All whitepapers

Whitepaper · October 3, 2025

Healthcare CybersecurityJoint Security Plan (JSP)

Joint Security Plan (JSP) Quick Reference Guide: Who Does What, When, and Why

The JSP Quick Reference Guide helps medical device teams understand their role in building and maintaining a secure product. Using the cybersecurity house analogy, it simplifies complex regulatory requirements into four phases — Concept, Design & Development, Verification & Validation, and Maintenance — so everyone, from product managers to executives, can see where they fit and what’s expected of them.

Open whitepaper PDF
Thumbnail for Joint Security Plan (JSP) Quick Reference Guide: Who Does What, When, and Why

Executive summary

What this whitepaper covers

The Joint Security Plan (JSP) is the medical technology industry’s framework for embedding cybersecurity across the total product lifecycle. Medcrypt’s JSP Quick Reference Guide distills this comprehensive plan into a practical, shareable resource that helps teams understand who does what, when, and why in building secure medical devices. Using a simple “house” analogy — Foundation (Concept), Framing (Design & Development), Inspection (Verification & Validation), and Maintenance (Postmarket) — this guide makes it easy for product teams, executives, and service functions to align on their cybersecurity responsibilities and regulatory expectations.

Why it matters

The regulatory and product context

The JSP is the backbone of medical device cybersecurity, but many teams struggle to operationalize it. This guide bridges that gap, translating complex regulatory requirements into clear, actionable steps. As the FDA, HSCC, and AAMI continue to emphasize secure-by-design development and lifecycle traceability, understanding the JSP isn’t optional; it’s essential to achieving compliance, building resilient products, and fostering trust with hospitals and regulators.

Key insights

What you’ll take away

  • The JSP maps cybersecurity activities across all phases of product development.
  • Every function, from engineers to executives, plays a role in securing the product.
  • Clear documentation and evidence are essential for FDA and regulatory alignment.
  • Lifecycle management (SBOMs, patching, surveillance) is an ongoing responsibility.
  • The JSP complements standards like IEC 81001-5-1, offering a “what and why” overview alongside “how and when” resources.

Who should read this

  • Product Managers, Engineers, and QA/RA professionals responsible for lifecycle documentation
  • Executives and cybersecurity program leaders ensuring organizational readiness
  • Clinical and usability teams validating safety and workflow compatibility
  • Sales, marketing, and service teams who communicate security value to customers
Open PDF

Know where your submission stands this week.

Run the free check in about five minutes or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness
Exploded insulin pump showing its display enclosure, protective plate, control board, pump mechanism, insulin reservoir, and infusion-set tubing connection