eSTAR Cybersecurity Section Checklist
Sixteen artifacts FDA reviewers look for in the eSTAR cybersecurity sections. Check what you have; we show you what's missing and where it goes.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
What you'll see after you submit
Check what you have - see the eSTAR cyber readiness ring
- RingScore infographic showing the percentage of the 16 cyber artifacts you have ready.
- Per-artifact list of what's ready vs. missing, with the eSTAR section number for each.
- Reviewer-aligned definition of 'ready' so a half-done draft doesn't count as complete.
- Print-to-PDF audit trail for your internal submission-readiness review.
Common misconceptions
What teams usually get wrong
-
Myth: eSTAR auto-validates our cybersecurity content.
Reality: eSTAR validates structure and required attachments, not content quality. A PDF named 'SBOM.pdf' that's actually a screenshot will pass eSTAR and fail RTA review.
-
Myth: All 16 artifacts must be one document each.
Reality: Some sections accept consolidated documents (e.g., security risk management report can roll up threat model + SBOM analysis). The checklist shows acceptable consolidations.
-
Myth: The architecture diagram is for context, not review.
Reality: Reviewers literally trace threats and controls on your diagram. A vague network diagram is the #1 cause of follow-up AI letters in cybersecurity sections.
-
Myth: If we use a Premarket Cybersecurity Decoder, eSTAR is done.
Reality: Decoders map content to sections; they don't generate the content. You still need each artifact to exist, be current, and match the rest of the submission.
References & further reading
Primary sources behind this tool
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
Close the gaps with the right partner.
FDA premarket cybersecurity services
Full SPDF + eSTAR-ready submission.
Learn morePremarket cybersecurity checklist
Long-form companion to this tool.
Learn moreFDA 524B explained
What §524B actually requires, in plain English.
Learn moreMore tools
PCCP, threat model, CVD policy, deficiency triage.
Learn more