
On this page
Published:
Key Takeaways
- The review clock stops the day the FDA issues an Additional Information request, not the day you read it.
- For 510(k) and De Novo submissions, a complete response is due within 180 calendar days, or the FDA considers the submission withdrawn.
- One complete response is the goal. A partial answer can lead to a second round of questions and more delay.
- Cybersecurity fixes that need firmware changes or new penetration testing usually take the most time, so start them first.
- An early call with the FDA reviewer can confirm what evidence will close each deficiency before you build it.
When the FDA sends an Additional Information request with cybersecurity deficiencies, the review goes on hold the day the letter is issued. For a 510(k) or De Novo, you have 180 calendar days to respond in full. If the FDA does not receive a complete response within 180 days, it considers the submission withdrawn. Most cybersecurity fixes need new testing or design evidence, so plan the response in weeks, not days.
A cybersecurity deficiency letter stops the review clock. Every day after that is on you, not the FDA.
Many teams read "180 days" and relax. That is a mistake. Closing a cybersecurity deficiency often means updating the threat model, rerunning penetration testing, fixing firmware, regenerating the SBOM and revising labeling. Each of those takes time, and they depend on each other.
The February 3, 2026 final guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," sets the evidence the FDA expects. The deficiency letter tells you which parts of that evidence the reviewer could not find.
This post explains how the clock works for each pathway and gives a realistic plan for answering on time.
Why This Matters
Cybersecurity is now one of the most common subjects of FDA Additional Information requests on connected devices. Since March 29, 2023, Section 524B of the FD&C Act has required cyber device submissions to include a plan to monitor and address vulnerabilities, processes that provide reasonable assurance of cybersecurity, and a software bill of materials. The February 3, 2026 guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," describes the evidence behind each of those requirements.
When evidence is missing, the letter arrives and the clock stops. In our MTEC webinar, we ranked the eight cybersecurity deficiencies that appeared most often across 10 real Additional Information letters on submissions we did not prepare. SBOM and vulnerability gaps, threat model gaps and missing traceability showed up again and again. You can see the full ranking in 8 FDA cybersecurity deficiencies, ranked from real letters.
The standards that usually sit behind these requests are AAMI TIR57 and ANSI/AAMI SW96 for security risk management, IEC 81001-5-1 for secure development, and ISO 14971 for safety risk. A response that ties each fix back to these standards is easier for a reviewer to accept.
How does the FDA deficiency clock work for each pathway?
The clock works the same way in principle across pathways: the FDA review stops when the letter is issued and restarts when a complete response arrives. The review goals and deadlines differ.
| Pathway | FDA review goal (MDUFA) | Response window | If you miss it |
|---|---|---|---|
| 510(k) | 90 FDA days | 180 calendar days | Considered withdrawn |
| De Novo | 150 FDA days | 180 calendar days | Considered withdrawn |
| PMA | 180 FDA days | 180 calendar days for a major deficiency letter | Considered voluntarily withdrawn |
The response must address every deficiency in the letter. The FDA reviews the response as a whole, and unresolved items can trigger another request or a negative decision.
Before a formal letter, some reviewers use interactive review to ask quick questions by email. Those answers are usually due within a short window set by the reviewer. Treat them as urgent, because a good answer can keep an issue out of the formal letter.
What does a realistic response plan look like?
A realistic plan starts the longest tasks in the first week and leaves a buffer before day 180. Here is how we usually structure it.
- Days 1 to 3: gap analysis. Map each deficiency to the missing evidence, the owner and the work needed. We deliver this free within 48 hours.
- Week 1 to 2: reviewer call. Request a call to confirm your planned approach for the hardest items.
- Weeks 2 to 8: evidence work. Update the threat model and risk assessment, fix design issues, regenerate the SBOM and VEX, and rerun testing where needed.
- Weeks 8 to 12: documentation. Update architecture views, traceability, labeling and the management plan.
- Weeks 12 to 16: review and submit. Internal quality review, then one complete response.
That leaves room before day 180 for firmware slips or retest findings. Teams that wait until month four to start testing often run out of time.
Want a second opinion on your letter? We offer a free 48-hour gap analysis. Send us your deficiency letter.
Which cybersecurity deficiencies take the longest to close?
The slowest deficiencies are the ones that need design changes or new testing. Documentation-only gaps are faster.
See also: What Is a Cyber Device Under FDA Section 524B?, Does FDA 524B Apply to Auto-Injectors?, and Ransomware and Medical Devices: What the FDA Expects.
- Slowest: unsupported or end-of-life components, missing authentication or encryption, and penetration testing gaps. These often need firmware updates, new verification and a retest.
- Medium: threat model gaps and missing architecture views. These need engineering input but usually no code changes.
- Fastest: labeling gaps, SBOM formatting issues and missing traceability, as long as the underlying work was done.
Our FDA cybersecurity deficiency letter examples guide shows the typical wording for each type and the evidence that answers it.
When should you talk to the FDA reviewer?
Talk to the reviewer early, once you have a draft plan for each deficiency. The FDA allows sponsors to request a call or meeting to clarify an Additional Information request.
A short call can confirm whether your proposed evidence will be enough, especially for disputed findings or where you plan to justify residual risk instead of changing the design. Come prepared with a one-page summary of each deficiency and your planned response. Do not use the call to argue; use it to confirm.
How Blue Goat Cyber Approaches This
We start every deficiency response with a free gap analysis delivered within 48 hours. It maps each item in the letter to the missing evidence, the work needed and a realistic timeline against the 180-day clock.
Our US-based engineers then build the evidence: threat model updates, security risk assessment revisions, SBOM and VEX regeneration, and mostly manual, expert-led penetration testing with AI-driven tools in support. We write the response so each fix traces back to the letter, the guidance and the relevant standard, which makes it easier for the reviewer to close.
We have supported more than 275 device submissions. See our FDA cybersecurity deficiency response service. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
Frequently Asked Questions
How long do you have to respond to an FDA cybersecurity deficiency letter?
For a 510(k) or De Novo, you have 180 calendar days from the date of the Additional Information request to send a complete response. If the FDA does not receive one in that time, it considers the submission withdrawn. For a PMA major deficiency letter, the window is also 180 days. The review stays on hold until your response arrives.
Does the 180-day clock start when we receive the letter?
No. The clock starts on the date the FDA issues the Additional Information request, not the day your team reads it. Letters sent by email reach you the same day, but any internal delay in routing the letter still counts against your 180 days. Log the issue date as soon as the letter arrives.
Can we get an extension beyond 180 days?
Do not plan on one. The 180-day window is the standard expectation for 510(k) and De Novo submissions, and the FDA considers the submission withdrawn if no complete response arrives. If you run out of time, you may need to resubmit. The safer plan is to start the longest cybersecurity tasks in week one.
Should we answer the easy deficiencies first?
No, and this is a common mistake. Answer them all in one complete response, but start the slowest work first. Firmware fixes and penetration retesting usually drive the timeline. Documentation fixes can run in parallel. Sending a partial response early does not restart the review in your favor and can cause another round of questions.
What if we disagree with a cybersecurity deficiency?
You can explain why you disagree, but you must back it with evidence. A reviewer call is the best place to test your position before you write it up. Provide a clear rationale tied to the guidance, the standard and your risk assessment. Unsupported disagreement usually leads to the same question in the next letter.
CTA
If you have a cybersecurity deficiency letter now, send it to us. Within 48 hours you will get a free gap analysis that maps every item to the evidence needed and a plan that fits the 180-day clock. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost. Get your free gap analysis.
About the author. Christian Espinosa, MBA, is the founder and CEO of Blue Goat Cyber and a graduate of the US Air Force Academy. He has reviewed more than 30 FDA cybersecurity deficiency letters and presented the MTEC webinar ranking the most common findings. Read more about Christian.
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
