Security Stack Logo
Helm logo

Cyber-Physical Systems (CPS) Security

Helm

Vulnerability management platform for medical devices with automated SBOM and compliance reporting.

Helm Overview

What it does

Helm is a Software Bill of Materials (SBOM) vulnerability management platform that automates creation, analysis, and validation of software supply chain data to identify and remediate cybersecurity risks in medical device software components while meeting Food and Drug Administration (FDA) premarket submission requirements. Built by former FDA reviewers, Helm eliminates up to 95% of false positives generated by generic cybersecurity tools through AI-powered intelligence that detects affected technology stacks and medical device-specific exploitability analysis, enabling engineering teams to focus on vulnerabilities that pose real risk to patient safety rather than investigating thousands of irrelevant alerts.

How it works

The platform integrates into development pipelines to automate SBOM ingestion and vulnerability detection at every build phase, continuously monitoring software components against Exploit Prediction Scoring System (EPSS), Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV), ExploitDB, Metasploit, National Vulnerability Database (NVD), and Common Weakness Enumeration (CWE) Top 25 databases while providing bulk rescoring across product versions, automated remediation workflows with short-term mitigations and upgrade paths, and rule-based compliance automation including alias rules for consistent component matching and lifecycle rules for End of Support/End of Life metadata management.

Credentials and traction

MedCrypt was named a Representative Vendor in the 2025 Gartner Market Guide for Medical Device Risk Management Platforms, and appeared on Becker's Hospital Review "116 Healthcare Cybersecurity Companies to Know" list in 2025. It was recognized in the 2023 Cybersecurity Excellence Awards for vulnerability management. Helm is used by three of the top five medical device manufacturers, serving engineering and product security teams responsible for FDA premarket cybersecurity submissions.

Key Capabilities

mapped to solution categories
Medical Device Security

Generates or ingests machine-readable SBOMs for medical devices (CycloneDX, SPDX) covering commercial, open-source and off-the-shelf components, and keeps them current per device model and software version. Serves a manufacturer documenting its own device portfolio for premarket submissions and postmarket management, and a healthcare provider tracking component vulnerabilities across the devices it operates. Required of cyber devices by FD&C Act section 524B and expected under EU MDR.

Assembles the cybersecurity documentation a premarket submission needs (security risk management report, threat model, security architecture views, SBOM, a cybersecurity management plan with vulnerability monitoring sources and patch release timelines, and labeling) in the structure the FDA premarket cybersecurity guidance and FD&C Act section 524B expect, and maps the same evidence to EU MDR cybersecurity requirements for devices sold in Europe.

Continuously rechecks the components in a manufacturer's device SBOMs against vulnerability and exploit intelligence (the NVD, EPSS, the CISA Known Exploited Vulnerabilities catalog and exploit databases), records an exploitability decision for each finding in the context of the device, and produces VEX and vulnerability disclosure report (VDR) documents that evidence the postmarket vulnerability monitoring plan FD&C Act section 524B requires of cyber devices and that EU MDR post-market surveillance expects.

Records the support level and end-of-support date of every software component in a device SBOM (actively maintained, no longer maintained, abandoned) and checks them against the years the device is expected to stay on the market, so a manufacturer can supply the per-component support information a premarket submission needs and plan replacements before a component loses support during the device lifetime.

SBOM Management

Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.

Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.

Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.

Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.

Tracks the support level and end-of-support date of each SBOM component, flagging components that will lose security maintenance while the product is still on the market. Covers the two per-component elements FDA premarket cybersecurity guidance requires beyond the NTIA baseline.

Searches the organization-wide SBOM inventory by component, version or CVE and returns the affected products, projects and environments, so a newly disclosed vulnerability or a suspect package can be traced to everywhere it ships.

Normalizes ingested SBOMs to the CISA minimum elements by resolving missing or inaccurate component identifiers such as PURL and CPE and dependency relationships, and enriches components with license, supplier and support metadata, so SBOMs from any generator can be analyzed for third-party risk consistently.

Integrations

compatible tools
Azure DevOpsGitHub Actions

Implementation & support

Deployment model
Agentless (API Integration)SaaS
Support channels
Documentation

Info last updated on September 8, 2026

Buyers

Start a shortlist with Helm

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.