Compliance & Regulation

What happens when the FDA flags a cybersecurity deficiency

An Additional Information letter with cybersecurity deficiencies is not a rejection. It's a structured list of what the FDA's reviewers could not verify, and it starts a clock: 180 calendar days to respond, after which the submission is withdrawn automatically. What happens inside that window depends less on how bad the letter looks and more on whether your evidence exists and agrees with itself.

What the AI letter contains

When a submission includes cybersecurity documentation (an SBOM, threat model, risk assessment, testing reports), the FDA's cybersecurity team reviews it in detail, and deficiencies come back organized by type or by eSTAR section. The same items appear over and over:

  • A threat model that never defines assets, interfaces, or attack vectors
  • A Cybersecurity Risk Management Plan that is missing, or outdated against lifecycle expectations
  • A risk assessment that fails to tie vulnerabilities and mitigations to patient safety or essential performance
  • A missing Cybersecurity Risk Management Report on control effectiveness
  • Testing reports (penetration testing, vulnerability scanning, fuzzing) that are thin or untraceable to risk controls
  • Missing cybersecurity views: architecture, data flow, system-level representations
  • An SBOM with no vulnerability assessment behind it, or residual risk carrying no justification

Each of these is explicitly referenced in the eSTAR template and expected in any 510(k), De Novo, or PMA involving software or connectivity. None of them should surprise anyone in 2025. Most still do.

The clock, and the exit ramps

The 180-day window has to absorb everything: new testing, documentation rework, internal review, and the response itself. Miss it and the submission is withdrawn automatically, and you refile from the back of the queue.

If a deficiency reads as unclear, duplicative, or contrary to feedback the agency already gave you, don't guess. A Submission Issue Request through the Q-Submission process asks the FDA to clarify or reconsider a specific item, and the agency typically answers in writing within 21 days. I've watched teams burn two months of their window reworking a deliverable the reviewer never asked them to rework. A SIR spends three weeks to prevent exactly that.

The 180-day response windowSubmission incybersecurity reviewAI letter issuedday 0 · deficiencies listed180 calendar days to respondtesting · rework · clarificationResponse filedreview resumesNo responseautomatic withdrawalSubmission Issue RequestQ-Sub · written answer in ~21 daysunclear or duplicative item?ask before you rework
The letter starts a fixed clock. A SIR spends three weeks to avoid wasting months; silence forfeits the submission.

Why deficiencies happen at all

Read enough AI letters and the pattern is hard to miss. Submissions rarely stall because one document is weak. They stall because documents disagree: the threat model describes interfaces the architecture views never show, or the risk assessment scores vulnerabilities the SBOM doesn't list. Reviewers cross-examine, and the seams are where deficiencies come from.

Reviewers don't grade documents in isolation. They cross-examine them against each other.

That's the failure mode ELTON was built against. The digital twin gives every deliverable the same source. Architecture views generated from the model become the cybersecurity views eSTAR asks for. The threat model sits on those same components and interfaces. Every vulnerability carries a CVSS score and a written justification traceable to the release it affects, using a rubric the FDA recognized through the MDDT program. And the testing evidence (SAST, DAST, fuzzing, pentest-class testing run against the real device) lands in the same record, tied to the same architecture.

A response package built that way agrees with itself because it was never assembled from separate sources in the first place. Across 1,000+ FDA submissions, that internal consistency is what makes second-round questions rare.

After the letter closes

The deficiencies the FDA flags premarket are the same capabilities it expects to keep running postmarket. The monitoring that produced your response evidence is the operational form of the Cybersecurity Risk Management Plan the reviewer asked about. Stand it up properly for the response, and the postmarket obligation is already running the day the submission clears.

A deficiency letter feels like a verdict. It's closer to a checklist, written by someone who will read your answer skeptically. The manufacturers who respond fastest aren't the ones with the best writers. They're the ones whose evidence already existed before anyone asked.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about an FDA cybersecurity deficiency.

How long do you have to respond to an FDA deficiency letter?

180 calendar days. An Additional Information letter is not a rejection, it is a structured list of what the FDA's reviewers could not verify, and it starts a fixed clock. Miss the window and the submission is withdrawn automatically, which means refiling from the back of the queue.

Which cybersecurity deficiencies come up most often?

A threat model that never defines assets, interfaces or attack vectors. A missing or outdated Cybersecurity Risk Management Plan. A risk assessment that does not tie vulnerabilities and mitigations to patient safety or essential performance. Testing reports that are thin or untraceable to risk controls. An SBOM with no vulnerability assessment behind it.

What do you do if a deficiency looks unclear or contradictory?

File a Submission Issue Request through the Q-Submission process. It asks the FDA to clarify or reconsider a specific item, and the agency typically answers in writing within 21 days. Three weeks on a SIR is cheaper than two months reworking a deliverable the reviewer never asked you to rework.

Which submissions get cybersecurity deficiency review?

Any 510(k), De Novo or PMA involving software or connectivity. When a submission includes cybersecurity documentation, the FDA's cybersecurity team reviews it in detail and returns deficiencies organized by type or by eSTAR section, and every item is explicitly referenced in the eSTAR template.

Does the response work help after the submission clears?

Yes. The deficiencies the FDA flags premarket are the same capabilities it expects to keep running postmarket. The monitoring that produced your response evidence is the operational form of the Cybersecurity Risk Management Plan the reviewer asked about, so the postmarket obligation is already running on day one.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON