Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Blog · FDA

    Q-Sub vs Pre-Sub: FDA Cybersecurity Feedback Guide

    Q-Sub vs Pre-Sub for FDA cybersecurity: what they are, how they differ, and when to use a Pre-Submission to de-risk Section 524B threat models, SBOMs, and pen tests.

    Two overlapping regulatory document silhouettes representing FDA Q-Submission and Pre-Submission pathways
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Published: July 22, 2026

    Key Takeaways

    • Q-Sub is the umbrella program; Pre-Sub is the most common submission type inside it.
    • Every Q-Sub type gets a "Q" tracking number, which is why people conflate the terms.
    • Pre-Subs are the right vehicle for FDA feedback on cybersecurity strategy before filing.
    • FDA typically responds to a Pre-Sub within 70–75 days, often with a meeting.
    • Submission Issue Requests (SIRs) are also Q-Subs, but reviewer-initiated mid-review.
    • Cybersecurity Pre-Subs work best when scoped to 3–5 specific, answerable questions.
    Direct Answer

    There is no meaningful difference — a Pre-Sub is a Q-Sub. Q-Submission (Q-Sub) is the FDA's umbrella program for all pre-market interactions with CDRH/CBER; every submission in the program gets a tracking number starting with "Q". Pre-Submission (Pre-Sub) is the most common type of Q-Sub: a formal written request for FDA feedback on a specific question before you file a 510(k), De Novo, or PMA. For medical device cybersecurity, a Pre-Sub is the right vehicle to de-risk threat model scope, SBOM format, penetration test methodology, or SW96 conformance approach before you burn a review cycle.

    People use "Q-Sub" and "Pre-Sub" interchangeably, and in casual conversation that is fine. Technically, Pre-Sub ⊂ Q-Sub — the Q-Sub program contains several submission types, and Pre-Sub is one of them.

    For cybersecurity teams, the distinction only matters when you are choosing the right vehicle. A Pre-Sub gets you written FDA feedback and a meeting. Other Q-Sub types (Informational Meeting, Study Risk Determination, Submission Issue Request) have different purposes, timelines, and expectations.

    This guide covers the Q-Sub umbrella, where Pre-Sub fits, when to use a Pre-Sub for cybersecurity questions, and what to include so the feedback is actually useful.

    Table of Contents

    Why this matters

    The FDA's Q-Submission program is governed by the guidance Requests for Feedback and Meetings for Medical Device Submissions: The Q-Submission Program (most recent revision June 2, 2023, still in force in 2026). Since the February 3, 2026 final premarket cybersecurity guidance took effect, cybersecurity Pre-Subs have become one of the highest-leverage tools MedTech teams have. A single well-scoped Pre-Sub can eliminate an entire deficiency cycle on a 510(k) — saving 60–120 days of review time and avoiding the "restart the clock" penalty that a mid-review pivot triggers. Applicable standards for the substance of what you file include ANSI/AAMI SW96:2023, ANSI/AAMI/IEC 81001-5-1, and AAMI TIR97.

    What is the FDA Q-Submission (Q-Sub) program?

    The Q-Submission program is the FDA's structured mechanism for any pre-market interaction between a sponsor and CDRH or CBER. It covers written feedback requests, meetings, and reviewer-initiated communications during an active submission. Every item in the program is tracked with a number starting with "Q" (for example, Q240123).

    The program includes several distinct submission types:

    Q-Sub Type Purpose Who Initiates
    Pre-Submission (Pre-Sub) Formal request for FDA feedback on specific questions Sponsor
    Informational Meeting Share information with FDA; no feedback requested Sponsor
    Study Risk Determination Confirm whether a study is significant-risk Sponsor
    Submission Issue Request (SIR) Reviewer asks sponsor to fix a specific issue mid-review FDA reviewer
    PMA Day 100 Meeting Statutorily required meeting during PMA review FDA / sponsor
    Agreement Meeting / Determination Meeting PMA-specific pre-planning meetings Sponsor
    Breakthrough Device Interactions Structured feedback for Breakthrough-designated devices Sponsor

    All of these are Q-Subs. That is why "Q-Sub" alone is ambiguous unless you specify which type.

    What is a Pre-Submission (Pre-Sub)?

    A Pre-Submission is a formal written request for FDA feedback on specific questions about a device before you submit a marketing application. It is the workhorse of the Q-Sub program and the type most sponsors mean when they say "Q-Sub."

    A Pre-Sub typically includes device background, the regulatory pathway you are planning, the specific questions you want FDA to weigh in on, and any supporting artifacts (protocols, draft threat models, test plans). FDA responds in writing within roughly 70–75 calendar days and usually offers a teleconference or written-only response.

    The feedback is non-binding but carries substantial weight. If you follow FDA's Pre-Sub advice and document it, the review team will generally honor that position when your 510(k), De Novo, or PMA lands. If you ignore it, expect the same concerns to come back as deficiencies.

    Q-Sub vs Pre-Sub: side-by-side comparison

    Dimension Q-Sub (umbrella) Pre-Sub (specific type)
    Scope All pre-market FDA interactions Written feedback on specific questions
    Tracking prefix Q Q (same — it is a Q-Sub)
    Who initiates Sponsor or FDA (depending on type) Sponsor
    FDA response format Varies by type Written feedback ± meeting
    Typical timeline Varies (SIR is days, Breakthrough is ongoing) ~70–75 calendar days
    Governing guidance Q-Submission Program guidance (June 2023) Same guidance, Section IV
    Cybersecurity use case Any FDA cyber interaction De-risk threat model, SBOM, pen test, SW96 scope

    The one-line rule: every Pre-Sub is a Q-Sub; not every Q-Sub is a Pre-Sub.

    When should a cybersecurity team file a Pre-Sub?

    See also: FDA SIR Cybersecurity Response: eSTAR Prep Guide, Medical Device Pen Testing: FDA vs EU MDR 2026, and Mining FDA Databases for Cybersecurity Precedent.

    File a cybersecurity Pre-Sub when a wrong answer would cost you a review cycle. Good triggers:

    • Novel connectivity or architecture (mesh BLE, cellular fallback, cloud-controlled therapy) with no obvious precedent.
    • Uncertainty about whether the device falls under Section 524B (borderline "cyber device" definition).
    • Deciding between AAMI TIR57 and ANSI/AAMI SW96 as the primary threat model reference.
    • Penetration test scope questions on a modular platform where testing every configuration is impractical.
    • SBOM format or depth questions for a device with heavy third-party firmware.
    • Postmarket monitoring plan design where CVE triage cadence is unclear.
    • Predetermined Change Control Plan (PCCP) scope for cybersecurity patches or SBOM component swaps.

    Do not file a Pre-Sub for questions the Feb 3, 2026 premarket guidance already answers clearly, or for questions you can resolve by mining FDA databases for precedent. Reviewers dislike Pre-Subs that ask them to re-explain published guidance.

    What to include in a cybersecurity Pre-Sub

    Keep it tight. A useful cybersecurity Pre-Sub is 15–30 pages, not 150.

    1. Device description — one page. Intended use, architecture, connectivity, data flows.
    2. Regulatory strategy — pathway (510(k) / De Novo / PMA), predicate if any, applicable product code.
    3. Cybersecurity posture summary — standards you are aligning to (SW96, IEC 81001-5-1), SPDF stage.
    4. Draft artifacts — threat model excerpt, SBOM sample, pen test scope document, postmarket plan outline. Excerpts, not full deliverables.
    5. Specific questions — 3–5, numbered, each answerable in a paragraph. Avoid "do you have any concerns?"
    6. Your proposed answer — for each question, state what you plan to do. FDA reviewers strongly prefer confirming or correcting a proposal to writing one from scratch.
    Key requirement

    Every question in a cybersecurity Pre-Sub should include your proposed answer. Reviewers read "Question / Sponsor's proposed position / Question for FDA" formatting fastest, and it is the difference between a directive response and a hedge.

    How Blue Goat Cyber approaches cybersecurity Pre-Subs

    We draft cybersecurity Pre-Sub packages in the "Question / Proposed position / Ask" format the FDA reads fastest. Our team pairs an ex-military red team lead (OSCP) with a submission-side regulatory strategist to write the questions, build the supporting excerpts (threat model, SBOM, pen test scope), and rehearse the teleconference. See our FDA premarket cybersecurity services for scope and engagement models.

    If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.

    FAQ

    Is a Q-Sub the same as a Pre-Sub?

    Not exactly, but close enough that most people use the terms interchangeably. Q-Sub is the umbrella program covering all pre-market FDA interactions. Pre-Sub is the most common type of Q-Sub — a written request for feedback on specific questions. Every Pre-Sub is a Q-Sub, but Q-Subs also include Informational Meetings, Study Risk Determinations, Submission Issue Requests, and Breakthrough interactions.

    How long does the FDA take to respond to a Pre-Sub?

    FDA targets 70–75 calendar days for a Pre-Sub response, either as written feedback only or as written feedback plus a teleconference. That target is met most of the time, but plan for 90 days when building your submission schedule. Complex cybersecurity questions rarely slip the timeline; scope-of-review disputes sometimes do.

    Do I need a Pre-Sub for Section 524B cybersecurity questions?

    No, and you should not file one for questions the Feb 3, 2026 premarket cybersecurity guidance already answers. File a Pre-Sub when your device architecture is genuinely novel, when precedent is ambiguous, or when a wrong methodological choice (threat model framework, pen test scope, SBOM depth) would cost you a review cycle.

    Is a Submission Issue Request (SIR) the same as a Pre-Sub?

    No. Both are Q-Subs, but a SIR is reviewer-initiated mid-review — the FDA reviewer asks you to fix or clarify something specific inside eSTAR before substantive review can continue. A Pre-Sub is sponsor-initiated, filed before the marketing application, and asks the FDA questions rather than answering them.

    Can I file a Pre-Sub after I have already submitted my 510(k)?

    Not for the same questions. Once a submission is under review, FDA's mechanism for reviewer-driven questions is the SIR, and the sponsor's mechanism for asking new questions is limited. If you need pre-market feedback, file the Pre-Sub before the 510(k). A Pre-Sub filed while a related 510(k) is open will usually be redirected or held.

    Ready to plan a cybersecurity Pre-Sub?

    If you are weighing a Pre-Sub for a Section 524B question — threat model framework, SBOM scope, pen test methodology, or PCCP design — book a working session with Blue Goat Cyber. We will help you decide whether a Pre-Sub is the right vehicle and draft the questions if it is.


    Christian Espinosa, Founder & CEO of Blue Goat Cyber, CISSP · OSCP. Christian has led cybersecurity submissions for connected medical devices across 510(k), De Novo, and PMA pathways, including Q-Sub strategy for novel connectivity and PCCP-scoped cybersecurity changes.

    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.