generated: '2026-09-13' method: searched source: https://www.hologic.com/support/usa/breast-skeletal-products-cybersecurity note: >- Hologic publishes no trust center in the SaaS sense — there is no trust.hologic.com, no SOC 2 / ISO 27001 report request portal, and no compliance-document download gateway. Probed https://www.hologic.com/trust (404), /security (404), /cybersecurity (404) and /product-security (404); 0-working/probe-security-programs.py likewise returned trust=none. What stands in its place is a product-security hub scoped to the Breast & Skeletal Health division, which is where a medical device buyer's security review actually lands. trust_center: exists: false equivalent: name: Breast & Skeletal Products Cybersecurity url: https://www.hologic.com/support/usa/breast-skeletal-products-cybersecurity http_status: 200 scope: Breast and Skeletal Health division products only — not company-wide. contents: - Coordinated Vulnerability Disclosure Policy - MDS2 security disclosure forms, per product (36 linked) - Cybersecurity reports and best-practice guides, per product - Validated Microsoft monthly critical patch releases - Antivirus installation and configuration guides - Dated security advisories for third-party CVEs affecting Hologic products certifications: named_publicly: [] note: >- No SOC 2, ISO 27001, ISO 13485, PCI DSS, HIPAA attestation or FedRAMP authorization is named on any public Hologic page reached by this pass. Regulatory posture is expressed instead as FDA 510(k) clearance and CE marking per device, and as per-product MDS2 forms. Absence here is a publication finding, not a claim that Hologic holds no certifications. probes: - url: https://www.hologic.com/trust status: 404 - url: https://www.hologic.com/security status: 404 - url: https://www.hologic.com/cybersecurity status: 404 - url: https://www.hologic.com/product-security status: 404 - url: https://www.hologic.com/support/usa/breast-skeletal-products-cybersecurity status: 200