What the FDA actually wrote
Anonymized excerpts from ten FDA cybersecurity deficiency letters we reviewed in full, grouped by the eight findings that come back most often.
For the full analysis and the five checks to run before you submit, read 8 FDA Cybersecurity Deficiencies, Ranked From Real Letters.
1. SBOM
9 of 10 lettersWhat the FDA wrote
The SBOM does not carry the data the FDA asked for. It is rarely missing outright.
From one letter: One letter named components 10 and 16 years past end of life, with CVE scores of 7.5 and 7.8 and no compensating-control justification.
Root cause: Support status and dated end of support missing, a PDF instead of a machine-readable file, NTIA minimum elements missing, and no per-component check against NVD and CISA KEV.
What closes it: A machine-readable SBOM (SPDX or CycloneDX) with support status, dated end of support, NTIA minimum elements, and a per-component vulnerability assessment.
2. Security controls written as principles
7 of 10 lettersWhat the FDA wrote
Only a high-level description was provided, so the adequacy of the control cannot be determined.
From one letter: One letter raised this same finding nine separate times against nine different controls in a single submission.
Root cause: Controls stated as goals: passwords required with no password policy, TLS 1.2 named without cipher suites, ECDSA cited without the curve or hash.
What closes it: Every control given a unique requirement ID at specification level, traced to the test case that verified it.
3. Cybersecurity labeling
7 of 10 lettersWhat the FDA wrote
The labeling plan is not labeling. Does the content actually reach the customer?
From one letter: One letter listed fourteen separate missing labeling elements for a single device.
Root cause: The same missing elements recur: ports and interfaces, secure configuration, update notification, anomalous-condition behavior, backup and restore, forensics, a user-facing SBOM, and end of life.
What closes it: A labeling checklist mapped one to one against the FDA's expected elements and verified in the customer-facing document itself.
4. Security and penetration testing
7 of 10 lettersWhat the FDA wrote
Vulnerability scanning is not a substitute for penetration testing. A scan identifies known vulnerabilities; a penetration test demonstrates impact.
From one letter: One letter cited a local agent bridging the browser to physical scales and label printers that was left out of test scope entirely.
Root cause: Scope gaps, risk-based justifications for skipping testing, and no independence between testers and the design team.
What closes it: A full-system penetration test report covering tester independence and expertise, scope, duration, methods, and results.
5. Cybersecurity risk assessment
6 of 10 lettersWhat the FDA wrote
No stated methodology or acceptance criteria, and impact written as a system effect rather than patient harm.
From one letter: One letter singled out full system control rated as Medium impact, a system effect rather than a patient-harm outcome.
Root cause: Exploitability claimed without defining it, risk IDs that do not match across tables, and no trace from a risk to a requirement.
What closes it: A documented method (CVSS, AAMI TIR57, or ANSI/AAMI SW96) with matched risk IDs and pre- and post-mitigation levels.
6. Cybersecurity risk management report
5 of 10 lettersWhat the FDA wrote
The report points at other documents instead of standing on its own.
From one letter: Several letters flagged that no security risk process ran alongside the safety risk process at all.
Root cause: Summarizing the scope of each supporting document instead of its outcome and the residual risk conclusion.
What closes it: One report stating the evaluation methods, the residual risk conclusion, and the mitigations performed, traced across the threat model, risk assessment, SBOM, and testing.
7. Unresolved anomalies
5 of 10 lettersWhat the FDA wrote
Answering that there are no unresolved cybersecurity issues is not responsive. The FDA means known software defects deliberately left in the product.
From one letter: The mirror-image mistake showed up repeatedly: functional bugs listed with no security-impact assessment attached.
Root cause: Anomalies assessed in isolation instead of against the risk management file.
What closes it: An anomaly-by-anomaly write-up: description, how it was found, root cause, safety and effectiveness impact, and a risk-based rationale for not fixing it.
8. Threat model
4 of 10 lettersWhat the FDA wrote
The assumption that the network is hostile is not stated.
From one letter: Across the AI-enabled devices in the set, data poisoning, model inversion, and model evasion were consistently missing.
Root cause: Supply chain, decommissioning, and end-to-end infrastructure left out.
What closes it: A threat model that states the hostile-network assumption, covers the full lifecycle, and names AI-specific threats where relevant.
Holding a letter right now?
Paste in your deficiency items for a free triage, or check how ready your package is before you submit. The FDA gives you 180 days to respond.
Examples describe patterns in past letters. They do not predict what the FDA will ask about any specific device.
Get FDA cleared without the cybersecurity headaches.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.
