
On this page
Published: · Updated:
Key Takeaways
- Divided into distinct sections for submission.
- Enables continuous dialogue with the FDA.
- Offers flexibility in the submission timeline.
- Enhances risk management for complex devices.
- Can improve efficiency and resource allocation.
- Aims for quicker approval for new technologies.
Part of our FDA 2026 medical device cybersecurity submission series. For the full overview, start with FDA Cybersecurity Requirements for Medical Devices (2026).
A modular PMA submission lets a manufacturer submit a Premarket Approval application in separate sections under a plan agreed with the FDA. Modules may cover preclinical evidence, manufacturing information, or clinical results. The FDA can review completed sections while other work continues. This approach supports earlier feedback, but it does not lower the evidence requirements or guarantee faster approval. Cybersecurity evidence must remain consistent across modules as the device changes.
Modular PMA changes when manufacturers submit evidence, not the standard that evidence must meet. For connected devices, the difficult part is keeping the architecture, risk assessment, security testing, and labeling aligned while different sections move through review.
We approach that problem from the cybersecurity side. A reviewed section is not a reason to stop tracking design changes. If a later change affects an earlier security claim, the submission needs to show that connection. The FDA's cybersecurity resources provide the regulatory context; the manufacturer's submission plan determines where the evidence belongs.
Why this matters
A modular approach can expose evidence gaps before the manufacturer submits the complete application. That is useful for software-driven devices, where a change to authentication, firmware updates, or a third-party component can affect several documents at once. Earlier feedback can reduce late rework, but it does not remove the possibility of deficiencies or a negative approval decision.
The FDA's “Cybersecurity in Medical Devices” final guidance from February 3, 2026, describes expectations for lifecycle cybersecurity and supporting documentation. Applicable statutory requirements still apply. Standards such as IEC 81001-5-1 for health software security and ISO 14971 for risk management can help structure the work.
Manufacturers should agree with the FDA on how to distribute that evidence across modules. A dedicated cybersecurity section does not make cybersecurity independent of preclinical testing, manufacturing controls, clinical use, or postmarket planning. Earlier review can support risk reduction, but the filing structure alone cannot prevent postmarket problems or recalls.
Understanding the Basics of a Modular PMA Submission
A Modular PMA Submission lets manufacturers submit completed portions of a PMA while other evidence is still being developed. The approach can suit a long development program in which nonclinical, manufacturing, and clinical data become available at different times.
The submission plan matters more than the module labels. It should identify each module's scope, expected timing, and dependencies. Feedback on one module may affect work planned for another.
Definition of a Modular PMA Submission
A modular PMA is a method for seeking FDA approval, not clearance. Manufacturers divide the application into defined sections rather than submitting the entire package at once.
Review of an individual module does not authorize marketing. The FDA still needs to assess the complete application and determine whether the evidence supports the device's safety and effectiveness.
Importance of a Modular PMA Submission
The main value is earlier review of completed work. Manufacturers can address questions about that evidence while other development activities continue, rather than discovering every issue at the end.
That flexibility also supports resource planning and responses to changing regulatory requirements. It is not permission to change the device without consequences. New findings or technology may require updates to previously submitted information. We recommend treating those dependencies as part of change control from the start.
Components of a Modular PMA Submission
Preclinical, manufacturing, and clinical information are common groupings. The actual module structure should follow the submission plan agreed with the FDA, not a generic template.
Preclinical Module
Preclinical information supports the device's safety and effectiveness before human use. Depending on the device, it can include bench testing, animal studies, testing protocols, and results. A detailed risk assessment should connect identified hazards to controls and supporting evidence.
For cybersecurity, we look for testable claims. “Firmware integrity is checked” does not tell a reviewer whether the device rejects unauthorized code.
On a Class II wearable we tested, the OTA bootloader checked a CRC but did not verify a cryptographic signature. We modified one byte in a captured firmware image; the device installed it and rebooted into the modified firmware. The recommended controls included ECDSA P-256 signature verification in the bootloader and a monotonic version counter for anti-rollback. This was not a modular PMA example, but it illustrates the evidence problem: a stated integrity check is not proof of an effective security control.
Manufacturing Module
Manufacturing information describes facilities, quality control processes, production equipment, and the controls used to produce the device consistently. Supply chain information and contingency planning may also be relevant, depending on the device and submission scope.
We recommend checking how production affects cybersecurity. The design may specify secure configuration, but the manufacturing process must preserve it. Submitted information should make clear how the released hardware, firmware, and configuration relate to the versions covered by the security evidence.
Clinical Module
Clinical information presents human study evidence, including study design, statistical analysis, and patient outcomes. Reviewers need to understand how those results support the intended use and risk-benefit assessment.
Postmarket surveillance plans may also be needed, with their placement determined by the submission plan. For a connected device, clinical and cybersecurity teams should reconcile assumptions about connectivity, alerts, updates, and user actions. A security-related behavior described in the risk assessment should not contradict the device behavior described in clinical documentation or labeling.
Modular Versus Traditional PMA
The choice affects when cybersecurity evidence has to be ready, not whether it is required.
| Traditional PMA | Modular PMA | |
|---|---|---|
| How it is filed | One complete submission | Sections submitted as they are finished |
| Feedback timing | After the full package is reviewed | Per module, as each is reviewed |
| Effect on schedule | Long single review | Earlier feedback, longer total engagement |
| Cybersecurity evidence | Assembled once, near the end | Must be planned so modules stay consistent |
| Main risk | A late finding affects everything | A change in one module invalidates another |
| Suits | Devices with a settled design | Long development programs with staged data |
These are planning contrasts, not fixed outcomes. In either pathway, cybersecurity work should start during design. Assembling the final evidence package near submission is different from postponing the underlying risk analysis and testing until then.
The Process of a Modular PMA Submission
The process starts with an agreed submission plan and continues through module review, responses, and assessment of the complete application. We recommend managing cybersecurity dependencies alongside that regulatory schedule.
Preparing for a Modular PMA Submission
Bring regulatory affairs, engineering, clinical, quality, and cybersecurity owners into planning. Define what each module will contain, who owns the evidence, and which design baseline it describes.
Before filing, we recommend answering four questions:
- Which cybersecurity documents support each module?
- Which requirements, risk identifiers, and test results cross module boundaries?
- What changes would require an earlier document to be reassessed?
- Who decides whether submitted evidence still represents the current device?
A risk assessment and contingency plan should address likely schedule problems as well as technical gaps. If security testing depends on an unfinished update mechanism, that dependency belongs in the plan, not in a last-minute explanation to the reviewer.
Submitting the Modules
Submit each module when it meets the agreed scope and readiness criteria. Filing an unfinished section merely to preserve regulatory momentum can move work into the response cycle rather than save time.
Track submission dates, document versions, reviewer questions, owners, and response deadlines. Keep explanations specific. When a control changes, identify the affected requirement, risk assessment, test evidence, and labeling rather than describing the change only in a cover letter.
Review and Approval Process
The FDA assesses individual modules and how their evidence fits together. Questions may require clarification, additional data, or revisions. Manufacturers should retain a clear record of each exchange and the documents changed in response.
Some applications may involve an advisory committee. Preparation should focus on explaining the evidence and unresolved questions, not simply rehearsing the submission narrative.
Final approval depends on the complete application. Earlier module feedback can help resolve issues, but it does not guarantee the final decision.
Benefits of a Modular PMA Submission
The benefits come from using earlier feedback to improve decisions. Dividing documents into folders, by itself, provides little value.
Flexibility and Efficiency
Manufacturers can submit completed evidence while other work continues. That can help distribute regulatory and technical workloads across a long program.
The schedule is still constrained by module dependencies and the agreed plan. We would not describe modular PMA as working entirely at the manufacturer's own pace. A change to the device can require reassessment of work that appeared finished.
Continuous Interaction with the FDA
See also: Breakthrough Device Designation and Cybersecurity, FDA Penetration Testing Requirements, and Letter to File vs New 510(k).
Module reviews create opportunities to clarify expectations before the full application is complete. Specific questions and documented answers can reduce misunderstandings.
The most useful exchanges concern evidence: whether the scope is adequate, whether a result supports a claim, or whether a change affects an earlier conclusion. A good working relationship helps communication, but it cannot substitute for missing data.
Enhanced Risk Management
Earlier review can reveal weaknesses in risk methods, control specifications, or test coverage while there is still time to address them.
In the FDA letters we reviewed for our September 2026 MTEC webinar, one letter raised insufficient control detail nine separate times against nine different controls in a single submission. The recurring problem was specification-level information: passwords without a stated policy, TLS 1.2 without cipher suites, or ECDSA without the curve and hash function.
Those letters were not presented as a modular PMA dataset. The lesson still applies: resolve the detail behind a control before other modules depend on it. Otherwise, the same gap spreads through requirements, testing, and risk conclusions.
Cost-Effectiveness
Modular review may reduce costs when earlier feedback prevents expensive late changes. It can also help smaller manufacturers distribute work and spending across development stages.
Savings are not automatic. More review interactions, document updates, and cross-module reconciliation also consume resources. We recommend budgeting for those activities rather than assuming that phased filing will shorten time to market.
Challenges in a Modular PMA Submission
The main challenge is maintaining one coherent account of the device while evidence arrives in stages.
Managing the Modular Process
Each module needs an owner, a schedule, and a defined relationship to the others. A delay in one section can affect later submissions, especially when they rely on the same design baseline or test results.
Project tracking tools help, but they do not make technical decisions. Regular reviews should ask what changed and which evidence is affected. Regulatory affairs, R&D, quality, and cybersecurity need the same answer.
This is the part teams skip: checking whether an earlier security conclusion still holds after a later design change.
Ensuring Module Completeness
A document's presence does not establish completeness. A module checklist should examine content, traceability, and consistency, not just filenames.
In the FDA letters we reviewed for our September 2026 MTEC webinar, SBOM findings usually concerned missing information rather than a missing SBOM. Gaps included support status, dated end-of-support information, machine-readable format, NTIA minimum elements, and component-level vulnerability mapping to NVD or the CISA Known Exploited Vulnerabilities catalog.
For modular planning, the practical lesson is to define acceptance criteria before filing and reassess the inventory when the software changes. A previously submitted SBOM does not describe a later build automatically.
Teams must also track current guidance and applicable requirements. An incomplete module can delay review; a material unresolved evidence gap can affect the final approval decision. Internal review and qualified regulatory advice should address those gaps before submission where possible.
Tips for a Successful Modular PMA Submission
We recommend a small set of repeatable controls over a large submission checklist that nobody maintains.
Planning and Organization
Give every module an owner, an evidence baseline, and a readiness review. Set realistic milestones for testing, remediation, and retesting, not just writing and publishing documents.
Maintain a dependency register showing which artifacts support multiple modules. When one changes, use that register to identify the required reviews. Regular meetings should resolve open decisions and assign actions rather than repeat status updates.
Communication with FDA
Use the FDA's pre-submission program, where appropriate, to discuss the proposed submission strategy and focused technical questions.
Prepare questions that explain the device context, the proposed approach, and the uncertainty requiring feedback. Record the answer and its implications for the submission plan. During review, respond directly to the request and identify the supporting evidence.
Quality Control and Assurance
Before submission, check that the data is accurate, the tested version is identified, and the evidence supports the claim being made. Standardized module checklists and internal audits can help catch inconsistencies.
For cybersecurity, we recommend checking the full chain:
- Threat and affected interface.
- Security requirement and implemented control.
- Test case and result.
- Finding, remediation, and retest evidence where applicable.
- Residual risk conclusion and relevant labeling.
Document-management tools can preserve version history and an audit trail. Staff still need training and clear responsibility for reviewing changes. Software cannot decide whether a revised control invalidates an earlier test result.
Conclusion
Modular PMA can make earlier review possible during a long development program. Its value depends on disciplined planning, complete modules, and consistent evidence across the application. It is not a shortcut around the approval standard.
For connected devices, cybersecurity must remain tied to the current design throughout that process. We recommend treating threat models, risk assessments, component inventories, test reports, and labeling as linked records rather than separate submission tasks.
Blue Goat Cyber focuses on medical device cybersecurity, including threat modeling, security risk management, penetration testing, and submission support. We offer fixed-fee engagements and unlimited remediation retesting within the defined premarket service scope. Contact us today for cybersecurity help to discuss your device, evidence gaps, and submission schedule.
How Blue Goat approaches this
We start with the device's architecture and threat model, then assess whether the security evidence covers the relevant interfaces and attack paths. Our focus is cybersecurity, not management of the entire PMA or the manufacturer's verification and validation responsibilities.
We connect threats to control requirements, security test evidence, and risk conclusions. The aim is to make each claim traceable and to identify gaps before the manufacturer files the supporting material.
Our Medical Device Penetration Testing produces evidence tied to the threat model, including reproduction steps, patient-safety impact, risk-file traceability, remediation recommendations, and retest planning. We also support responses to FDA cybersecurity deficiencies. Service scope and commercial terms belong in the engagement agreement; neither testing nor submission support guarantees approval.
If you want one team to own the whole cybersecurity package, see our full-service FDA premarket cybersecurity submission support.
FAQ
What is a Modular PMA Submission?
A Modular PMA Submission is an FDA application method in which manufacturers submit medical device approval information in defined modules, such as preclinical, manufacturing, and clinical information, rather than filing the complete application at once.
What are the benefits of a Modular PMA?
Potential benefits include flexible evidence submission timing, earlier feedback from the FDA, earlier identification of risk and documentation gaps, and better distribution of resources. Faster approval and lower costs are not guaranteed.
Does a Modular PMA replace traditional PMA submissions?
No. Modular PMA is an alternative method for submitting a Premarket Approval application. Both methods seek FDA approval for devices subject to PMA requirements, not clearance.
What components are in a Modular PMA Submission?
Typical components include preclinical information with nonclinical testing, manufacturing information covering production and quality controls, and clinical information presenting human study data and patient outcomes. The actual structure follows the submission plan agreed with the FDA.
How does the FDA review Modular PMA submissions?
The FDA reviews submitted modules and may request clarification or additional information before the application is complete. The agency also assesses how the evidence fits together. Module review does not authorize marketing; approval depends on the complete application.
Is a Modular PMA suitable for all medical devices?
No. It is an option within the PMA pathway, not a submission method for every device. Its suitability depends on the device, development timeline, evidence readiness, and submission plan. It can be useful when substantial data become available in stages.
Related: Medical Device Cybersecurity: A Complete Lifecycle Guide
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
Sources & references
Primary sources cited in this article. Links open in a new tab.
- FDA's cybersecurity resources- U.S. FDA
- Modular PMA Submission- U.S. FDA
