On this page
Published: April 12, 2025 · Last reviewed: May 1, 2026
Key Takeaways
- The 510(k), De Novo, and PMA databases each publish different cybersecurity evidence: Summary Statements, Decision Summaries, and Summaries of Safety and Effectiveness Data.
- De Novo Decision Summaries are the richest public source of FDA cybersecurity reasoning for novel devices, and are routinely skipped by teams that only search 510(k).
- Product codes, not device names, are the correct primary search key across all three databases.
- Cybersecurity content is heavily redacted under FOIA exemption (b)(4), but structural patterns (SBOM format, threat-model methodology, pen-test scope) still show through.
- Cross-referencing MAUDE and AccessGUDID adds [postmarket cybersecurity](/services/fda-postmarket-cybersecurity-services "FDA postmarket cybersecurity services") context that the premarket databases do not carry.
- Cleared submissions in your product code define the current bar for Section 524B evidence in your device category.
Search the FDA 510(k), De Novo, and PMA databases for cybersecurity precedent, product codes, and predicate devices before a Section 524B premarket filing.
Updated July 10, 2026
Mining the FDA databases is one of the highest-leverage things a MedTech cybersecurity or regulatory lead can do before starting a Section 524B submission. Cleared submissions in your product code tell you exactly how the agency read cybersecurity evidence for a device like yours: what was accepted, what was redacted, what got called out.
The three databases are shaped by three different review pathways, and each surfaces cybersecurity information differently. Reading them the same way, or skipping De Novo entirely, is one of the most common precedent-research mistakes we see.
This guide covers what each database contains, how to search it, and how to read the results through a cybersecurity lens.
Why This Matters for Section 524B Submissions
The FDA's Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions (February 3, 2026 final guidance) codified the cybersecurity documentation the agency expects for every "cyber device" under Section 524B of the FD&C Act. Reviewers apply the same expectations across 510(k), De Novo, and PMA pathways, but the depth and format of what each pathway makes public is very different.
Cleared submissions in your product code are the closest proxy the public record offers for what "acceptable" looks like right now. The FDA's FY2024 CDRH performance data lists cybersecurity among the most-cited deficiency categories in Additional Information (AI) letters. Reading cleared precedent from the same product code helps you calibrate SBOM depth, threat-model methodology, and pen-test scope before you file, not after a deficiency letter.
Precedent research is not a shortcut around the requirements in AAMI TIR57, ANSI/AAMI SW96, and IEC 81001-5-1, but it does tell you how those requirements are currently being read for devices like yours.
What Is the FDA 510(k) Database and What Cybersecurity Content Does It Expose?
Link: FDA 510(k) Premarket Notification Database
The 510(k) database returns every cleared premarket notification submitted under 21 CFR 807 Subpart E, filterable by device name, applicant, product code, decision date, and K-number. For each cleared submission it exposes a Summary Statement (or a Statement) that the sponsor is required to make available. Summary Statements vary widely in depth: some are two pages, some are thirty, and the difference matters when you are trying to read cybersecurity precedent.
For cybersecurity teams, 510(k) records reliably identify:
- Whether the predicate is connected, wireless, or software-based
- The product code and regulation number that trigger cybersecurity review
- Whether the summary references Section 524B, SBOMs, or the February 2026 guidance
- The date of clearance, which tells you which cybersecurity guidance was in force at review
A 510(k) Summary that does not mention cybersecurity is not proof cybersecurity was absent from review. Since Section 524B took effect, cyber devices have been evaluated against the full premarket cybersecurity guidance regardless of what the public Summary Statement chose to disclose.
What Is the FDA De Novo Database and Why Is It the Most Underused for Cybersecurity Research?
Link: FDA De Novo Database
De Novo is the pathway for novel low-to-moderate risk devices with no valid predicate. Each granted De Novo publishes a Decision Summary, which is written by the FDA and is meaningfully more detailed than a 510(k) Summary Statement. Decision Summaries walk through the risks the agency identified, the special controls it imposed, and the evidence the sponsor provided, often including cybersecurity risk analysis, software documentation, and interoperability testing.
That structure makes De Novo grants the single most useful public source for reading FDA cybersecurity reasoning:
- The Decision Summary explicitly names the identified device risks and the mitigations required
- Cybersecurity special controls, when the FDA imposes them, become the regulatory floor for follow-on 510(k)s in the new product code
- The narrative shows how the FDA weighed threat modeling, SBOM, and pen-test evidence rather than just listing artifacts
If your device is novel, or if your product code was created by a De Novo grant, that grant is the primary precedent you should be reading. Teams that only search the 510(k) database miss it entirely.
What Is the FDA PMA Database and How Deep Does Its Cybersecurity Documentation Go?
Link: FDA PMA Database
Premarket Approval is required for Class III devices, those that support or sustain life or present an unreasonable risk of illness or injury. Each PMA approval publishes a Summary of Safety and Effectiveness Data (SSED) and a searchable trail of PMA supplements covering post-approval changes, including cybersecurity updates.
PMA records are the deepest public FDA source for cybersecurity documentation because:
See also: Mining FDA Databases for Cyber Precedent, Letter to File vs New 510(k), and Special vs Traditional 510(k).
- SSEDs frequently include software description, cybersecurity risk assessment, and interoperability content in named sections
- PMA supplements (S001, S002, and so on) show how cybersecurity changes flow through post-approval review, which is directly relevant to Predetermined Change Control Plan scoping
- FDA review memos referenced in SSEDs sometimes call out specific security controls, encryption approach, or update mechanisms
For any implantable, life-supporting, or high-risk connected device, PMA precedent tells you both the initial cybersecurity bar and how the agency has handled cybersecurity changes across the device's lifecycle.
How to Search All Three Databases by Product Code and Read Results Through a Cybersecurity Lens
Product code, not device name, is the correct primary search key. A product code (three letters, e.g. DQA for infusion pumps) maps to a specific 21 CFR regulation number and defines the FDA review team, the guidance stack, and the current cybersecurity expectations for the device category. Start at the FDA Product Classification Database to confirm your code, then search all three premarket databases with that code.
Once you have the results:
- Sort by decision date descending, recent clearances reflect the current cybersecurity guidance
- Read at least three post-Section-524B clearances in your product code
- For each one, note whether the Summary explicitly cites the February 2026 guidance, AAMI SW96, IEC 81001-5-1, or SPDX/CycloneDX SBOM format
- Flag any redactions marked under FOIA exemption (b)(4), that is where the sponsor claimed confidential commercial information, and the structural context around it still tells you what type of artifact was submitted
If you have already received a deficiency letter, cross-reference the language against our library of real FDA cybersecurity deficiency letter examples to see the patterns reviewers use. If your device is AI/ML or firmware-updatable, pair that read with our FDA PCCP change-control plans guide so the change-authority precedent you find in cleared submissions maps to a filable modifications protocol.
Which FDA Sources Fill the Gaps the Premarket Databases Leave
The three premarket databases do not cover postmarket cybersecurity events, recalls, or unique-device-identifier data. For a full precedent picture, pair them with:
- MAUDE, searchable adverse event reports, useful for finding cybersecurity-related failure modes in the same product code
- AccessGUDID, the Unique Device Identifier database, useful for confirming device model families and identifier structure
- FDA FOIA reading room, releases documents obtained by FOIA request, occasionally including cybersecurity-relevant redacted review memos
- 510(k) Third Party Review lists, useful for identifying which product codes are eligible for accelerated review
For a workflow that walks these sources in order and shows how to convert what you find into submission-ready evidence, see our deep dive on mining FDA databases for medical device cybersecurity precedent.
Ready to convert precedent research into a filing plan? Schedule a scoping call and we will map the cleared submissions in your product code against the Section 524B expectations for your device.
How Blue Goat approaches this
Blue Goat Cyber's medical device practice is led by engineers with CISSP, OSCP, and prior military red-team backgrounds. Before we open a new engagement, we pull every post-Section-524B clearance in the client's product code and reconstruct the cybersecurity evidence pattern the FDA has been accepting: SBOM format, threat-model methodology, pen-test scope, and postmarket plan structure.
That precedent read becomes the baseline for the artifacts we produce, calibrated to the current guidance and to how reviewers in that product code have written recent AI letters. See our FDA premarket cybersecurity services for the full scope. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
FAQ
How do I search the FDA 510(k), De Novo, and PMA databases by cybersecurity content?
None of the three databases have a "cybersecurity" filter. Search by product code, then read the Summary Statement, Decision Summary, or Summary of Safety and Effectiveness Data manually. De Novo Decision Summaries are the most likely to contain explicit FDA cybersecurity reasoning because they are written by the agency rather than the sponsor.
Why does the De Novo database matter for cybersecurity precedent research?
De Novo grants create the product code and its special controls, which become the regulatory floor for every follow-on 510(k) in that code. When the FDA imposes cybersecurity special controls in a De Novo grant, subsequent 510(k) submissions in the code must show substantial equivalence to those controls, so the Decision Summary is precedent that outlives the original grant.
What FOIA exemption redacts cybersecurity content in FDA summaries?
Cybersecurity content is most often redacted under FOIA exemption (b)(4), which covers trade secrets and confidential commercial information. The structure of what was submitted, section headings, artifact types, and standards references, usually remains visible even when specific technical detail is redacted.
Do 510(k) Summary Statements always mention cybersecurity for cyber devices?
No. Section 524B compliance is required regardless of whether the sponsor discloses cybersecurity content in the public Summary Statement. Absence in a Summary does not mean absence in the submission or the review.
What is the difference between a 510(k) Summary Statement and a De Novo Decision Summary?
A 510(k) Summary Statement is written by the sponsor to justify substantial equivalence, and its depth varies widely. A De Novo Decision Summary is written by the FDA to document the risks identified, the special controls imposed, and the evidence considered, so it is a more consistent public window into FDA cybersecurity reasoning.
Related: Mining FDA Databases for Medical Device Cybersecurity Precedent · FDA Cybersecurity Deficiency Letter Examples · FDA PCCP Change-Control Plans · FDA Pathway Cybersecurity Differences
About the author
Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 250+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
Sources & references
Primary sources cited in this article. Links open in a new tab.
- FDA 510(k) Premarket Notification Database- U.S. FDA
- FDA De Novo Database- U.S. FDA
- FDA PMA Database- U.S. FDA
- FDA Product Classification Database- U.S. FDA
- MAUDE- U.S. FDA
- AccessGUDID- NIH
- FDA FOIA reading room- U.S. FDA
- 510(k) Third Party Review lists- U.S. FDA



