On this page
Published: May 27, 2026
Key Takeaways
- Cybersecurity review runs in parallel with the overall FDA submission clock, there is no separate cyber review queue.
- Refuse to Accept (RTA) screening happens at day 15; incomplete Appendix 1 cyber artifacts trigger an RTA hold.
- AI letters typically arrive between day 60 and day 90 of substantive review and stop the FDA clock while the sponsor responds.
- Each cyber deficiency round adds 60-180 calendar days; sponsors average 1.4 rounds on cyber devices in 2025 FDA data.
- The controllable variable is submission quality: a complete SPDF package shipped at day zero routinely clears cyber review in one round.
Part of our FDA 2026 medical device cybersecurity submission series. For the full overview, start with FDA Cybersecurity Requirements for Medical Devices (2026).
How long does FDA cybersecurity review take? Real 510(k), De Novo, and PMA timelines, clock stops, and where cyber deficiencies add 90-180 days.
The February 3, 2026 final premarket cybersecurity guidance did not change the review clocks. It changed how often cybersecurity is the reason those clocks stop. Sponsors submitting cyber devices in 2026 report cybersecurity is now the leading cause of Additional Information (AI) letters on 510(k) submissions, ahead of clinical, software validation, and biocompatibility.
The good news: the cybersecurity timeline is one of the most controllable variables in an FDA submission. Sponsors who ship a submission-ready cybersecurity package clear review in the FDA's stated windows. Sponsors who submit incomplete cyber evidence add three to nine months.
This post walks through the actual clocks, where cybersecurity stops them, and what a submission-ready cyber package looks like against 2026 reviewer expectations.
Table of Contents
- The FDA Review Clocks Explained
- Where Cybersecurity Stops the Clock
- Real 2025-2026 Timelines by Pathway
- What a Submission-Ready Cyber Package Looks Like
- How to Shave 90+ Days off the Timeline
Why This Matters
Section 524B of the Federal Food, Drug, and Cosmetic Act, added by the Consolidated Appropriations Act, 2023, gave FDA the statutory authority to refuse cyber device submissions that fail to include a threat model, an SBOM, a vulnerability management plan, and evidence of secure design controls. The February 3, 2026 final premarket cybersecurity guidance is how reviewers now operationalize that authority.
FDA's own MDUFA V performance goals set the review clocks: 90 FDA days for 510(k), 150 for De Novo, 180 for PMA. Those clocks pause when the FDA sends an AI letter, an interactive review request, or a Major deficiency letter. Cyber deficiencies are one of the most frequent reasons the clock stops.
The standards reviewers cross-reference during cybersecurity review: ANSI/AAMI SW96:2023, AAMI TIR57 (threat modeling), IEC 81001-5-1 (secure software lifecycle), ISO 14971 (risk management with cybersecurity linkage), and NIST SP 800-115 (penetration testing methodology). Submissions that do not map to these standards are the ones that draw Major deficiencies.
The FDA Review Clocks Explained
FDA review timelines use two different clocks. The FDA clock counts only days the submission is under agency review, it pauses during any hold. The calendar clock counts every day from submission to clearance, including hold time.
| Pathway | FDA clock | Typical calendar time (no deficiencies) | With one cyber deficiency round |
|---|---|---|---|
| 510(k) | 90 FDA days | 4-6 months | 7-10 months |
| De Novo | 150 FDA days | 8-12 months | 12-16 months |
| PMA | 180 FDA days | 10-14 months | 14-20 months |
| Q-Sub (pre-submission) | 75 FDA days | 3-4 months | N/A (no clock stops) |
The FDA clock is what MDUFA performance reports track. The calendar clock is what your executive team plans a launch around. The gap between them is deficiency response time.
Where Cybersecurity Stops the Clock
Cybersecurity issues surface at three distinct points in the review, and each triggers a different type of clock stop.
Day 15, Refuse to Accept (RTA) screening. For 510(k) and De Novo, FDA performs an administrative completeness check. Missing Appendix 1 cybersecurity artifacts (threat model, SBOM, vulnerability management plan, secure design documentation) are RTA-eligible. Sponsors have 180 calendar days to respond, but responding fast is critical, the submission does not enter substantive review until it passes RTA.
Day 60-90, Additional Information (AI) letters. Once substantive review starts, the reviewer issues AI letters for any deficiency that blocks their ability to complete the review. Cyber AI letters typically cite specific gaps: incomplete threat model coverage, SBOM missing pURLs or unresolved CVEs, pen test with insufficient methodology, missing residual-risk statements. The FDA clock stops until the sponsor responds. Sponsors have 180 calendar days.
Later, Major or Minor deficiencies. Toward the end of review, FDA issues a formal deficiency letter. Major deficiencies stop the clock for 180 days; Minor deficiencies typically resolve in a single Interactive Review exchange.
Already have an AI letter with cyber deficiencies?
Blue Goat Cyber is a medical-device-only cybersecurity firm. We ship a 48-hour gap analysis mapping every item in the letter to the FDA guidance section it cites, then rebuild the artifacts and package a reviewer-ready response, without losing your place in the queue. → FDA Cybersecurity Deficiency Response
Real 2025-2026 Timelines by Pathway
Actual calendar times observed across cyber device engagements in the last 18 months:
510(k) with clean cyber package: 4.5-5.5 months from submission to clearance. Cyber review completes in the FDA's stated 90-day window with no clock stops.
510(k) with one cyber AI letter round: 7-9 months. The AI letter arrives around day 70, the sponsor responds in 30-60 days, and substantive review resumes for another 30-45 days.
510(k) with two cyber deficiency rounds: 10-14 months. This is where sponsors miss launch commitments. Common root cause: threat model deficiencies uncovered late trigger downstream pen test and SBOM/VEX rework.
See also: Premarket FDA Cybersecurity Checklist, FDA IDE Cybersecurity Requirements: 2026, and SBOM Diffing & CVE Correlation Postmarket.
De Novo with clean cyber package: 9-11 months. Cyber scrutiny is more intense than 510(k), reviewers probe threat model depth and residual-risk linkage harder for novel devices.
De Novo with deficiencies: 13-18 months. Novel devices with weak threat models routinely absorb 6+ months in cyber deficiency response.
PMA with clean cyber package: 11-14 months. PMA cyber scrutiny matches the safety burden of the device class.
What a Submission-Ready Cyber Package Looks Like
Appendix 1 of the FDA's 2026 premarket cybersecurity guidance defines the artifact set. A submission that ships all of these, traceable to the threat model and mapped to current standards, clears cyber review in a single round in the vast majority of engagements.
- Security Risk Management Plan and Report, mapped to ANSI/AAMI SW96:2023 and linked to ISO 14971 patient-harm analysis.
- Threat Model, STRIDE- or AAMI TIR57 / ANSI/AAMI SW96:2023-aligned, with data flow diagrams, trust boundaries, asset inventory, and threat-to-control traceability. Global, multi-patient harm, and updateability views (2026 additions).
- SBOM, machine-readable (CycloneDX or SPDX), complete to transitive dependencies, with pURL identifiers and end-of-support dates.
- VEX, exploitability status for every known CVE in the SBOM.
- Vulnerability Management Plan, CVD process, monitoring cadence, and patch delivery mechanism.
- Penetration Test Report, manual methodology mapped to NIST SP 800-115 or PTES, findings traced to the threat model, residual-risk statements.
- Security Architecture Views, global system view, multi-patient harm view, updateability view.
- Secure Development Lifecycle Documentation, evidence the SPDF is implemented, not just described.
How to Shave 90+ Days off the Timeline
Two practices consistently cut cybersecurity-driven delays.
Book a cyber-focused Q-sub before you submit. The Q-sub clock is separate and does not stop the eventual submission clock. Ninety days of Q-sub feedback on your threat model and SBOM approach eliminates the most common Major deficiency patterns.
Do the deficiency response yourself in the first submission. Sponsors who imagine the AI letter they would receive and pre-emptively address it in the initial package cut second-round risk to near zero. That is the work we ship with our FDA Premarket Cybersecurity Services engagement.
How Blue Goat Cyber Approaches This
We run cyber submissions like a regulated engineering workstream, not a document deliverable. Every artifact is generated inside your QMS, mapped to the February 2026 FDA guidance, AAMI SW96, TIR57/TIR97, IEC 81001-5-1, and ISO 14971, with citations embedded so reviewers do not have to guess.
Our FDA Premarket Cybersecurity Services covers the full Appendix 1 artifact set through submission; FDA Cybersecurity Deficiency Response is the entry point for sponsors already in a deficiency loop. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
Frequently Asked Questions
How long does FDA cybersecurity review take?
Cyber review runs in parallel with the overall submission clock: 90 FDA days for 510(k), 150 for De Novo, 180 for PMA. There is no separate cyber queue. Calendar time is longer, typically 4-6 months for a clean 510(k) and 8-12 months for a clean De Novo, plus 60-180 days per cyber deficiency round.
What triggers an RTA hold for cybersecurity?
Missing Appendix 1 artifacts. FDA screens for the threat model, SBOM, vulnerability management plan, and secure design documentation at day 15. Any missing artifact triggers an RTA hold. Sponsors have 180 calendar days to respond, but the submission does not enter substantive review until it passes.
How much time does a cyber AI letter add?
Sixty to 180 calendar days. The FDA clock stops the day the AI letter is issued. Sponsors have 180 calendar days to respond; most experienced sponsors respond in 30-60 days. Substantive review then resumes for another 30-45 days.
Can I submit a cyber device without a threat model?
No. Section 524B of the FD&C Act requires threat modeling for every cyber device. Submissions without a threat model, or with a generic template not built from the device's actual architecture, are the leading cause of RTA holds and Major deficiencies since 2024.
Does a Q-sub delay my 510(k) submission?
No. Q-sub review runs on a separate 75-day FDA clock and does not affect the eventual submission timeline. Cyber-focused Q-subs are the highest-leverage way to reduce Major deficiency risk in the actual submission.
What percentage of cyber device submissions get a cyber AI letter?
In 2025 FDA data on cyber devices, roughly 60% of 510(k) submissions and 75% of De Novo submissions received at least one cyber-related AI letter. Sponsors who shipped a complete SPDF package aligned to AAMI SW96 and the 2026 guidance dropped the AI-letter rate to under 15% in our engagements.
CTA
If you are scoping a submission timeline and want a defensible cyber package that clears review in one round, we ship the full Appendix 1 artifact set inside your QMS. Request a scoping call with the target submission date and device profile.
About the author
Christian Espinosa, CISSP, Founder, Blue Goat Cyber. Christian leads a team focused exclusively on medical device cybersecurity for FDA premarket submissions and postmarket compliance, with 250+ device submissions across 510(k), De Novo, PMA, and EU MDR pathways. Read more about Christian.



