
On this page
Key Takeaways
- Triage in 24 hours: identify which deficiencies need rebuilt artifacts vs updated artifacts.
- A reviewer-ready response is point-by-point, traces back to the original submission, and produces evidence the reviewer can verify in 30 minutes.
- Most deficiencies cluster in three patterns: thin threat model, incomplete pen test, weak postmarket plan. Plan fixes accordingly.
- A 24-hour gap analysis converts panic into a fixed-fee timeline before the 180-day clock burns.
Talk to a MedTech cybersecurity expert
The first 24 hours
When the deficiency letter arrives, the 180-day clock is already running. Within 24 hours you should know:
- Which deficiency items need full artifact rebuilds (e.g., new pen test) and which need updates (e.g., add a missing architecture view).
- Which items have data dependencies (need engineering work) vs documentation dependencies (need writing).
- Whether retesting is required and on what scope.
- A realistic timeline with milestone gates.
Triage: read the letter the way reviewers wrote it
Reviewers reference specific guidance sections. Map each deficiency item to the section it cites and the artifact it implicates. Group items into categories:
- Artifact missing entirely (rebuild from scratch).
- Artifact present but inadequate scope (extend or rerun).
- Artifact present but inconsistent with another artifact (reconcile).
- Documentation gap (write the missing narrative).
- Traceability gap (build the missing matrix entries).
The three deficiency patterns we see most
1. Thin threat model
STRIDE present but not per element, missing architecture views (almost always multi-patient harm or updateability), no traceability matrix. Fix: rebuild the threat model with the four views and the traceability matrix. Time: 3-5 weeks.
2. Incomplete pen test
Scope did not cover full attack surface (cloud or wireless typically), no Letter of Attestation, or methodology was black-box. Fix: scope the missing surface, retest, produce the Letter. Time: 4-6 weeks for the missing surface plus retest of high/critical fixes.
3. Weak postmarket plan
Plan describes intent but not cadence, SLAs, or named owners. Fix: rewrite with monitoring sources, triage SLA, patch cadence, CVD intake, and EOS tracking. Time: 1-2 weeks.
The reviewer-ready response format
A response that gets through second-cycle review without a third cycle has a specific structure:
- Cover letter - identifies the submission, the deficiency letter date, and the response date.
- Point-by-point response document - each deficiency item quoted verbatim, response narrative, references to updated/new artifacts.
- Traceability matrix - deficiency item → response → artifact location.
- Updated artifacts - rebuilt or extended threat model, pen test report, SBOM, postmarket plan, etc.
- Letter of Attestation - if pen test was redone or extended.
- Reviewer-eye narrative - one-page summary the reviewer can read first to orient.
Pathway-specific considerations
510(k) AI letter
Focused on substantial-equivalence-relevant cyber items - threat model alignment to predicate, SBOM completeness, pen test scope. Predicate-comparison narrative is often the missing piece.
De Novo deficiencies
Often probe novel risk arguments and security-architecture justifications. Response needs to strengthen the architecture rationale, not just add documents.
PMA deficiencies
Deepest documentation, full design history file traceability, and frequently coordinate with non-cyber reviewers on risk control and human factors. Response should explicitly address cross-discipline integration.
IDE Clinical Hold (21 CFR §812.42)
Focus on whether unresolved cybersecurity risks could expose study subjects to unreasonable risk. Response demonstrates threat model coverage of the clinical environment, security risk assessment, and any compensating controls before enrollment proceeds.
How fixed-fee response works
After the 24-hour gap analysis, you receive a fixed-fee quote covering: rebuilt or extended artifacts, retesting where required, point-by-point response document, traceability matrix, and reviewer-ready package. Includes one revision pass if the reviewer comes back with follow-up questions; new deficiencies on second cycle are handled under a separate engagement (rare with this approach).
Frequently asked questions
Anatomy of a response that closes the item
Reviewers assess responses against the specific question they asked, not against the general quality of your submission. A response closes when the reviewer can, without hunting, see three things: the direct answer, the changed artifact, and where the change lives.
Structure each item the same way:
- Restate the deficiency verbatim. Do not paraphrase. Paraphrasing is how a response ends up answering a slightly different question than the one asked.
- Answer in the first two sentences. Lead with the conclusion, not the background. "The threat model has been revised to enumerate threats for all four external interfaces, including the previously omitted USB service port" is a better opening than three paragraphs of methodology.
- Name the changed artifact and version. "Threat Model, rev C, Section 4.2, Table 7, rows 41 to 58."
- Attach the revised artifact in full, not an excerpt, and keep revision history visible.
- State what did not change and why, when the reviewer's premise is partly incorrect. Disagreement is acceptable when it is evidenced; silence is not.
When the reviewer's premise is wrong
Occasionally a deficiency rests on a misreading, usually because the information existed but was in an unexpected place. Push back, carefully. Acknowledge the reviewer's concern, point to exactly where the information was located in the original submission, and then make it easier to find anyway by adding a cross-reference or moving the content to the expected attachment.
What does not work is a response that says the information was already provided and stops there. Even when true, it invites a second cycle. Fixing the discoverability problem alongside the factual correction closes the item.
Managing the clock
Interactive review questions typically carry short response windows, and a full deficiency letter puts the submission on hold until you respond. The failure pattern is spending three of your available weeks re-testing and one week writing, then discovering that the new test results contradict an unchanged artifact elsewhere in the package.
Work in the opposite order. Draft the response structure in the first two days, which surfaces every artifact that must change. Run remediation and testing against that list. Reserve the final quarter of the window for a consistency pass across all changed and unchanged documents, because a response that introduces a new inconsistency generates the next letter.
Where to go next
A deficiency letter is a scheduling problem before it is a technical problem. You have 180 days, the technical fixes are usually smaller than they look, and the responses that fail are almost never the ones that ran out of engineering capacity. They are the ones that spent ninety days deciding what the reviewer meant.
Do the interpretation pass in the first week, with the whole team in one room. Read each item twice: once for the literal words, once for the concern behind them. "Provide additional detail on the threat model" is rarely a request for more pages. It usually means a trust boundary was analyzed incompletely, or threats were listed without linking to clinical harm, or the model did not cover the mobile app and cloud backend. Write down your reading of the underlying concern next to each item, and if two people on your team read it differently, that item goes on the Q-Sub or clarification call list rather than into the response draft.
Second, triage by remediation cost, not by item order. Items that need only better documentation of work you already did can be closed in days. Items that need new testing need a lab booking now, because turnaround plus retest plus report writing is measured in weeks. Items that need a design change need an immediate decision on whether you change the design or argue the risk is acceptable, and that decision cannot wait until month four.
Third, write each response so it stands alone. State the concern as you understand it, state what you did, point to the specific attachment and page, and state the residual risk. Reviewers read your response next to the original item, not next to your whole submission. A response that requires them to reconstruct context earns a second letter.
Fourth, check consistency across items before you file. Deficiency responses are written by different people under time pressure, and the fastest way to earn a follow-up is to give two answers that cite different threat model versions or different tested builds.
If the letter arrived this week, book the interpretation session and the test lab in that order, today.
- FDA Cybersecurity Deficiency Response Service - reviewer-intent analysis, remediation, retesting, and a consistent response package inside the 180-day window.
- Premarket FDA Cybersecurity Submission Checklist - the completeness standard your reissued package should meet before it goes back.
- How to Pass FDA 510(k) Cybersecurity on the First Submission - what to do differently on the next program so there is no second letter.


