Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Blog · FDA

    FDA Cybersecurity Review Timeline: 510(k) & De Novo Guide

    Learn the actual timelines for FDA cybersecurity review. Understand 510(k) and De Novo clock stops, RTA hold periods, and how to avoid costly delays.

    Abstract medical device circuit board with a clock overlay, symbolizing FDA cybersecurity review timelines
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Published: May 27, 2026

    Key Takeaways

    • Cybersecurity review runs in parallel with the overall FDA submission clock, there is no separate cyber review queue.
    • Refuse to Accept (RTA) screening happens at day 15; incomplete Appendix 1 cyber artifacts trigger an RTA hold.
    • AI letters typically arrive between day 60 and day 90 of substantive review and stop the FDA clock while the sponsor responds.
    • Each cyber deficiency round adds 60-180 calendar days; sponsors average 1.4 rounds on cyber devices in 2025 FDA data.
    • The controllable variable is submission quality: a complete SPDF package shipped at day zero routinely clears cyber review in one round.

    Part of our FDA 2026 medical device cybersecurity submission series. For the full overview, start with FDA Cybersecurity Requirements for Medical Devices (2026).

    Direct Answer

    How long does FDA cybersecurity review take? Real 510(k), De Novo, and PMA timelines, clock stops, and where cyber deficiencies add 90-180 days.

    The February 3, 2026 final premarket cybersecurity guidance did not change the review clocks. It changed how often cybersecurity is the reason those clocks stop. Sponsors submitting cyber devices in 2026 report cybersecurity is now the leading cause of Additional Information (AI) letters on 510(k) submissions, ahead of clinical, software validation, and biocompatibility.

    The good news: the cybersecurity timeline is one of the most controllable variables in an FDA submission. Sponsors who ship a submission-ready cybersecurity package clear review in the FDA's stated windows. Sponsors who submit incomplete cyber evidence add three to nine months.

    This post walks through the actual clocks, where cybersecurity stops them, and what a submission-ready cyber package looks like against 2026 reviewer expectations.

    Table of Contents

    Why This Matters

    Section 524B of the Federal Food, Drug, and Cosmetic Act, added by the Consolidated Appropriations Act, 2023, gave FDA the statutory authority to refuse cyber device submissions that fail to include a threat model, an SBOM, a vulnerability management plan, and evidence of secure design controls. The February 3, 2026 final premarket cybersecurity guidance is how reviewers now operationalize that authority.

    FDA's own MDUFA V performance goals set the review clocks: 90 FDA days for 510(k), 150 for De Novo, 180 for PMA. Those clocks pause when the FDA sends an AI letter, an interactive review request, or a Major deficiency letter. Cyber deficiencies are one of the most frequent reasons the clock stops.

    The standards reviewers cross-reference during cybersecurity review: ANSI/AAMI SW96:2023, AAMI TIR57 (threat modeling), IEC 81001-5-1 (secure software lifecycle), ISO 14971 (risk management with cybersecurity linkage), and NIST SP 800-115 (penetration testing methodology). Submissions that do not map to these standards are the ones that draw Major deficiencies.

    The FDA Review Clocks Explained

    FDA review timelines use two different clocks. The FDA clock counts only days the submission is under agency review, it pauses during any hold. The calendar clock counts every day from submission to clearance, including hold time.

    Pathway FDA clock Typical calendar time (no deficiencies) With one cyber deficiency round
    510(k) 90 FDA days 4-6 months 7-10 months
    De Novo 150 FDA days 8-12 months 12-16 months
    PMA 180 FDA days 10-14 months 14-20 months
    Q-Sub (pre-submission) 75 FDA days 3-4 months N/A (no clock stops)

    The FDA clock is what MDUFA performance reports track. The calendar clock is what your executive team plans a launch around. The gap between them is deficiency response time.

    Where Cybersecurity Stops the Clock

    Cybersecurity issues surface at three distinct points in the review, and each triggers a different type of clock stop.

    Day 15, Refuse to Accept (RTA) screening. For 510(k) and De Novo, FDA performs an administrative completeness check. Missing Appendix 1 cybersecurity artifacts (threat model, SBOM, vulnerability management plan, secure design documentation) are RTA-eligible. Sponsors have 180 calendar days to respond, but responding fast is critical, the submission does not enter substantive review until it passes RTA.

    Day 60-90, Additional Information (AI) letters. Once substantive review starts, the reviewer issues AI letters for any deficiency that blocks their ability to complete the review. Cyber AI letters typically cite specific gaps: incomplete threat model coverage, SBOM missing pURLs or unresolved CVEs, pen test with insufficient methodology, missing residual-risk statements. The FDA clock stops until the sponsor responds. Sponsors have 180 calendar days.

    Later, Major or Minor deficiencies. Toward the end of review, FDA issues a formal deficiency letter. Major deficiencies stop the clock for 180 days; Minor deficiencies typically resolve in a single Interactive Review exchange.

    Already have an AI letter with cyber deficiencies?

    Blue Goat Cyber is a medical-device-only cybersecurity firm. We ship a 48-hour gap analysis mapping every item in the letter to the FDA guidance section it cites, then rebuild the artifacts and package a reviewer-ready response, without losing your place in the queue. → FDA Cybersecurity Deficiency Response

    Real 2025-2026 Timelines by Pathway

    Actual calendar times observed across cyber device engagements in the last 18 months:

    510(k) with clean cyber package: 4.5-5.5 months from submission to clearance. Cyber review completes in the FDA's stated 90-day window with no clock stops.

    510(k) with one cyber AI letter round: 7-9 months. The AI letter arrives around day 70, the sponsor responds in 30-60 days, and substantive review resumes for another 30-45 days.

    510(k) with two cyber deficiency rounds: 10-14 months. This is where sponsors miss launch commitments. Common root cause: threat model deficiencies uncovered late trigger downstream pen test and SBOM/VEX rework.

    See also: Premarket FDA Cybersecurity Checklist, FDA IDE Cybersecurity Requirements: 2026, and SBOM Diffing & CVE Correlation Postmarket.

    De Novo with clean cyber package: 9-11 months. Cyber scrutiny is more intense than 510(k), reviewers probe threat model depth and residual-risk linkage harder for novel devices.

    De Novo with deficiencies: 13-18 months. Novel devices with weak threat models routinely absorb 6+ months in cyber deficiency response.

    PMA with clean cyber package: 11-14 months. PMA cyber scrutiny matches the safety burden of the device class.

    What a Submission-Ready Cyber Package Looks Like

    Appendix 1 of the FDA's 2026 premarket cybersecurity guidance defines the artifact set. A submission that ships all of these, traceable to the threat model and mapped to current standards, clears cyber review in a single round in the vast majority of engagements.

    • Security Risk Management Plan and Report, mapped to ANSI/AAMI SW96:2023 and linked to ISO 14971 patient-harm analysis.
    • Threat Model, STRIDE- or AAMI TIR57 / ANSI/AAMI SW96:2023-aligned, with data flow diagrams, trust boundaries, asset inventory, and threat-to-control traceability. Global, multi-patient harm, and updateability views (2026 additions).
    • SBOM, machine-readable (CycloneDX or SPDX), complete to transitive dependencies, with pURL identifiers and end-of-support dates.
    • VEX, exploitability status for every known CVE in the SBOM.
    • Vulnerability Management Plan, CVD process, monitoring cadence, and patch delivery mechanism.
    • Penetration Test Report, manual methodology mapped to NIST SP 800-115 or PTES, findings traced to the threat model, residual-risk statements.
    • Security Architecture Views, global system view, multi-patient harm view, updateability view.
    • Secure Development Lifecycle Documentation, evidence the SPDF is implemented, not just described.

    How to Shave 90+ Days off the Timeline

    Two practices consistently cut cybersecurity-driven delays.

    Book a cyber-focused Q-sub before you submit. The Q-sub clock is separate and does not stop the eventual submission clock. Ninety days of Q-sub feedback on your threat model and SBOM approach eliminates the most common Major deficiency patterns.

    Do the deficiency response yourself in the first submission. Sponsors who imagine the AI letter they would receive and pre-emptively address it in the initial package cut second-round risk to near zero. That is the work we ship with our FDA Premarket Cybersecurity Services engagement.

    How Blue Goat Cyber Approaches This

    We run cyber submissions like a regulated engineering workstream, not a document deliverable. Every artifact is generated inside your QMS, mapped to the February 2026 FDA guidance, AAMI SW96, TIR57/TIR97, IEC 81001-5-1, and ISO 14971, with citations embedded so reviewers do not have to guess.

    Our FDA Premarket Cybersecurity Services covers the full Appendix 1 artifact set through submission; FDA Cybersecurity Deficiency Response is the entry point for sponsors already in a deficiency loop. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.

    Frequently Asked Questions

    How long does FDA cybersecurity review take?

    Cyber review runs in parallel with the overall submission clock: 90 FDA days for 510(k), 150 for De Novo, 180 for PMA. There is no separate cyber queue. Calendar time is longer, typically 4-6 months for a clean 510(k) and 8-12 months for a clean De Novo, plus 60-180 days per cyber deficiency round.

    What triggers an RTA hold for cybersecurity?

    Missing Appendix 1 artifacts. FDA screens for the threat model, SBOM, vulnerability management plan, and secure design documentation at day 15. Any missing artifact triggers an RTA hold. Sponsors have 180 calendar days to respond, but the submission does not enter substantive review until it passes.

    How much time does a cyber AI letter add?

    Sixty to 180 calendar days. The FDA clock stops the day the AI letter is issued. Sponsors have 180 calendar days to respond; most experienced sponsors respond in 30-60 days. Substantive review then resumes for another 30-45 days.

    Can I submit a cyber device without a threat model?

    No. Section 524B of the FD&C Act requires threat modeling for every cyber device. Submissions without a threat model, or with a generic template not built from the device's actual architecture, are the leading cause of RTA holds and Major deficiencies since 2024.

    Does a Q-sub delay my 510(k) submission?

    No. Q-sub review runs on a separate 75-day FDA clock and does not affect the eventual submission timeline. Cyber-focused Q-subs are the highest-leverage way to reduce Major deficiency risk in the actual submission.

    What percentage of cyber device submissions get a cyber AI letter?

    In 2025 FDA data on cyber devices, roughly 60% of 510(k) submissions and 75% of De Novo submissions received at least one cyber-related AI letter. Sponsors who shipped a complete SPDF package aligned to AAMI SW96 and the 2026 guidance dropped the AI-letter rate to under 15% in our engagements.

    CTA

    If you are scoping a submission timeline and want a defensible cyber package that clears review in one round, we ship the full Appendix 1 artifact set inside your QMS. Request a scoping call with the target submission date and device profile.

    About the author

    Christian Espinosa, CISSP, Founder, Blue Goat Cyber. Christian leads a team focused exclusively on medical device cybersecurity for FDA premarket submissions and postmarket compliance, with 250+ device submissions across 510(k), De Novo, PMA, and EU MDR pathways. Read more about Christian.

    Related. FDA Premarket Cybersecurity

    Continue exploring this topic

    Pillar
    FDA Premarket Cybersecurity
    Article
    FDA Pen Test Timing for Submissions
    Article
    IEC 62304 Classes vs FDA Device Classes
    Article
    Infusion Pump Cybersecurity: FDA Expectations (2026)
    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.