test results, findings, and observations." Scope, duration, methods, results and findings come out of the operation ledger as the run happens. Independence and technical expertise is a statement you make about who ran the test. FDA does not clear tools, and Cracken is not an accredited laboratory.Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Final guidance, supersedes the 27 June 2025 edition, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)

Can Cracken test the device itself?

Yes, across the programme the device sits in: the management and clinician portals under the Web App Pentest playbook, the cloud back end that receives telemetry under Cloud Pentest, the segment the devices and lab systems sit on under Network Pentest, and the directory that administers them under AD Pentest. Firmware, radio stacks and embedded controllers are covered by the OT/ICS and malware-research playbooks. Scope is fixed against a realm allowlist before anything runs.

Will it touch a GxP-validated system?

Only what you authorise, and only at the intrusiveness you set. Targets are fixed against a realm allowlist before anything runs, and a target outside it stops the run. Approval on each command is the default until you raise the ceiling. Every command, result and artifact lands in the operation ledger, so the record a change-control reviewer wants is written while the run happens rather than reconstructed afterwards. Where change control forbids testing the qualified system, the Tentacle goes on the qualified non-production replica and the same scope runs there.

Our CRO, CDMO or MSP connection is the real exposure. Can you test that?

Cracken tests your side of it. A Tentacle placed on an authorised host in the segment a partner's access lands in shows what that access actually reaches: which hosts answer, which credential path leads out of that segment, and where the boundary stopped the attempt. The partner's own estate is a separate target that needs the partner's written authorisation and a scope of its own. Cracken will not run against a system you cannot authorise.

What do we hand a reviewer or an auditor at the end?

The original report, not a summary of one. FDA's 3 February 2026 guidance states: "For any third-party test reports, manufacturers should provide the original third-party report. For all testing, manufacturers should provide their assessment of any findings including rationales for not implementing or deferring any findings". A Cracken run outputs that artifact: the scope, the commands, the captured signal, and each finding with the evidence of the operation that reproduced it, plus what could not be proven, named separately from what was. The assessment of the findings, and the rationale for anything you defer, stays yours to write.Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Cybersecurity Testing section, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)

You have no life-sciences customers. Why should we believe the model runs a real operation?

The evidence is published rather than asserted. The team's paper Red-Teaming the Agentic Red-Team reports: "Table 3 reports the attack success rate aggregated across the 10 agentic-red-teams. On average, code execution is achieved in 97.8% of runs." — alongside a security analysis spanning twelve agentic tools. Two public repositories are readable before you scope anything: Blacksea, an active honeypot for LLM-driven attackers, and RedLineBench, 153 grounded, single-turn offensive-security prompts scored on refusal and capability, where every target domain and public IP is a sinkhole Cracken owns.Red-Teaming the Agentic Red-Team (arXiv:2606.24496) (arXiv — Pasquini, Bazyli, Fedynyshyn, Sorokin, 2026-06-23)

If you run the operation

See the engine underneath this.

Tentacles, the Cybergraph, the approval gate every action passes through, and the operation ledger that records what ran. Pharma & life sciences is one playbook on top of that engine.

If you own the risk

Start from the exposure, not the technique.

One playbook answers one question. The case for validating exposure at all — why a scanner score is not a finding, and what changes when something proves the path instead of ranking it — is the argument this page assumes.

Take the portal, then the cloud behind it.

Scope a run against the network around your validated systems.