On this page
Published: July 22, 2026
Key Takeaways
- Q-Sub is the umbrella program; Pre-Sub is the most common submission type inside it.
- Every Q-Sub type gets a "Q" tracking number, which is why people conflate the terms.
- Pre-Subs are the right vehicle for FDA feedback on cybersecurity strategy before filing.
- FDA typically responds to a Pre-Sub within 70–75 days, often with a meeting.
- Submission Issue Requests (SIRs) are also Q-Subs, but reviewer-initiated mid-review.
- Cybersecurity Pre-Subs work best when scoped to 3–5 specific, answerable questions.
There is no meaningful difference — a Pre-Sub is a Q-Sub. Q-Submission (Q-Sub) is the FDA's umbrella program for all pre-market interactions with CDRH/CBER; every submission in the program gets a tracking number starting with "Q". Pre-Submission (Pre-Sub) is the most common type of Q-Sub: a formal written request for FDA feedback on a specific question before you file a 510(k), De Novo, or PMA. For medical device cybersecurity, a Pre-Sub is the right vehicle to de-risk threat model scope, SBOM format, penetration test methodology, or SW96 conformance approach before you burn a review cycle.
People use "Q-Sub" and "Pre-Sub" interchangeably, and in casual conversation that is fine. Technically, Pre-Sub ⊂ Q-Sub — the Q-Sub program contains several submission types, and Pre-Sub is one of them.
For cybersecurity teams, the distinction only matters when you are choosing the right vehicle. A Pre-Sub gets you written FDA feedback and a meeting. Other Q-Sub types (Informational Meeting, Study Risk Determination, Submission Issue Request) have different purposes, timelines, and expectations.
This guide covers the Q-Sub umbrella, where Pre-Sub fits, when to use a Pre-Sub for cybersecurity questions, and what to include so the feedback is actually useful.
Table of Contents
- What is the FDA Q-Submission (Q-Sub) program?
- What is a Pre-Submission (Pre-Sub)?
- Q-Sub vs Pre-Sub: side-by-side comparison
- When should a cybersecurity team file a Pre-Sub?
- What to include in a cybersecurity Pre-Sub
- How Blue Goat Cyber approaches cybersecurity Pre-Subs
- FAQ
Why this matters
The FDA's Q-Submission program is governed by the guidance Requests for Feedback and Meetings for Medical Device Submissions: The Q-Submission Program (most recent revision June 2, 2023, still in force in 2026). Since the February 3, 2026 final premarket cybersecurity guidance took effect, cybersecurity Pre-Subs have become one of the highest-leverage tools MedTech teams have. A single well-scoped Pre-Sub can eliminate an entire deficiency cycle on a 510(k) — saving 60–120 days of review time and avoiding the "restart the clock" penalty that a mid-review pivot triggers. Applicable standards for the substance of what you file include ANSI/AAMI SW96:2023, ANSI/AAMI/IEC 81001-5-1, and AAMI TIR97.
What is the FDA Q-Submission (Q-Sub) program?
The Q-Submission program is the FDA's structured mechanism for any pre-market interaction between a sponsor and CDRH or CBER. It covers written feedback requests, meetings, and reviewer-initiated communications during an active submission. Every item in the program is tracked with a number starting with "Q" (for example, Q240123).
The program includes several distinct submission types:
| Q-Sub Type | Purpose | Who Initiates |
|---|---|---|
| Pre-Submission (Pre-Sub) | Formal request for FDA feedback on specific questions | Sponsor |
| Informational Meeting | Share information with FDA; no feedback requested | Sponsor |
| Study Risk Determination | Confirm whether a study is significant-risk | Sponsor |
| Submission Issue Request (SIR) | Reviewer asks sponsor to fix a specific issue mid-review | FDA reviewer |
| PMA Day 100 Meeting | Statutorily required meeting during PMA review | FDA / sponsor |
| Agreement Meeting / Determination Meeting | PMA-specific pre-planning meetings | Sponsor |
| Breakthrough Device Interactions | Structured feedback for Breakthrough-designated devices | Sponsor |
All of these are Q-Subs. That is why "Q-Sub" alone is ambiguous unless you specify which type.
What is a Pre-Submission (Pre-Sub)?
A Pre-Submission is a formal written request for FDA feedback on specific questions about a device before you submit a marketing application. It is the workhorse of the Q-Sub program and the type most sponsors mean when they say "Q-Sub."
A Pre-Sub typically includes device background, the regulatory pathway you are planning, the specific questions you want FDA to weigh in on, and any supporting artifacts (protocols, draft threat models, test plans). FDA responds in writing within roughly 70–75 calendar days and usually offers a teleconference or written-only response.
The feedback is non-binding but carries substantial weight. If you follow FDA's Pre-Sub advice and document it, the review team will generally honor that position when your 510(k), De Novo, or PMA lands. If you ignore it, expect the same concerns to come back as deficiencies.
Q-Sub vs Pre-Sub: side-by-side comparison
| Dimension | Q-Sub (umbrella) | Pre-Sub (specific type) |
|---|---|---|
| Scope | All pre-market FDA interactions | Written feedback on specific questions |
| Tracking prefix | Q | Q (same — it is a Q-Sub) |
| Who initiates | Sponsor or FDA (depending on type) | Sponsor |
| FDA response format | Varies by type | Written feedback ± meeting |
| Typical timeline | Varies (SIR is days, Breakthrough is ongoing) | ~70–75 calendar days |
| Governing guidance | Q-Submission Program guidance (June 2023) | Same guidance, Section IV |
| Cybersecurity use case | Any FDA cyber interaction | De-risk threat model, SBOM, pen test, SW96 scope |
The one-line rule: every Pre-Sub is a Q-Sub; not every Q-Sub is a Pre-Sub.
When should a cybersecurity team file a Pre-Sub?
See also: FDA SIR Cybersecurity Response: eSTAR Prep Guide, Medical Device Pen Testing: FDA vs EU MDR 2026, and Mining FDA Databases for Cybersecurity Precedent.
File a cybersecurity Pre-Sub when a wrong answer would cost you a review cycle. Good triggers:
- Novel connectivity or architecture (mesh BLE, cellular fallback, cloud-controlled therapy) with no obvious precedent.
- Uncertainty about whether the device falls under Section 524B (borderline "cyber device" definition).
- Deciding between AAMI TIR57 and ANSI/AAMI SW96 as the primary threat model reference.
- Penetration test scope questions on a modular platform where testing every configuration is impractical.
- SBOM format or depth questions for a device with heavy third-party firmware.
- Postmarket monitoring plan design where CVE triage cadence is unclear.
- Predetermined Change Control Plan (PCCP) scope for cybersecurity patches or SBOM component swaps.
Do not file a Pre-Sub for questions the Feb 3, 2026 premarket guidance already answers clearly, or for questions you can resolve by mining FDA databases for precedent. Reviewers dislike Pre-Subs that ask them to re-explain published guidance.
What to include in a cybersecurity Pre-Sub
Keep it tight. A useful cybersecurity Pre-Sub is 15–30 pages, not 150.
- Device description — one page. Intended use, architecture, connectivity, data flows.
- Regulatory strategy — pathway (510(k) / De Novo / PMA), predicate if any, applicable product code.
- Cybersecurity posture summary — standards you are aligning to (SW96, IEC 81001-5-1), SPDF stage.
- Draft artifacts — threat model excerpt, SBOM sample, pen test scope document, postmarket plan outline. Excerpts, not full deliverables.
- Specific questions — 3–5, numbered, each answerable in a paragraph. Avoid "do you have any concerns?"
- Your proposed answer — for each question, state what you plan to do. FDA reviewers strongly prefer confirming or correcting a proposal to writing one from scratch.
Every question in a cybersecurity Pre-Sub should include your proposed answer. Reviewers read "Question / Sponsor's proposed position / Question for FDA" formatting fastest, and it is the difference between a directive response and a hedge.
How Blue Goat Cyber approaches cybersecurity Pre-Subs
We draft cybersecurity Pre-Sub packages in the "Question / Proposed position / Ask" format the FDA reads fastest. Our team pairs an ex-military red team lead (OSCP) with a submission-side regulatory strategist to write the questions, build the supporting excerpts (threat model, SBOM, pen test scope), and rehearse the teleconference. See our FDA premarket cybersecurity services for scope and engagement models.
If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
FAQ
Is a Q-Sub the same as a Pre-Sub?
Not exactly, but close enough that most people use the terms interchangeably. Q-Sub is the umbrella program covering all pre-market FDA interactions. Pre-Sub is the most common type of Q-Sub — a written request for feedback on specific questions. Every Pre-Sub is a Q-Sub, but Q-Subs also include Informational Meetings, Study Risk Determinations, Submission Issue Requests, and Breakthrough interactions.
How long does the FDA take to respond to a Pre-Sub?
FDA targets 70–75 calendar days for a Pre-Sub response, either as written feedback only or as written feedback plus a teleconference. That target is met most of the time, but plan for 90 days when building your submission schedule. Complex cybersecurity questions rarely slip the timeline; scope-of-review disputes sometimes do.
Do I need a Pre-Sub for Section 524B cybersecurity questions?
No, and you should not file one for questions the Feb 3, 2026 premarket cybersecurity guidance already answers. File a Pre-Sub when your device architecture is genuinely novel, when precedent is ambiguous, or when a wrong methodological choice (threat model framework, pen test scope, SBOM depth) would cost you a review cycle.
Is a Submission Issue Request (SIR) the same as a Pre-Sub?
No. Both are Q-Subs, but a SIR is reviewer-initiated mid-review — the FDA reviewer asks you to fix or clarify something specific inside eSTAR before substantive review can continue. A Pre-Sub is sponsor-initiated, filed before the marketing application, and asks the FDA questions rather than answering them.
Can I file a Pre-Sub after I have already submitted my 510(k)?
Not for the same questions. Once a submission is under review, FDA's mechanism for reviewer-driven questions is the SIR, and the sponsor's mechanism for asking new questions is limited. If you need pre-market feedback, file the Pre-Sub before the 510(k). A Pre-Sub filed while a related 510(k) is open will usually be redirected or held.
Ready to plan a cybersecurity Pre-Sub?
If you are weighing a Pre-Sub for a Section 524B question — threat model framework, SBOM scope, pen test methodology, or PCCP design — book a working session with Blue Goat Cyber. We will help you decide whether a Pre-Sub is the right vehicle and draft the questions if it is.
Christian Espinosa, Founder & CEO of Blue Goat Cyber, CISSP · OSCP. Christian has led cybersecurity submissions for connected medical devices across 510(k), De Novo, and PMA pathways, including Q-Sub strategy for novel connectivity and PCCP-scoped cybersecurity changes.
