Start with one product and one milestone. Inventory the evidence you already have, identify the decisions it supports, and give each unresolved gap an owner.
What should a readiness review answer?
A useful readiness review connects a business milestone to a bounded set of security questions. It should help an engineering or quality lead explain what is known, what remains uncertain, and which decisions need attention next.
Choose a product version, an intended environment, and a milestone. A broad request to assess every product and process is difficult to price, deliver, or act on. A specific release provides a more useful boundary.
Start with an evidence map
Make a working inventory with four columns: the security question, the available evidence, its owner, and the next decision. For example, a question about privileged access might connect an architecture diagram, an authentication design, and a test result. A policy alone does not establish how the product behaves.
- Gather system diagrams, data flows, and trust boundaries.
- Identify threat-model assumptions and unresolved risks.
- Locate the software inventory and vulnerability-handling process.
- Link security requirements to implementation and verification evidence.
- Record missing information separately from known technical weaknesses.
Keep the regulatory context in view
The FDA's February 2026 cybersecurity guidance addresses quality management system considerations and premarket submission content. Use the current guidance and determine which provisions apply to your device and submission with your regulatory lead. A readiness engagement can organize work toward that review; it does not establish FDA acceptance.
Turn gaps into decisions
For every gap, name an owner and the evidence that would resolve it. Distinguish work your team can complete from work requiring a specialist, such as a scoped penetration test. Agree on dependencies before promising a delivery date.
Our suggested output is a short decision log alongside the evidence map. Record the issue, the decision needed, the accountable person, and the expected next step. This gives the team something more useful than a long list of observations.
What belongs in the next engagement?
A readiness sprint produces a review and plan. Implementation, specialist testing, remediation verification, and full submission preparation need their own scope. Use the findings to select the next workstream and agree on its completion criteria.
Sources & further reading
This perspective offers practical planning guidance. Apply requirements to your specific product, systems, and responsibilities with the appropriate specialists.


