
Cyber-Physical Systems (CPS) Security
Helm
Vulnerability management platform for medical devices with automated SBOM and compliance reporting.
Helm Overview
What it does
Helm is a Software Bill of Materials (SBOM) vulnerability management platform that automates creation, analysis, and validation of software supply chain data to identify and remediate cybersecurity risks in medical device software components while meeting Food and Drug Administration (FDA) premarket submission requirements. Built by former FDA reviewers, Helm eliminates up to 95% of false positives generated by generic cybersecurity tools through AI-powered intelligence that detects affected technology stacks and medical device-specific exploitability analysis, enabling engineering teams to focus on vulnerabilities that pose real risk to patient safety rather than investigating thousands of irrelevant alerts.
How it works
The platform integrates into development pipelines to automate SBOM ingestion and vulnerability detection at every build phase, continuously monitoring software components against Exploit Prediction Scoring System (EPSS), Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV), ExploitDB, Metasploit, National Vulnerability Database (NVD), and Common Weakness Enumeration (CWE) Top 25 databases while providing bulk rescoring across product versions, automated remediation workflows with short-term mitigations and upgrade paths, and rule-based compliance automation including alias rules for consistent component matching and lifecycle rules for End of Support/End of Life metadata management.
Credentials and traction
MedCrypt was named a Representative Vendor in the 2025 Gartner Market Guide for Medical Device Risk Management Platforms, and appeared on Becker's Hospital Review "116 Healthcare Cybersecurity Companies to Know" list in 2025. It was recognized in the 2023 Cybersecurity Excellence Awards for vulnerability management. Helm is used by three of the top five medical device manufacturers, serving engineering and product security teams responsible for FDA premarket cybersecurity submissions.
Key Capabilities
mapped to solution categoriesGenerates or ingests machine-readable SBOMs for medical devices (CycloneDX, SPDX) covering commercial, open-source and off-the-shelf components, and keeps them current per device model and software version. Serves a manufacturer documenting its own device portfolio for premarket submissions and postmarket management, and a healthcare provider tracking component vulnerabilities across the devices it operates. Required of cyber devices by FD&C Act section 524B and expected under EU MDR.
Assembles the cybersecurity documentation a premarket submission needs (security risk management report, threat model, security architecture views, SBOM, a cybersecurity management plan with vulnerability monitoring sources and patch release timelines, and labeling) in the structure the FDA premarket cybersecurity guidance and FD&C Act section 524B expect, and maps the same evidence to EU MDR cybersecurity requirements for devices sold in Europe.
Continuously rechecks the components in a manufacturer's device SBOMs against vulnerability and exploit intelligence (the NVD, EPSS, the CISA Known Exploited Vulnerabilities catalog and exploit databases), records an exploitability decision for each finding in the context of the device, and produces VEX and vulnerability disclosure report (VDR) documents that evidence the postmarket vulnerability monitoring plan FD&C Act section 524B requires of cyber devices and that EU MDR post-market surveillance expects.
Records the support level and end-of-support date of every software component in a device SBOM (actively maintained, no longer maintained, abandoned) and checks them against the years the device is expected to stay on the market, so a manufacturer can supply the per-component support information a premarket submission needs and plan replacements before a component loses support during the device lifetime.
Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.
Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.
Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.
Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.
Tracks the support level and end-of-support date of each SBOM component, flagging components that will lose security maintenance while the product is still on the market. Covers the two per-component elements FDA premarket cybersecurity guidance requires beyond the NTIA baseline.
Searches the organization-wide SBOM inventory by component, version or CVE and returns the affected products, projects and environments, so a newly disclosed vulnerability or a suspect package can be traced to everywhere it ships.
Normalizes ingested SBOMs to the CISA minimum elements by resolving missing or inaccurate component identifiers such as PURL and CPE and dependency relationships, and enriches components with license, supplier and support metadata, so SBOMs from any generator can be analyzed for third-party risk consistently.
Integrations
compatible toolsImplementation & support
Info last updated on September 8, 2026
Buyers
Start a shortlist with Helm
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.