CREST Penetration Testing
Expert CREST-accredited penetration testing for digital health, defence, robotics, AI platforms, SaMD, and critical business systems. We deliver bespoke security solutions that safeguard your technologies and help you meet tough regulatory and compliance standards.
Our Clients
Trusted by essential services, critical suppliers and organisations across health, technology and digital services.
Professional vulnerability assessment and security testing
Our CREST certified penetration testing services help identify security vulnerabilities before malicious actors can exploit them. We simulate real-world attacks to strengthen your defenses and protect your critical systems and data.
Ensuring Security Through Penetration Testing
Our Penetration testing is customisable to fit the specific needs and requirements for digital health organisations, which makes it a valuable tool to identify and mitigate vulnerabilities in your computer systems, networks, and web applications.
LEADING TESTERS
Our penetration testing services provide comprehensive assessments for business, digital health and medical devices to identify and address potential security risks.
TAILORED SOLUTIONS
We offer customised penetration testing solutions to meet the unique needs of digital health organisations. We meet standards such as FDA, EUMDR and more.
How It Works
Comprehensive cybersecurity testing for medical devices, Software as Medical Device (SaMD), and healthcare systems to ensure patient safety, regulatory compliance, and data protection.
FDA & EU MDR Compliance
Meet FDA cybersecurity guidance and EU MDR requirements with comprehensive penetration testing that addresses IEC 62304, IEC TR 60601-4-5:2021, and MDCG 2021-5 Rev.1 standards for medical device cybersecurity.
Patient Safety & Data Protection
Protect patient health information (PHI) and ensure medical device functionality cannot be compromised by cyberattacks. Identify vulnerabilities that could impact patient care or expose sensitive healthcare data.
Software as Medical Device (SaMD) Testing
Specialized penetration testing for SaMD applications, mobile health apps, and cloud-based medical software. Ensure your digital therapeutics and diagnostic software meet cybersecurity requirements.
ISO 14971 Risk Management
Integrate cybersecurity risk assessment into your ISO 14971 risk management process. Identify, analyze, and mitigate security risks throughout the medical device lifecycle.
Faster Market Access & Approval
Accelerate FDA 510(k) submissions and CE marking processes with comprehensive cybersecurity documentation. Demonstrate proactive security measures to regulatory bodies.
IoMT & Connected Device Security
Secure Internet of Medical Things (IoMT) devices, wearables, and connected medical equipment. Test network communications, device authentication, and data transmission security.
Specialised Medical Device Testing
Medical Device Categories
SaMD & Digital Health
FDA
Cybersecurity in Medical Devices
EU MDR
European Medical Device Regulation
IEC 62304
Medical Device Software
ISO 14971
Risk Management
Services
WE HAVE A VARIETY OF SERVICES SPECIFIC TO ENSURING THE SECURITY OF YOUR MEDICAL DEVICES.
CREST accreditation means Periculo's testers and methodology are independently vetted against a recognised industry standard, so you get consistent, audit-ready results rather than an unregulated freelance test. It's increasingly requested by NHS trusts, MDR notified bodies, and enterprise procurement teams as proof of testing quality.
FDA premarket cybersecurity guidance and EU MDR both expect documented, competent security testing, and CREST accreditation is one of the clearest ways to demonstrate that competence to a notified body or auditor. It isn't always a strict legal requirement, but it significantly de-risks your regulatory submission.
Medical device testing has to account for constrained hardware, real-time operating requirements, and patient safety implications that a standard web or network pentest doesn't consider. Periculo's approach combines CREST-standard methodology with medical-device-specific test cases covering firmware, wireless interfaces, and clinical workflow integrity.
Most regulators and NHS DSPT guidance expect testing at least annually, and additionally after any significant software or firmware change. Devices handling patient data or connected to hospital networks should be tested more frequently given the higher risk profile.
A SaMD-focused test examines the application layer, API security, data storage and transmission, and authentication controls, alongside the clinical safety impact of any vulnerability found. Periculo maps findings directly to ISO 13485 and IEC 62304 requirements so results feed straight into your technical file.
Timelines depend on scope, but a typical medical device or SaMD engagement runs two to four weeks from scoping call to final report, including retesting of any critical findings. Periculo provides a scoping call upfront to give an accurate timeline for your specific system.
You receive a full report ranked by severity and clinical risk, with remediation guidance for each finding, and Periculo offers a free retest of critical and high issues once fixed. This closes the loop for regulatory evidence that vulnerabilities were identified and resolved, not just found.
Periculo combines CREST accreditation with specialist medical device and digital health expertise, so findings are reported in the language your MDR notified body, NHS DSPT assessor, or FDA reviewer expects to see. Generic providers can find the same bugs but rarely frame them for healthcare regulatory context.

