Compliance & Regulation

What happens when the FDA flags a cybersecurity deficiency

An Additional Information letter with cybersecurity deficiencies is not a rejection. It's a structured list of what the FDA's reviewers could not verify, and it starts a clock: 180 calendar days to respond, after which the submission is withdrawn automatically. What happens inside that window depends less on how bad the letter looks and more on whether your evidence exists and agrees with itself.

What the AI letter contains

When a submission includes cybersecurity documentation (an SBOM, threat model, risk assessment, testing reports), the FDA's cybersecurity team reviews it in detail, and deficiencies come back organized by type or by eSTAR section. The same items appear over and over:

  • A threat model that never defines assets, interfaces, or attack vectors
  • A Cybersecurity Risk Management Plan that is missing, or outdated against lifecycle expectations
  • A risk assessment that fails to tie vulnerabilities and mitigations to patient safety or essential performance
  • A missing Cybersecurity Risk Management Report on control effectiveness
  • Testing reports (penetration testing, vulnerability scanning, fuzzing) that are thin or untraceable to risk controls
  • Missing cybersecurity views: architecture, data flow, system-level representations
  • An SBOM with no vulnerability assessment behind it, or residual risk carrying no justification

Each of these is explicitly referenced in the eSTAR template and expected in any 510(k), De Novo, or PMA involving software or connectivity. None of them should surprise anyone in 2025. Most still do.

The clock, and the exit ramps

The 180-day window has to absorb everything: new testing, documentation rework, internal review, and the response itself. Miss it and the submission is withdrawn automatically, and you refile from the back of the queue.

If a deficiency reads as unclear, duplicative, or contrary to feedback the agency already gave you, don't guess. A Submission Issue Request through the Q-Submission process asks the FDA to clarify or reconsider a specific item, and the agency typically answers in writing within 21 days. I've watched teams burn two months of their window reworking a deliverable the reviewer never asked them to rework. A SIR spends three weeks to prevent exactly that.

The 180-day response windowSubmission incybersecurity reviewAI letter issuedday 0 · deficiencies listed180 calendar days to respondtesting · rework · clarificationResponse filedreview resumesNo responseautomatic withdrawalSubmission Issue RequestQ-Sub · written answer in ~21 daysunclear or duplicative item?ask before you rework
The letter starts a fixed clock. A SIR spends three weeks to avoid wasting months; silence forfeits the submission.

Why deficiencies happen at all

Read enough AI letters and the pattern is hard to miss. Submissions rarely stall because one document is weak. They stall because documents disagree: the threat model describes interfaces the architecture views never show, or the risk assessment scores vulnerabilities the SBOM doesn't list. Reviewers cross-examine, and the seams are where deficiencies come from.

Reviewers don't grade documents in isolation. They cross-examine them against each other.

That's the failure mode ELTON was built against. The digital twin gives every deliverable the same source. Architecture views generated from the model become the cybersecurity views eSTAR asks for. The threat model sits on those same components and interfaces. Every vulnerability carries a CVSS score and a written justification traceable to the release it affects, using a rubric the FDA recognized through the MDDT program. And the testing evidence (SAST, DAST, fuzzing, pentest-class testing run against the real device) lands in the same record, tied to the same architecture.

A response package built that way agrees with itself because it was never assembled from separate sources in the first place. Across 600+ regulatory submissions, that internal consistency is what makes second-round questions rare.

After the letter closes

The deficiencies the FDA flags premarket are the same capabilities it expects to keep running postmarket. The monitoring that produced your response evidence is the operational form of the Cybersecurity Risk Management Plan the reviewer asked about. Stand it up properly for the response, and the postmarket obligation is already running the day the submission clears.

A deficiency letter feels like a verdict. It's closer to a checklist, written by someone who will read your answer skeptically. The manufacturers who respond fastest aren't the ones with the best writers. They're the ones whose evidence already existed before anyone asked.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo