In short
A frequency analysis of FDA cybersecurity deficiency letters, Additional Information requests written on submissions Blue Goat Cyber did not prepare. The webinar ranks the eight findings that come back most often, shows the pattern of what the FDA wrote for each, the root cause in the submission, and the specific artifact that closes it, then ends with five checks to run before a submission goes out.
Key takeaways
1. SBOM (90% of sampled letters)
Rarely missing outright. The SBOM lacks what the FDA asked for: support status and dated end-of-support per component, a machine-readable format such as SPDX or CycloneDX, NTIA minimum elements, and a per-component check against NVD and the CISA KEV catalog.
2. Security controls written as principles (70%)
"Passwords required" without a password policy, or "TLS 1.2" without cipher suites. Give every control a requirement ID at specification level and trace it to the test case that verified it.
3. Cybersecurity labeling (70%)
The same missing-element list recurs almost word for word: ports and interfaces, secure configuration, update notification, backup and restore, forensic logging, an SBOM for users, and end-of-life. Map the labeling to that list one to one.
4. Security and penetration testing (70%)
A vulnerability scan is not a penetration test. Findings include components left out of scope, risk-based excuses for skipping testing, and no independence between testers and designers. The report needs independence, scope, duration, methods and results.
5. Cybersecurity risk assessment (60%)
Usually a method problem: no stated method or acceptance criteria, exploitability not defined, impact written as a system effect instead of patient harm, and risk IDs that don't match across tables.
6. Risk management report, unresolved anomalies and threat model (40-50%)
Reports that point at other documents instead of stating the residual risk conclusion; "no unresolved issues" answers when the FDA means known defects left in the product; and threat models missing the hostile-network assumption, supply chain, decommissioning, or AI-specific threats.
Watch the recording
Recording courtesy of MTEC (Medical Technology Enterprise Consortium). View on MTEC
View the slides
All 24 slides, free to view, download and share as a PDF.

Prefer the file? Open the PDF in a new tab.
What the analysis is based on
The ranking is the share of sampled Additional Information letters that raised each finding: 10 letters on submissions Blue Goat Cyber did not prepare, analyzed in full, spanning software-only, AI-enabled, cloud and on-premise devices, capital equipment, wearables and vital signs monitors, across CDRH and CBER. It is not an industry-wide rate. The same eight findings recur, in roughly the same order, across Christian's review of more than 30 FDA cybersecurity letters. Client names, device names and submission numbers are excluded.
The thread through all eight: traceability
SBOM, traceability, labeling and testing account for most of what comes back. The common thread is traceability: a control traced to a requirement ID, a threat traced through pre- and post-mitigation scores, and a risk traced to a test case. The deck shows Blue Goat Cyber's SW96 security and ISO 14971 safety risk matrices, how one exploitability score feeds both, and a DFD3 data flow diagram of a wireless infusion pump.
Five checks before a submission goes out
Gate the SBOM before it ships. Treat labeling as a checklist, not prose. Trace every control to a test case. Confirm full-system penetration test scope, including bridging components and local agents. Search the submission for likelihood and probability language, because the FDA assesses cybersecurity risk on exploitability.
Holding a deficiency letter now?
Send it to christian@bluegoatcyber.com, anonymized if you prefer. We provide a free gap analysis within 48 hours of receiving your letter.
Go deeper
More sessions on the talks and workshops page.
