i.

Scoping

SCOPING

We identify the product, target countries for regulatory approval, and required test items, then prepare a Test Plan.

1~2 weeks
ii.

Threat Modeling

THREAT MODELING

We identify assets, entry points, and threats based on STRIDE, and finalize the scope of testing.

1 week
iii.

Testing

TESTING

We conduct vulnerability assessment, penetration testing, fuzzing, and SAST/DAST concurrently. Real-time test status sharing.

2~4 weeks
iv.

Reporting

REPORTING

We prepare test reports mapped to each standard, SBOM, VEX, and threat modeling deliverables.

1~2 weeks
v.

Submission

SUBMISSION

We support Q&A on security documentation for FDA, MFDS, and EU regulatory submissions.

Ongoing