Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Blog · FDA

    Breakthrough Device Designation and Cybersecurity

    Breakthrough Device designation speeds FDA interaction but waives no cybersecurity requirement. Here is how Section 524B applies to Breakthrough devices in 2026.

    Abstract arrow of layered navy and cyan panels accelerating through regulatory gate frames around a shield silhouette
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Published: July 30, 2026

    Direct Answer

    Breakthrough Device designation does not change your cybersecurity obligations. The program gives you priority review, interactive sprint discussions, and senior FDA engagement, but Section 524B applies in full to any cyber device regardless of designation. You still owe a threat model, an SBOM, security testing evidence, and a postmarket vulnerability management plan, and an incomplete package can still trigger a Refuse to Accept decision.

    A designation letter feels like momentum. Teams get one and quietly assume the whole review will be more forgiving, cybersecurity included. It will not be.

    The Breakthrough Devices Program changes how fast and how often you talk to the FDA. It changes nothing about what a cyber device submission must contain. In practice the effect runs the other way: Breakthrough devices are disproportionately connected, novel, AI-enabled, or first-of-a-kind, and reviewers apply more scrutiny to architectures they have never seen before, not less.

    The real risk is scheduling. Priority review compresses your timeline. Cybersecurity work that would have hidden inside a twelve-month runway now sits on the critical path.

    Why this matters

    The Breakthrough Devices Program is statutory, created by Section 3051 of the 21st Century Cures Act and codified at Section 515B of the FD&C Act. Section 524B, added by the Consolidated Appropriations Act 2023 and effective March 29, 2023, is equally statutory and contains no carve-out for Breakthrough, priority, or expedited devices. Neither does the FDA's final premarket cybersecurity guidance of February 3, 2026, which supersedes the 2023 final guidance and sets the current expectations for Secure Product Development Framework evidence, threat modeling depth, SBOM contents, and labeling.

    That means two statutes run in parallel. One shortens your review clock. The other sets a content floor you must clear before the clock starts at all. Sponsors who treat designation as a reason to defer security work end up spending the time they saved on deficiency responses.

    What Breakthrough Device designation actually gives you

    The program is a set of interaction benefits, not a lowered evidence bar:

    Benefit What it means in practice
    Priority review Your submission moves to the front of the reviewer's queue
    Sprint discussions Time-boxed, topic-specific interactions to resolve a single question fast
    Senior management engagement Escalation path when a review question stalls
    Data development plan feedback Early alignment on what evidence you will generate
    Post-designation flexibility More willingness to accept postmarket data collection for clinical evidence

    Note what is absent: nothing about reduced content requirements, nothing about deferred testing, nothing about cybersecurity.

    Key requirement

    Section 524B(b) requires every cyber device sponsor to submit a plan to monitor and address postmarket vulnerabilities, design processes providing reasonable assurance of cybersecurity, a coordinated vulnerability disclosure process, and an SBOM. Designation status is irrelevant to all four.

    Does the Refuse to Accept policy apply to Breakthrough submissions?

    Yes. The FDA's Refuse to Accept policy for cyber devices under Section 524B applies at the acceptance-review stage, before substantive review begins, and before any Breakthrough priority benefit takes effect.

    This is the sequencing detail that surprises teams. Priority review affects your position in the substantive review queue. An RTA decision happens upstream of that queue entirely. A Breakthrough device with a missing SBOM or an absent postmarket plan gets held at the door like anything else, and the calendar advantage you were counting on disappears in the resubmission.

    Why Breakthrough devices often face harder cybersecurity review

    Designation criteria select for exactly the device characteristics that raise cybersecurity risk:

    • Novelty. Breakthrough devices are frequently first-of-a-kind. There is no predicate architecture for the reviewer to anchor against, so the threat model carries more of the argument.
    • Connectivity. Remote monitoring, cloud analytics, and companion apps are common in the population that qualifies. Every interface is attack surface you must document.
    • AI and adaptive software. Model update pathways, training data provenance, and PCCP interaction with cybersecurity controls all draw questions.
    • High-acuity use. Devices treating irreversibly debilitating conditions have severe harm ceilings, which pushes exploitability and patient-harm analysis into sharper focus.

    A conventional predicate-backed 510(k) can lean on established architecture patterns. A Breakthrough device usually cannot, so the STRIDE analysis, data flow diagrams, and control rationale have to stand on their own.

    How to use sprint discussions for cybersecurity

    Sprint discussions are the most underused asset in the program. They are short, scoped, and designed to close a specific question quickly, which is exactly the shape of most unresolved cybersecurity decisions.

    See also: Types of 510(k): Traditional, Special, Abbreviated, Q-Sub vs Pre-Sub: FDA Cybersecurity Guide, and FDA SIR Cybersecurity Response: eSTAR Prep Guide.

    Questions worth spending a sprint on:

    • Is our system boundary and trust-boundary decomposition at the right level of granularity for this architecture?
    • Does our SBOM format and depth of transitive dependency coverage meet expectations for this device?
    • Is our proposed penetration testing scope and independence sufficient given the interfaces involved?
    • How should the PCCP interact with the cybersecurity risk assessment for the adaptive model?
    • Does our conformance approach to ANSI/AAMI SW96:2023 and IEC 81001-5-1 satisfy the SPDF expectation?

    Sponsors overwhelmingly spend sprints on clinical endpoints and study design. Those matter, but clinical questions rarely cause an RTA. Cybersecurity gaps do.

    What to build alongside the designation request

    Designation requests are reviewed within 60 days. That window is the right time to start the security work, not to pause it:

    1. Threat model skeleton. Data flow diagrams and trust boundaries, even before the design is frozen. The architecture will change; the discipline of maintaining the model through change is what the SPDF expects.
    2. SBOM pipeline. Automated generation in CycloneDX or SPDX wired into your build, not a spreadsheet assembled at submission time.
    3. Vulnerability intake. A published coordinated disclosure process with a real intake path and defined response timelines.
    4. Security risk file. Distinct from the ISO 14971 safety risk file, connected to it, and scored on exploitability rather than clinical probability.
    5. Testing plan. Scope, independence, and timing for vulnerability scanning, fuzzing, and penetration testing, with schedule room for remediation and retest.

    How Blue Goat Cyber approaches this

    We treat designation status as a scheduling input, not a scope input. The cybersecurity package for a Breakthrough device is built to the same February 3, 2026 guidance expectations as any other cyber device, then sequenced backward from the compressed review calendar the designation creates.

    In practice that means starting the threat model during the designation request window, standing up SBOM generation in CI before design freeze, and reserving at least one sprint discussion for a cybersecurity question we have deliberately scoped to be answerable in a single interaction. Penetration testing is scheduled with remediation and retest time built in, because a finding discovered two weeks before filing is a schedule event, not a technical one.

    We do not promise a clearance outcome. We scope the work so no cybersecurity gap is left open when the submission goes in.

    FAQ

    Does Breakthrough Device designation exempt my device from Section 524B?

    No. Section 524B applies to any cyber device that includes software, has the ability to connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats. There is no expedited-program exemption in the statute and none in the February 3, 2026 final guidance.

    Can the FDA refuse to accept a Breakthrough submission on cybersecurity grounds?

    Yes. Acceptance review happens before substantive review, so the priority benefit of designation never comes into play. A missing SBOM, absent postmarket plan, or no coordinated disclosure process can hold a Breakthrough submission at the acceptance gate.

    Should I raise cybersecurity in a sprint discussion or a Pre-Sub?

    Use a sprint discussion when you hold designation and the question is narrow enough to resolve in one exchange, such as SBOM depth or pen test scope. Use a Pre-Sub for broader strategy questions that need a written response covering several linked decisions.

    Does designation help if my cybersecurity documentation is incomplete?

    No. Senior engagement and interactive review help resolve genuine scientific ambiguity. They do not substitute for required content. Reviewers will still issue deficiencies, and each cycle costs more calendar time relative to a compressed priority-review schedule.

    Do AI-enabled Breakthrough devices have extra cybersecurity expectations?

    The requirements are the same, but the surface is larger. Model update mechanisms, training and inference data paths, and any PCCP-governed change process all need representation in the threat model and in the security risk assessment.

    CTA

    If you hold Breakthrough designation or are preparing a request, get the cybersecurity package moving now while the calendar still has slack. Book a working session and we will map your Section 524B obligations against your projected submission date.

    About the author

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber

    U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 250+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.

    Read more about ChristianLinkedIn

    More in this category

    More FDA articles

    Browse all
    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.