
FDA SIR Cybersecurity Response: eSTAR Prep Guide
FDA Submission Issue Request (SIR) response strategy for cybersecurity: eSTAR prep checklist, common 524B gaps, and how to answer without restarting review.
Read articleEvery article in our archive tagged eSTAR.
eSTAR is the FDA's electronic submission template, and it is required for 510(k) and De Novo submissions. Its cybersecurity section asks targeted questions and expects specific attachments, such as the threat model, risk assessment, SBOM, testing reports and labeling. An incomplete section can stop a submission at the technical screening stage.
The articles below walk through the cybersecurity questions, how to map your documents to them, the differences between IVD and non-IVD templates, and how to handle unresolved anomalies and submission issue requests.
Looking for a quick answer instead? The FDA medical device cybersecurity FAQ covers Section 524B scope, SBOMs, threat models, CR515 and GMLP, deficiencies, and postmarket duties.
Showing 8 of 8 articles tagged eSTAR

FDA Submission Issue Request (SIR) response strategy for cybersecurity: eSTAR prep checklist, common 524B gaps, and how to answer without restarting review.
Read article
Where containers appear in medical devices, the testing the FDA expects under the Feb 3, 2026 guidance, and how container evidence maps to eSTAR v7.0.
Read article
eSTAR v7.0 cybersecurity attachments are identical for IVD and nIVD submissions, but the content reviewers expect is not. Here's how to fill each section correctly.
Read article
What the FDA's Feb 2026 guidance expects in interoperability labeling for connected medical devices, and where each element sits in the eSTAR package.
Read article
What the FDA's Feb 2026 guidance expects in the unresolved cybersecurity anomalies assessment, how to document residual risk, and the deficiency pattern.
Read article
Section 524B(b)(1) makes patchability statutory. What the FDA's Feb 2026 guidance expects in the patch and update mechanism test evidence, the test cases.
Read article
DAST is a subset of FDA-required penetration testing. What the Feb 2026 guidance expects in eSTAR Slot 7, and why a Burp scan alone will fail review.
Read article
Every cybersecurity artifact the FDA expects in an eSTAR 510(k): Cybersecurity attachment mapping, SBOM, threat model, SPDF evidence, and traceability matrix.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ devices supported.