On this page
Published: May 27, 2026
Key Takeaways
- MDUFA goals target 90 days for a 510(k) decision, but that clock pauses entirely during any RTA hold or Additional Information request, which most cyber device submissions receive at least once.
- An RTA hold happens in the first 15 days if a required cybersecurity artifact, most often the [SBOM](/services/fda-compliant-sbom-services-for-medtech "FDA-compliant SBOM services"), is missing outright, and it stops the clock before substantive review even begins.
- The day-60 substantive interaction milestone is when most cybersecurity-specific questions surface, because that is when a reviewer has had time to actually work through the SPDF evidence.
- You get 180 days to respond to a Major deficiency or AI letter, but using the full window adds that time directly to your calendar; fast, complete responses clear meaningfully sooner.
- Pre-submission meetings and a completed penetration test before filing are the two levers manufacturers control that most reliably shorten the real-world timeline.
Part of our FDA 2026 medical device cybersecurity submission series. For the full overview, start with FDA Cybersecurity Requirements for Medical Devices (2026).
A 510(k) with a clean cybersecurity package typically clears within the MDUFA goal of 90 review days if no deficiency letter is issued. In practice, most submissions with a cyber device profile receive at least one Additional Information request, which pauses the clock and adds 60 to 180 days depending on response speed. De Novo and PMA reviews run longer, and an RTA hold at intake can add weeks before substantive review even starts.
"How long will this take" is usually the first question a program manager asks once cybersecurity work starts, and it is also the hardest to answer honestly, because the honest answer depends entirely on how complete your Secure Product Development Framework evidence is before you file. This post walks through the actual clock mechanics, where cybersecurity-specific delays come from, and what measurably shortens the real timeline.
Understanding the FDA review clock
The Medical Device User Fee Amendments (MDUFA) set performance goals the FDA tracks against, not statutory deadlines. For a standard 510(k), the MDUFA V goal is a decision within 90 FDA review days. That number gets misunderstood constantly: it counts only the days the submission is actively with FDA reviewers. Any time the file is on hold, whether for an RTA screening failure or an outstanding Additional Information (AI) request, does not count against the 90-day goal, and it also does not count against your actual calendar time to market. Manufacturers plan around the wrong number when they treat 90 days as a ceiling rather than as the FDA's own internal target for its active review time.
Cybersecurity has become one of the more common sources of clock-stopping activity since Section 524B's requirements began being enforced at RTA in October 2023, precisely because it is a discrete, checkable set of artifacts (SBOM, threat model, vulnerability plan) that either exist in the right form or do not.
510(k) vs. De Novo vs. PMA timelines
| Pathway | MDUFA goal | Typical real-world timeline with cybersecurity review | Notes |
|---|---|---|---|
| 510(k) | 90 FDA review days | 4 to 9 months to clearance | Fastest when no AI letter is issued |
| De Novo | 150 FDA review days | 8 to 14 months to grant | Novel device profile means more cybersecurity scrutiny on first-of-kind features |
| PMA | 180 FDA review days (for filing decision, with panel-track and advisory steps adding time) | 12 to 24+ months to approval | Deeper security risk management file and broader penetration test scope typically expected |
These ranges assume at least one round of interactive review, which is the norm rather than the exception for a device that meets the 524B cyber device definition. See our De Novo cybersecurity submission guide and PMA cybersecurity requirements guide for pathway-specific detail.
The cybersecurity review process phases
RTA screening: days 1-15
Within roughly 15 days of filing, FDA staff screen the submission for completeness, not scientific merit. For cyber devices, this screening explicitly checks for the presence of the required 524B artifacts: an SBOM, a cybersecurity management plan, and evidence of a vulnerability monitoring process. A missing SBOM at this stage is the single most common cybersecurity-related RTA hold, and it is entirely avoidable with a pre-filing completeness check.
Substantive review and the day-60 milestone
Once accepted, the submission moves into substantive review. Around the 60-day mark, FDA has historically committed to substantive interaction, meaning either an interactive review call or a written communication about the state of the review. For cybersecurity, this is frequently when the first specific questions surface: a reviewer has had time to actually work through the threat model, the penetration test report, and the SBOM, and this is where gaps in traceability or evidence depth get flagged.
Deficiency letters and the final decision
If issues remain unresolved through interactive review, FDA issues either an AI request for a narrower clarification or a Major deficiency letter for more substantial gaps. Both pause the review clock. Once the sponsor responds with a complete package, the review clock resumes, often with a fresh review period rather than picking up exactly where it left off. A clean response can lead to clearance within weeks of resubmission; an incomplete response restarts the cycle.
Common causes of cybersecurity clock stops
- Deficiency letters and AI requests citing gaps in SBOM completeness, threat modeling traceability, or postmarket vulnerability plan specificity. See our deficiency letter examples guide for the actual patterns reviewers cite.
- Incomplete SBOMs and vulnerability assessments, most often missing PURL/CPE identifiers or VEX statements for open CVEs, which prevents a reviewer from verifying the monitoring claim.
- Lack of traceability in threat modeling, where mitigations are described but not linked to a specific verification test, forcing the reviewer to ask for the missing link explicitly rather than infer it.
- Penetration test scope gaps, commonly a report that covers the mobile companion app but omits the device firmware or the wireless interface actually used in the field.
How the RTA policy affects your timeline
The Refuse to Accept policy for cyber devices, in effect since October 1, 2023, gives FDA staff explicit authority to hold a submission at intake if 524B artifacts are missing. This is procedurally different from a deficiency during substantive review: an RTA hold happens before any reviewer has evaluated the technical merit of your cybersecurity approach, purely on the basis of whether the required documents are present in the right format. It is the fastest timeline hit to avoid, because it is entirely within the sponsor's control. A pre-filing checklist run against the 524B(b)(1) through (b)(3) requirements, ideally by someone other than the person who assembled the submission, catches the vast majority of RTA-triggering gaps. See our RTA prevention checklist.
Strategic ways to shorten the real timeline
See also: FDA Premarket Cybersecurity Checklist (2026 Guidance), FDA IDE Cybersecurity Requirements: 2026, and SBOM Diffing & CVE Correlation Postmarket.
Use a pre-submission meeting. A Q-Sub meeting focused specifically on your cybersecurity approach, before you file, surfaces disagreements about scope or methodology while they are still cheap to resolve. Reviewers who have already seen your threat model approach in a pre-sub are less likely to raise a fundamental scope objection during substantive review.
Complete penetration testing before filing, not during review. A submission that includes a finished, methodologically sound penetration test report avoids the most common source of AI requests in the SPDF category. Testing scheduled to run concurrently with FDA review, hoping to supplement the file later, almost always costs more calendar time than it saves. See our penetration testing for medical devices guide.
Respond fast and completely, not eventually. The 180-day response window for a deficiency letter is a ceiling, not a target. Submissions that respond within two to three weeks with the specific requested evidence, rather than a narrative explanation, consistently clear faster in our experience across hundreds of engagements.
Build the SBOM from your build pipeline, not by hand at submission time. A hand-assembled SBOM under deadline pressure is where most of the missing-identifier and stale-version problems originate. Automating generation removes the single most common RTA trigger.
How Blue Goat Cyber approaches review timelines
We treat the review timeline as a function of evidence completeness at filing, not as something to manage reactively once a deficiency letter arrives. That means running a full 524B completeness check before submission, scheduling penetration testing early enough that findings can still influence the design rather than only the documentation, and building the SBOM generation process into the build pipeline so it never becomes a last-minute reconstruction. Where a submission has already stalled on a deficiency letter, we scope the response against the underlying requirement rather than the letter's wording, because that is what actually closes the gap in one round instead of two. This work runs through our FDA Premarket Cybersecurity Services and FDA Cybersecurity Deficiency Response engagements.
FAQ
How long does a 510(k) cybersecurity review actually take?
The MDUFA goal is a 90-day FDA review clock, but that clock pauses for any RTA hold or AI request. Most submissions with a cyber device profile receive at least one round of questions, which realistically puts total time to clearance in the 4 to 9 month range depending on response speed and how complete the initial SPDF evidence was.
What triggers an FDA cybersecurity deficiency letter?
The most common triggers are an incomplete or non-machine-readable SBOM, a threat model that is not traced to verification evidence, and a postmarket vulnerability plan that describes an intended process rather than an operating one. See our deficiency letter examples guide for the specific patterns.
Does the FDA review cybersecurity during the RTA phase?
Yes. Since October 1, 2023, RTA screening explicitly checks for the presence of required 524B artifacts, most notably the SBOM and the cybersecurity management plan. This is a completeness check, not a technical evaluation, so a missing artifact triggers a hold regardless of how strong the underlying engineering work is.
How many rounds of questions does the FDA typically ask about cybersecurity?
One round of AI request or Major deficiency is common even for well-prepared submissions; two rounds usually indicates the first response addressed the letter's specific wording rather than the underlying requirement. Submissions that clear in zero rounds are the ones that completed penetration testing and SBOM generation well before filing.
Does a De Novo take longer than a 510(k) for cybersecurity review?
Generally yes. The MDUFA goal itself is longer (150 days versus 90), and because De Novo submissions involve a novel device type, reviewers often have less established precedent for what an adequate cybersecurity evidence package looks like, which can mean more back-and-forth on scope and methodology.
Can a pre-submission meeting shorten my cybersecurity review timeline?
Yes, indirectly. A pre-submission meeting does not shorten the formal review clock, but it surfaces disagreements about your cybersecurity methodology while they are inexpensive to resolve, which reduces the odds of a deficiency letter that would otherwise pause the clock for weeks or months.
Related reading on this site
- FDA Cybersecurity Deficiency Letter Examples
- FDA Cybersecurity RTA Prevention Checklist
- FDA 524B Cybersecurity Requirements Explained
- De Novo Cybersecurity Submission Guide
- FDA PMA Cybersecurity Requirements
Reviewed by the Blue Goat Cyber team. Last updated July 26, 2026.
About the author
Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 250+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.



