FDA Deficiency Letter vs RTA vs Hold
FDA Deficiency Letter, RTA, and Hold Letter explained side-by-side. What each one means, the clock impact, and how to respond without losing months.
Read articleDeep dives on FDA expectations, threat modeling, penetration testing, SDLC, and the standards your team is being asked to meet.
Showing 12 of 292 articles · Page 8 of 25
FDA Deficiency Letter, RTA, and Hold Letter explained side-by-side. What each one means, the clock impact, and how to respond without losing months.
Read article
Every cybersecurity artifact the FDA expects in an eSTAR 510(k): Section Q mapping, SBOM, threat model, SPDF evidence, and traceability matrix.
Read article
Brainjacking is unauthorized control of an implanted neurostimulator. We unpack attack vectors, clinical consequences, and what FDA reviewers expect.
Read article
FDA postmarket cybersecurity guidance for cleared medical devices: SBOM monitoring, validated patches, CVD, and 21 CFR Part 806 reporting under Section 524B.
Read article
When penetration test reports are vague, incomplete, or written to enterprise IT standards rather than medical device requirements, FDA reviewers issue.
Read article
Receiving an FDA cybersecurity Additional Information Request (AIR) doesn't mean your submission is dead. Aligned with the FDA's Feb 3, 2026 premarket.
Read article
Why ISO 27001 and SOC 2 don't satisfy FDA medical device cybersecurity: the gaps in Section 524B evidence and what reviewers require instead.
Read article
Understanding what causes the FDA to issue a cybersecurity deficiency for medical devices starts with one uncomfortable truth: most deficiencies have.
Read article
FDA 510(k) cybersecurity requirements - threat model, SBOM, testing, postmarket plan - scaled across 510(k), De Novo, and PMA pathways under Section 524B.
Read article
FDA cybersecurity documentation requirements (2026): SPDF artifacts, Section 524B evidence, SBOM, threat model, testing, and labeling reviewers expect.
Read article
Performing a thorough cybersecurity risk analysis for a medical device isn't optional once your product qualifies under Section 524B of the FD&C Act.
Read article
The four SBOM elements FDA reviewers verify at RTA screening under Section 524B: format (CycloneDX/SPDX), identifiers (PURL/CPE), vuln disposition, update process.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.