Integration across the company’s product lifecycle to help meet evolving regulatory standards and improve security
Jerusalem, Israel, May 20, 2025 – C2A Security today announced a multi-year enterprise agreement with Elekta, a global leader in precision radiation therapy, to enhance Elekta’s cybersecurity posture across its device and software portfolio while ensuring compliance with global regulations such as ISO 14971, the EU Cyber Resilience Act (CRA), NTIA, AAMI TIR57 and FDA guidelines.
Elekta will employ C2A Security’s AI-powered, context-driven product security orchestration platform, EVSec, to perform dynamic threat modeling, generate compliance reports, manage SBOMs, and identify, prioritize, and respond to software vulnerabilities through a context-driven, AI-based approach, from pre-market to post-market surveillance.
“With increased digitalization in healthcare and heightened regulatory focus on product cybersecurity, medical device manufacturers must ensure both clinical efficacy and cyber resiliency,” said Roy Fridman, CEO of C2A Security. “We are thrilled to partner with Elekta, a company known for both clinical innovation and deep commitment to patient safety and believe our platform’s versatility and robustness make it a perfect fit. With EVSec, Elekta will be able to scale their product security operations, automate compliance, and conduct context-driven risk management without sacrificing product innovation and time to market.”

“As healthcare cybersecurity becomes a focal point for regulators, the ability to continuously assess, monitor, and prove compliance is essential,” says John Chenoweth, Chief Product Security Officer of Elekta. “At Elekta, we’re committed to providing safe, resilient solutions to our customers. Our collaboration with C2A Security will enable us to integrate cybersecurity throughout our product portfolio, helping us meet compliance requirements while keeping our systems secure.”
C2A Security provides a contextualized product security platform tailored for cyber-physical systems and companies with software-defined products. The company’s EVSec Platform automates cybersecurity and enables cross-functional sharing and collaboration between teams, customers, and supply chains while offering full digital twin capabilities of the product. Its seamless integration with existing DevOps and CI/CD pipelines enables development and security teams to collaborate in real time, making security a native part of the product development process, saving costs while improving product security and competitiveness.