---
title: "Total Product Lifecycle: The Framing That Fixes Most…"
description: "Optimize MedTech submissions and device security by adopting a Total Product Lifecycle approach, integrating cybersecurity from design to decommissioning…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Total Product Lifecycle: The Framing That Fixes Most MedTech Submissions | Christian Espinosa",
      "description": "Optimize MedTech submissions and device security by adopting a Total Product Lifecycle approach, integrating cybersecurity from design to decommissioning…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/611ebc93-61f4-4bfd-b2a4-c642033f3154/total-product-lifecycle-the-framing-that-fixes-most-submissions-card.png",
      "datePublished": "2026-01-22T14:00:00Z",
      "dateModified": "2026-01-22T14:00:00Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/total-product-lifecycle-the-framing-that-fixes-most-submissions"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Total Product Lifecycle: The Framing That Fixes Most Submissions\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity isn't a phase. It's the design"
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        },
        {
          "@type": "Question",
          "name": "How does this connect to From the upcoming book?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Medical Device Cybersecurity: An In-Depth Guide; a chapter-by-chapter walkthrough of premarket submissions and postmarket surveillance, written for engineers, regulatory teams, and founders who'd rather not learn this the hard way. If the post landed, that is the natural next step; the preview the book link at the bottom of the page goes straight there."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Total Product Lifecycle: The Framing That Fixes Most Submissions

January 22, 2026 4 min read 852 words 

Cybersecurity isn't a phase. It's the design

![](/__l5e/assets-v1/a867b45b-fe2c-4ba0-9681-3ff8c54569cb/total-product-lifecycle-the-framing-that-fixes-most-submissions-hero.webp)

Published

January 22, 2026

Read time

4 min

In this essay

1.  [01 What TPLC Actually Means ](#what-tplc-actually-means)
2.  [02 The Two Shapes A Program Takes ](#the-two-shapes-a-program-takes)
3.  [03 What This Looks Like In A Submission ](#what-this-looks-like-in-a-submission)
4.  [04 The Cheap Way To Adopt It ](#the-cheap-way-to-adopt-it)

Jump to

1.  [01 What TPLC Actually Means ](#what-tplc-actually-means)
2.  [02 The Two Shapes A Program Takes ](#the-two-shapes-a-program-takes)
3.  [03 What This Looks Like In A Submission ](#what-this-looks-like-in-a-submission)
4.  [04 The Cheap Way To Adopt It ](#the-cheap-way-to-adopt-it)

The takeaways

1.  01 
    
    MedTech cybersecurity requires a Total Product Lifecycle approach, addressing threats from design to decommissioning, not just for submission.
    
    What to do next Add product to the next leadership review as a standing item, not a one-time slide.
    
2.  02 
    
    Integrate cybersecurity into every development stage, including threat modeling, secure coding, and SBOM generation as a build artifact.
    
    What to do next Open your current threat plan today and identify the one gap you would not want an auditor to find.
    
3.  03 
    
    Verification should involve penetration testing, vulnerability scanning, and fuzz testing, all aligned with a comprehensive threat model.
    
    What to do next Ask your security lead this week for the one-page view of penetration in your environment, and read it end to end.
    
4.  04 
    
    A strong premarket submission demonstrates a complete security story with verifiable evidence throughout the product's lifecycle.
    
    What to do next Pause for five minutes today, then name the one place in your week where premarket is playing out and you have been avoiding naming it.
    
5.  05 
    
    Postmarket activities like vulnerability disclosure, monitoring, patching, and SBOM updates are crucial for sustained device security.
    
    What to do next Add postmarket to the next leadership review as a standing item, not a one-time slide.
    

Editor's note

Adapted from Chapter 3 of Medical Device Cybersecurity: An In-Depth Guide. The TPLC framing is what unifies every other chapter; risk management, SPDF, threat modeling, SBOM, testing, postmarket. Once a team internalizes the lifecycle as the unit of work (instead of the submission), the rest of the program reorganizes itself.

Most of the deficiency letters I see start with the same gap: a security program built for the submission, not the device.

The FDA's framing is Total Product Lifecycle (TPLC) for a reason. A medical device is in the field for years. Threats evolve. Third-party components age out. Operating systems go end-of-life. Vulnerabilities get disclosed.

If your cybersecurity work ended the day I filed, my device is already drifting.

## What TPLC Actually Means

TPLC is not a section of the submission. It is the operating model that produces every section of the submission, and then keeps producing evidence after the device is on the market. The same engineering discipline runs from concept to decommissioning:

**Design.** Threat modeling, security requirements, architecture views; all derived from the intended use and the clinical risk, not bolted on once the design is frozen. Security requirements live in the same requirements management system as everything else, traceable to risk and to verification.

**Development.** Secure coding, third-party component analysis, SBOM generation as a build artifact (not a deliverable you scramble to produce later). The build pipeline emits the SBOM, the static analysis results, and the dependency provenance the same way it emits the binary.

**Verification.** Penetration testing, vulnerability scanning, and fuzz testing scoped to the threat model, not a checkbox at the end. Every test maps back to a threat. Every uncovered finding maps forward to a mitigation or an accepted risk with a justification a reviewer can follow.

**Premarket submission.** The story of all of the above, told with the evidence to back it. The submission is not the work; it is the readable artifact of work that already happened.

**Postmarket.** Coordinated vulnerability disclosure, monitoring, patching, SBOM updates, communication with users. The boring, expensive, durable part; and the part FDA is most consistently sharpening expectations around.

**End of support.** A plan for what happens when the device is still in clinical use after the company has moved on. Most manufacturers haven't thought about this. Reviewers are starting to.

## The Two Shapes A Program Takes

In practice, every program we walk into is one of two shapes.

The first shape is submission-shaped. There is a deadline. There is a scramble. Threat models, SBOMs, and architecture views are produced in the final months, by a small team, working backward from a design that is already locked. The submission goes out, deficiencies come back, and the team patches the document rather than the device. Postmarket happens to whoever has the bandwidth.

The second shape is lifecycle-shaped. The same artifacts exist, but they were generated as a side effect of how the team works week to week. The threat model is in version control alongside the design. The SBOM is regenerated on every build. Architecture views are updated when the architecture changes, not when a regulatory filing is opened. Postmarket monitoring is a real process owned by a real person, not a folder somebody promises to check.

The second shape costs less over the life of the device. It is also the only shape that actually scales to a second product.

## What This Looks Like In A Submission

Reviewers can tell which shape your program is in within the first few pages.

A lifecycle-shaped submission reads as one coherent system. The intended use statement, the risk file, the threat model, the architecture view, the SBOM, the verification report, and the postmarket plan all reference the same components, the same boundaries, the same data flows. When the reviewer drills into any one of those documents, the others corroborate it.

A submission-shaped submission contradicts itself. The architecture view shows three trust zones; the threat model only addresses two. The SBOM lists components the architecture view does not depict. The postmarket plan promises monitoring for a service the verification report did not test. Each individual artifact may be defensible. Together they look like a system nobody fully owns.

That contradiction is what produces most of the deficiency letters that follow.

## The Cheap Way To Adopt It

You do not need a reorganization to start working this way. You need three habits.

First, put the threat model and the architecture view under version control next to the design, and require an update whenever the design changes. Not at submission time. When the design changes.

First-class artifacts beat documentation drives every time.

Second, make the SBOM a build output, not a deliverable. If a human can edit it, it is already wrong. Wire it into CI, sign it, store it, and treat the latest build's SBOM as the source of truth.

Third, name a single owner for postmarket. Not a committee. One person whose job includes watching CVEs against the SBOM, triaging, and deciding what reaches a patch and what reaches a customer communication. Postmarket dies without a name on it.

The teams that operate this way file fewer times, get cleaner clearances, and have fewer postmarket fires. Not because they're spending more. Because they're spending in the right order.

The lifecycle isn't a documentation exercise. It's the design philosophy that makes everything else possible.

> “If your cybersecurity work ended the day you filed, your device is already drifting.”

Frequently asked

### What is the core idea behind "Total Product Lifecycle: The Framing That Fixes Most Submissions"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### How does this connect to From the upcoming book?

### From the upcoming book

Medical Device Cybersecurity: An In-Depth Guide; a chapter-by-chapter walkthrough of premarket submissions and postmarket surveillance, written for engineers, regulatory teams, and founders who'd rather not learn this the hard way.

[Preview the book](/books/medical-device-cybersecurity)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftotal-product-lifecycle-the-framing-that-fixes-most-submissions&text=Total%20Product%20Lifecycle%3A%20The%20Framing%20That%20Fixes%20Most%20Submissions) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftotal-product-lifecycle-the-framing-that-fixes-most-submissions) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftotal-product-lifecycle-the-framing-that-fixes-most-submissions) [Email](mailto:?subject=Total%20Product%20Lifecycle%3A%20The%20Framing%20That%20Fixes%20Most%20Submissions&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Ftotal-product-lifecycle-the-framing-that-fixes-most-submissions)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.

Keep reading

-   [
    
    ### Why Postmarket Cybersecurity Is Where MedTech Actually Fails
    
    The lifecycle gap, made concrete. What goes wrong when premarket effort doesn't translate into postmarket discipline.
    
    Read essay → ](/blog/why-postmarket-cybersecurity-is-where-medtech-actually-fails)
-   [
    
    ### Threat Modeling Is the Work. Everything Else Is the Receipt.
    
    The TPLC's highest-use practice. Where the design philosophy actually meets the engineering work.
    
    Read essay → ](/blog/threat-modeling-is-the-work-everything-else-is-the-receipt)

[← Previous essay 

Threat Modeling Is the Work. Everything Else Is the Receipt. | Christian Espinosa

](/blog/threat-modeling-is-the-work-everything-else-is-the-receipt)[Next essay → 

FDA Premarket Cybersecurity: What the 2026 Guidance Actually Requires | Christian Espinosa

](/blog/fda-premarket-cybersecurity-what-the-2026-guidance-actually-requires)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)