Rubric for Applying CVSS to Medical Devices

The United States Food and Drug Administration (FDA), under its Medical Device Development Tool (MDDT) program, has recently (as of October 20, 2020) qualified a cybersecurity MDDT that includes a series of structured questions to be used along with the Common Vulnerability Scoring System (CVSS) v3.0 to reliably calculate the severity of security vulnerabilities in medical devices and aid in vulnerability disclosure. See the following links for more details: Deep Armor's blog on the Rubric for CVSS and Official Guidance Document from MITRE

Deep Armor has developed this online calculator for using the rubric, recording the answers to the extended vector elements, and presenting the CVSS score and vector.

