
On this page
Published: · Updated:
Key Takeaways
- The FDA user fee is a fixed, published amount that changes every fiscal year and varies by submission type.
- Small business status can substantially reduce the user fee, but it requires a separate qualification request and does not reduce testing or consulting costs.
- Testing, consultant fees, and cybersecurity documentation typically cost more than the user fee itself, especially for connected devices.
- PMA submissions cost more than 510(k) submissions primarily because of the clinical evidence requirement, not the fee difference alone.
- Cybersecurity documentation cost scales with device connectivity, not with submission pathway.
- A deficiency letter is the most expensive outcome, since it forces a second round of evidence generation and adds review delay.
Part of our FDA 2026 medical device cybersecurity submission series. For the full overview, start with FDA Cybersecurity Requirements for Medical Devices (2026).
510(k) cost has three layers: the FDA user fee, the evidence you must generate to support the submission, and the cost of a deficiency letter if that evidence is incomplete. The user fee is the smallest and most predictable line item; testing, consultants, and cybersecurity documentation almost always cost more. Check the FDA's current fiscal year Medical Device User Fee Amendments schedule for the exact fee, since it changes every October 1.
Reviewed September 17, 2026
A manufacturer that budgets only for the FDA's published user fee is going to be surprised by the real cost of getting a device cleared. The fee itself is a fixed, published number that changes annually, but it is usually the smallest expense in the submission. Testing, consultants, clinical evidence for higher-risk pathways, and cybersecurity documentation for any connected device routinely dwarf the fee, and a deficiency letter can add months of delay and a second round of spending on top of all of it. Understanding which cost category moves with which decision, pathway, device complexity, connectivity, is what actually lets a team plan a realistic budget instead of anchoring on a number that covers a fraction of the real spend.
Why This Matters
The FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions guidance, issued in September 2023, updated June 27, 2025, and finalized again February 3, 2026, made cybersecurity documentation a gating criterion for clearance under section 524B of the FD&C Act. That gating status changes how manufacturers should budget, because cybersecurity work is no longer an optional add-on for connected devices; it is part of what a reviewer checks before the FDA will even accept the submission for review.
The FDA's refuse-to-accept process, in effect since October 1, 2023 for cyber devices covered by section 524B, means an incomplete SBOM or vulnerability management plan can stop a submission before substantive review starts. That is a cost multiplier because the manufacturer has already paid the user fee and invested in the rest of the submission package by the time a refuse-to-accept letter arrives. The FDA's own performance data consistently shows cybersecurity documentation among the top categories cited in Additional Information requests, behind only general software documentation and clinical evidence.
Budgeting for a submission without accounting for this reality means underestimating both the timeline and the total spend. A manufacturer that treats cybersecurity documentation as a late-stage checklist item, rather than as design-controlled engineering output built alongside the rest of the submission, is the one most likely to see costs balloon through rework after a deficiency letter.
What Is the FDA User Fee and How Is It Set?
The FDA user fee is a fixed payment set under the Medical Device User Fee Amendments (MDUFA) program, and it changes every fiscal year on October 1. The fee funds the FDA's review activities and is required at the time of submission unless the manufacturer qualifies for small business status. Because the fee schedule is updated annually and differs by submission type, the only reliable source for the current dollar amount is the FDA's published MDUFA fee schedule for the fiscal year in question; any number quoted in an article can be outdated within months.
[KEY REQUIREMENT] Confirm the current fiscal year's fee on the FDA's MDUFA fee schedule page before finalizing a submission budget, since fees are set annually and differ for 510(k), De Novo, and PMA submissions.
How Does Small Business Status Change the Fee?
Small business status can substantially reduce the standard user fee, but it does not reduce anything else in the submission budget. A company qualifies by submitting a Small Business Qualification Request (Form FDA 3602) and demonstrating gross receipts under the threshold the FDA sets for that program. Approval typically cuts the user fee by a large percentage compared to the standard fee, which matters for startups, but testing, consultant time, and cybersecurity documentation cost the same whether or not the company qualifies.
| Cost category | Moves with pathway | Moves with connectivity | Moves with small business status |
|---|---|---|---|
| FDA user fee | Yes | No | Yes, substantially reduced |
| Bench and biocompatibility testing | Somewhat | No | No |
| Clinical evidence | Yes, mainly PMA | No | No |
| Cybersecurity documentation and testing | No | Yes, strongly | No |
| Regulatory consultant fees | Somewhat | Somewhat | No |
| Deficiency letter rework | Yes, higher for PMA | Yes | No |
What Separates 510(k), De Novo, and PMA Cost?
The three pathways differ mainly in the evidence burden they impose, not in the user fee alone. A 510(k) requires showing substantial equivalence to a predicate device, which is generally the least evidence-intensive path and carries the lowest standard fee. A De Novo request applies to novel, low-to-moderate-risk devices without a predicate, sits in the middle on both fee and evidence burden, and often requires a cybersecurity approach built from scratch since there is no predicate labeling or documentation to reference. A PMA applies to Class III and other high-risk devices, carries the highest standard fee, and typically requires clinical trial data, which is the single largest cost driver in that pathway.
Cybersecurity cost does not track neatly with pathway. A 510(k) submission for a highly connected infusion pump can carry more cybersecurity documentation and testing cost than a PMA submission for a mechanically simple implant with no wireless features. Connectivity, not regulatory pathway, is the variable that predicts cybersecurity spend.
What Drives Cybersecurity Documentation Cost?
Cybersecurity documentation cost is driven by how connected the device is, not by which submission pathway it goes through. A device with wireless communication, cloud integration, a companion mobile app, or third-party software components needs a threat model, a software bill of materials, penetration testing, and a vulnerability management plan under the current premarket cybersecurity guidance. A device with no network connectivity and minimal software still needs a security risk assessment, but the scope and cost are much smaller.
See also: Letter to File vs New 510(k), Special vs Traditional 510(k), and FDA 510(k) & PMA Cybersecurity Guide.
[KEY REQUIREMENT] Scope cybersecurity testing and documentation to the device's actual connectivity and software architecture early in development, since retrofitting an SBOM or threat model after design freeze costs more than building it alongside the design controls.
Manufacturers should also budget for the possibility that cybersecurity gaps trigger an Additional Information request or a refuse-to-accept letter, since fixing those gaps after submission means paying for a second round of testing and documentation on a compressed timeline.
What Does a Deficiency Letter Actually Cost?
A deficiency letter is the most expensive outcome in the entire submission process because it forces a second round of evidence generation without refunding any of the money already spent. When the FDA issues an Additional Information request, the manufacturer has already paid the user fee, already paid for the original round of testing and documentation, and now has to fund another cycle of work on top of the delay to the product's launch timeline. Cybersecurity gaps are consistently among the top categories cited in these letters, alongside general software documentation and clinical evidence, which is why cybersecurity work done well the first time is one of the more cost-effective investments in the entire submission budget.
How to Estimate a Realistic Submission Budget
Building a realistic budget means adding four categories together rather than anchoring on the published user fee alone: the fee itself, the direct cost of testing and clinical evidence appropriate to the pathway, cybersecurity documentation and testing scaled to connectivity, and a contingency for a possible deficiency response. Consultant and regulatory affairs fees vary by project complexity and are worth quoting separately from internal engineering time, since the two are not interchangeable.
Teams frequently underestimate the internal engineering time a submission consumes, treating it as a line item that runs in parallel with product development rather than one that competes for the same engineers. Assigning a dedicated owner for the regulatory submission, separate from the engineers building the product, tends to produce a more accurate budget and a shorter path to clearance.
How Blue Goat Cyber Approaches This
Blue Goat Cyber helps manufacturers scope the cybersecurity portion of a submission budget accurately before development is finished, rather than after. Our FDA premarket cybersecurity services build the threat model, SBOM, and penetration testing evidence a submission needs, scoped to the device's actual connectivity and architecture so the manufacturer is not paying for testing scope it does not need or missing testing scope a reviewer will flag. That scoping work is what keeps cybersecurity from becoming the line item that turns a predictable user fee into an unpredictable total project cost.
If you want one team to own the whole cybersecurity package, see our full-service FDA premarket cybersecurity submission support.
Frequently Asked Questions
How much does a 510(k) submission cost in total?
The total cost includes the FDA user fee, which changes annually and should be confirmed on the current MDUFA fee schedule, plus testing, consultant fees, and cybersecurity documentation if the device is connected. For most 510(k) submissions, the user fee is the smallest of these categories, and the true total depends heavily on device complexity and connectivity.
Is a PMA always more expensive than a 510(k)?
Yes, a PMA submission is generally more expensive than a 510(k) because it requires clinical trial evidence and carries a higher standard user fee. The clinical evidence requirement, not the fee difference alone, is usually the larger driver of the total cost gap between the two pathways.
Does small business status reduce cybersecurity testing costs?
No, small business status only reduces the FDA user fee, not the cost of testing, consulting, or cybersecurity documentation. A qualifying small business still needs to fund the same scope of cybersecurity work as a larger company if its device has comparable connectivity.
Why does cybersecurity cost vary so much between devices?
Cybersecurity cost scales with how connected a device is, including wireless communication, cloud integration, mobile apps, and third-party software components. A simple, non-connected device needs a much smaller cybersecurity risk assessment than a highly connected device, regardless of which regulatory pathway either one uses.
What is the fastest way to reduce total submission cost?
The fastest way to reduce total cost is to avoid a deficiency letter, since a second round of testing and documentation on a compressed timeline is more expensive than doing the work correctly the first time. Building cybersecurity documentation alongside design controls, rather than after design freeze, is one of the more reliable ways to prevent that outcome.
CTA
Before you finalize a submission budget, confirm the current FDA user fee on the MDUFA fee schedule and get the cybersecurity scope right the first time. Contact Blue Goat Cyber to scope the testing and documentation your device actually needs.
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
