On this page
Published: July 23, 2026
Key Takeaways
- Three 510(k) types exist: Traditional (90-day goal), Special (30-day goal), and Abbreviated (90-day goal using consensus standards).
- Every 510(k) type is subject to Section 524B and the Feb 3, 2026 the FDA premarket cybersecurity guidance - the pathway does not shrink the artifact list.
- Special 510(k) requires *your own* cleared predicate and well-established evaluation methods; cybersecurity changes that expand attack surface get pushed to Traditional.
- Abbreviated 510(k) trades narrative testing for declarations of conformity to FDA-recognized standards like ANSI/AAMI SW96:2023 and IEC 62304.
- eSTAR is mandatory for all three types since Oct 2023; the cybersecurity section is the most-cited driver of Refuse-To-Accept (RTA) holds.
- A Pre-Sub is the cheapest way to confirm the pathway before you assemble the package.
The FDA recognizes three types of 510(k): Traditional, Special, and Abbreviated. Traditional is the default 90-day pathway for most Class II devices. Special is a 30-day pathway for a manufacturer's own modification to its cleared device using well-established evaluation methods. Abbreviated is a 90-day pathway that leans on FDA-recognized consensus standards. All three must satisfy FD&C Act Section 524B for cyber devices.
Picking the wrong 510(k) type is one of the fastest ways to burn a quarter of your regulatory calendar. A Special 510(k) filed for a change that expands the attack surface will get bumped to Traditional at Acceptance Review. An Abbreviated 510(k) filed without a matching declaration of conformity to a recognized standard will get the same treatment.
Cybersecurity makes the choice harder, not easier. Since the Feb 3, 2026 the FDA final guidance took effect, reviewers scrutinize the security risk profile of the change - not just the code diff.
This guide compares the three 510(k) types on eligibility, review clock, format, and the cybersecurity package each one actually needs.
Table of Contents
- Why This Matters
- What Are the Three Types of 510(k)?
- Traditional vs Special vs Abbreviated: Side-by-Side
- When Do You Use a Traditional 510(k)?
- When Does a Special 510(k) Actually Apply?
- When Is an Abbreviated 510(k) the Right Move?
- How Cybersecurity Requirements Differ by 510(k) Type
- How Blue Goat Approaches This
- FAQ
Why This Matters
The FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Feb 3, 2026 final guidance) applies to every 510(k) - Traditional, Special, and Abbreviated - because Section 524B of the FD&C Act does not distinguish among the three. Reviewers expect the same seven-section cybersecurity package: SPDF documentation, threat model, SBOM, security architecture views, security risk assessment, penetration test evidence, and a postmarket monitoring plan.
The FY2024 CDRH performance report shows cybersecurity remains among the top three deficiency categories cited in 510(k) Acceptance Review holds, behind only software documentation and clinical evidence. That statistic is pathway-agnostic - a Special 510(k) does not get a lighter cybersecurity review, only a faster clock.
Applicable standards include IEC 62304 (software lifecycle), ISO 14971 (risk management), and ANSI/AAMI SW96:2023 (medical device security risk management, which replaced AAMI TIR57 as the primary reference in the 2026 guidance).
What Are the Three Types of 510(k)?
The three 510(k) types are defined in the FDA's guidance The Special 510(k) Program (Sept 2019) and The Abbreviated 510(k) Program (Sept 2019), both of which remain current. They are not different regulatory outcomes - all three result in a "substantially equivalent" clearance decision under 21 USC 360(k). They differ in how you build the case for substantial equivalence and how fast the FDA promises to review it.
Traditional vs Special vs Abbreviated: Side-by-Side
| Dimension | Traditional 510(k) | Special 510(k) | Abbreviated 510(k) |
|---|---|---|---|
| Review clock (MDUFA goal) | 90 FDA days | 30 FDA days | 90 FDA days |
| Predicate | Any legally marketed predicate | Your own cleared device only | Any legally marketed predicate |
| Basis for substantial equivalence | Direct performance comparison | Design controls + risk analysis on your own change | Declaration of conformity to FDA-recognized consensus standard(s) |
| When to use | Default; new device or predicate not yours | Modification to your own device using well-established evaluation methods | Change or new device where a recognized standard fully addresses performance |
| Cybersecurity package | Full seven-section package | Full seven-section package scoped to the change | Full seven-section package + declarations of conformity |
| eSTAR mandatory | Yes (since Oct 2023) | Yes | Yes |
| Common rejection trigger | Missing/weak pen test, incomplete SBOM | Change expands attack surface or alters intended use | Declaration cites a non-recognized version of the standard |
When Do You Use a Traditional 510(k)?
Use a Traditional 510(k) as the default. It applies when you are a first-time submitter for the device, when the predicate belongs to another manufacturer, when your change to a cleared device is significant enough to affect safety or effectiveness, or when no consensus standard fully covers the performance claims you need to make.
Traditional is also the fallback when a Special or Abbreviated submission gets converted by the FDA during Acceptance Review - which happens roughly 20% of the time for Special submissions per the FDA's public 510(k) statistics.
When Does a Special 510(k) Actually Apply?
A Special 510(k) applies when all of the following are true: the modification is to your own legally marketed device, the modification does not alter the intended use, the modification does not alter the fundamental scientific technology, and the performance data needed to evaluate the change comes from well-established evaluation methods whose results can be sufficiently reviewed in a summary or risk-analysis format.
For cybersecurity changes, "well-established evaluation methods" is the sticking point. Rotating a signing certificate under an existing PKI usually qualifies. Adding a new BLE advertising service does not - it expands the attack surface and triggers a new threat-modeling cycle. See our companion post on Special vs Traditional 510(k) for cybersecurity changes for the decision tree.
When Is an Abbreviated 510(k) the Right Move?
An Abbreviated 510(k) is the right move when performance can be demonstrated through conformity to one or more FDA-recognized consensus standards, an FDA-issued guidance document, or a special control. You submit summary reports and declarations of conformity instead of full test reports.
See also: Q-Sub vs Pre-Sub: FDA Cybersecurity Guide, FDA SIR Cybersecurity Response: eSTAR Prep Guide, and Mining FDA Databases for Cybersecurity Precedent.
For a connected medical device, the standards that most often carry the Abbreviated pathway are IEC 62304 for software lifecycle, IEC 81001-5-1 for health-software security, and ANSI/AAMI SW96:2023 for security risk management. Verify the exact recognition number and version on the FDA's Recognized Consensus Standards database before filing - a declaration to an outdated edition is a common RTA trigger.
How Cybersecurity Requirements Differ by 510(k) Type
They do not differ in scope - Section 524B is pathway-agnostic. They differ in format and framing.
Traditional: Full narrative for every artifact. Threat model, SBOM with VEX, security architecture views (global, multi-patient harm, updateability, security use case), security risk assessment, pen test report, and postmarket plan - each with its own detailed evidence.
Special: Same seven artifacts, but scoped to the delta. The threat model updates the sections touched by the change. The SBOM shows before/after. The pen test focuses on the changed surface. Reviewers still expect a complete, standalone cybersecurity section in eSTAR.
Abbreviated: Same seven artifacts, but performance claims can reference a declaration of conformity. The SBOM and pen test still need to be filed as evidence - the standard does not replace them, it just lets you point to it for methodology.
[KEY REQUIREMENT] Regardless of type, every 510(k) for a "cyber device" (as defined in Section 524B(c)) must include: a plan to monitor, identify, and address postmarket cybersecurity vulnerabilities; a process for CVD; and an SBOM. Omit any of the three and the submission is rejected at Acceptance Review.
How Blue Goat Approaches This
Blue Goat Cyber's medical device practice is led by engineers with CISSP, OSCP, and prior military red-team backgrounds. We start every engagement with a pathway assessment - Traditional, Special, or Abbreviated - because the cybersecurity package needs to be scoped to the clock and the format the FDA expects, not built generically and reshaped later.
For clients unsure of the right pathway, we prepare a targeted Pre-Sub to confirm it with the FDA before assembling the full submission. Every artifact - threat model, SBOM, security risk assessment, penetration test, labeling - traces back to a controlled requirement and a verified result, aligned with the Feb 3, 2026 guidance. See our FDA premarket cybersecurity services for scope. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
FAQ
What are the three types of 510(k) submissions?
The FDA recognizes Traditional, Special, and Abbreviated 510(k) submissions. Traditional is the default 90-day pathway. Special is a 30-day pathway limited to a manufacturer's own modification to its cleared device using well-established evaluation methods. Abbreviated is a 90-day pathway that relies on declarations of conformity to FDA-recognized consensus standards, guidance documents, or special controls.
Does the cybersecurity package change with 510(k) type?
No. Section 524B applies to every 510(k) type, so the seven-section cybersecurity package - SPDF documentation, threat model, SBOM, architecture views, security risk assessment, penetration test, and postmarket plan - is required in all three. Only the depth of narrative changes: Special scopes to the delta, Abbreviated can reference consensus standards, Traditional requires full narrative.
Is a Special 510(k) always faster than a Traditional?
Only if the FDA accepts it as a Special. Roughly one in five Special 510(k) submissions is converted to Traditional at Acceptance Review, restarting the clock at 90 days. For cybersecurity changes, submitting a Pre-Sub before filing is the reliable way to confirm the pathway.
Can I file an Abbreviated 510(k) for a connected medical device?
Yes, if FDA-recognized consensus standards cover the performance you need to demonstrate. For connected devices, IEC 62304, IEC 81001-5-1, and ANSI/AAMI SW96:2023 are the standards most commonly used. Verify the recognition number and edition on the FDA's Recognized Consensus Standards database before submitting.
Is eSTAR required for all three 510(k) types?
Yes. Since Oct 1, 2023, eSTAR has been mandatory for all 510(k) submissions - Traditional, Special, and Abbreviated. The cybersecurity section within eSTAR is identical across the three types and is the most-cited driver of Refuse-To-Accept holds.
Ready to Confirm the Right 510(k) Type?
If you are weighing Traditional, Special, or Abbreviated for an upcoming submission, we will map your change to the right pathway and build the cybersecurity package to match. Schedule a discovery session - and if the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.
Related:
- Special vs Traditional 510(k) for cybersecurity changes
- Letter to File vs new 510(k) for cybersecurity changes
- Preparing your eSTAR 510(k) cybersecurity documentation
- 510(k) cybersecurity deficiencies that trigger the FDA holds
- Q-Sub vs Pre-Sub: FDA cybersecurity guide
About the Author
Christian Espinosa, CISSP, Founder, Blue Goat Cyber. Christian leads a team focused exclusively on medical device cybersecurity for FDA premarket submissions and postmarket compliance across Traditional, Special, and Abbreviated 510(k) pathways. Read more about Christian.
