Compliance & Regulation

What eSTAR requires in 2026

With the FDA's final cybersecurity guidance in full effect and QMSR aligned to ISO 13485 taking hold in February 2026, cyber-device submissions face the most rigorous cybersecurity requirements to date. If your device is a cyber device under Section 524B, your premarket submission carries a specific set of documentation through eSTAR.

The nine eSTAR cybersecurity deliverablesCybersecurity Management PlanSecurity Architecture ViewsThreat ModelCybersecurity Risk AssessmentAssessment of Unresolved AnomaliesCybersecurity MetricsCybersecurity ControlsSoftware Interoperability V&VVulnerability & Patch Management
Nine deliverables, each of which has to agree with the others.

The trap is not any single document. It is consistency. Your threat model, your architecture views, your SBOM-driven risk assessment, and your controls all have to tell the same story about the same device. Conflicting documentation is what draws deficiency questions, and in the worst case, outright rejection.

A submission does not fail because one document is weak. It fails because the documents disagree.

The fix is a single source of truth for architecture, findings, and dispositions, so every deliverable is generated from the same model instead of assembled by hand across teams and spreadsheets.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about eSTAR cybersecurity requirements in 2026.

What cybersecurity documents does eSTAR require in 2026?

Nine deliverables: a Cybersecurity Management Plan, Security Architecture Views, a Threat Model, a Cybersecurity Risk Assessment, an Assessment of Unresolved Anomalies, Cybersecurity Metrics, Cybersecurity Controls, Software Interoperability verification and validation, and Vulnerability and Patch Management. If your device is a cyber device under Section 524B, the premarket submission carries all of them.

Why are 2026 submissions more demanding than earlier ones?

The FDA's final cybersecurity guidance is in full effect and QMSR aligned to ISO 13485 takes hold in February 2026, so cyber-device submissions now face the most rigorous cybersecurity requirements to date. The documentation set did not just grow, the scrutiny applied to it grew with it.

What causes eSTAR cybersecurity deficiency questions?

Inconsistency, not weakness. A submission does not fail because one document is weak. It fails because the documents disagree. The threat model, the architecture views, the SBOM-driven risk assessment and the controls all have to tell the same story about the same device.

How do you keep nine eSTAR deliverables consistent with each other?

Generate them from a single source of truth for architecture, findings and dispositions rather than assembling them by hand across teams and spreadsheets. Documents produced from one model of the device cannot contradict each other, and contradiction is what draws deficiency questions and, at worst, rejection.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON