Medical Device Cybersecurity Tools
Browser-based tools we built from our consulting work — CVSS v3.1 and v4.0 vulnerability scoring and a CycloneDX VEX generator. Free, no account, and everything runs locally in your browser.
What these tools are
Each tool is free, adapted from the same rubrics and standards we use on engagements, and runs entirely client-side — nothing you enter is transmitted or stored. They speed up a specific task; they don't replace a full risk-management program.
CVSS 3.1 Vulnerability Scoring
Score medical device vulnerabilities with CVSS v3.1 base metrics, or a guided questionnaire adapted from MITRE’s "Rubric for Applying CVSS to Medical Devices."
Who it's forTeams that need consistent, defensible severity ratings for FDA submissions and post-market reports.
- Standard CVSS v3.1 base-metric calculator, or guided MITRE-rubric mode
- CVE lookup via the NVD and CISA KEV Database
- Score internal findings without a CVE
- Build a findings table and export it to CSV
CVSS 4.0 Vulnerability Scoring
Score vulnerabilities with CVSS v4.0: direct base metrics, a guided v4.0 rubric, a v3.1-to-v4.0 converter, and an AI-assisted score generator.
Who it's forTeams adopting CVSS v4.0 ahead of the July 2028 FDA transition, or re-scoring an existing v3.x library.
- Direct v4.0 base-metric entry, or a guided v4.0 rubric
- CVE lookup via the NVD and CISA KEV Database
- Convert an existing CVSS v3.1 vector to v4.0 via vector mapping
- AI-assisted v4.0 score from a v3.1 vector and vulnerability description, draft for analyst review
- Build a findings table and export it to CSV
VEX Generator
Produce standards-compliant VEX (Vulnerability Exploitability eXchange) documents in CycloneDX format through a guided wizard.
Who it's forManufacturers communicating, in post-market, whether a known CVE actually affects their product.
- Guided step-by-step wizard
- Supports single or multiple products
- CVE lookup through NVD and CISA KEV Database
- Option to add rationale and remediation recommendation
- Schema-validated, machine-readable CycloneDX JSON output
- Human-readable HTML / PDF report
Everything runs in your browser — nothing you enter is transmitted to Aktriva or stored. These tools are decision-support aids only: their output does not by itself satisfy FDA, EU MDR, or other regulatory obligations, and should be interpreted in the context of your device's full risk assessment.
When you need this run as a program
The tools help with a task in isolation. Turning their output into submission-ready documentation and a repeatable process is what our services do.
- CVSS scoring (v3.1 and v4.0)Vulnerability severity scoring, used in both pre-market and post-market.Security by Design Services · Post-Market Services · Penetration Testing & Exploitability Validation
- VEX GeneratorA post-market vulnerability-communication artifact.Post-Market Services
