Sixteen artifacts FDA reviewers look for in the eSTAR cybersecurity sections. Check what you have; we show you what's missing and where it goes.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
What you'll see after you submit
Common misconceptions
Myth: eSTAR auto-validates our cybersecurity content.
Reality: eSTAR validates structure and required attachments, not content quality. A PDF named 'SBOM.pdf' that's actually a screenshot will pass eSTAR and fail RTA review.
Myth: All 16 artifacts must be one document each.
Reality: Some sections accept consolidated documents (e.g., security risk management report can roll up threat model + SBOM analysis). The checklist shows acceptable consolidations.
Myth: The architecture diagram is for context, not review.
Reality: Reviewers literally trace threats and controls on your diagram. A vague network diagram is the #1 cause of follow-up AI letters in cybersecurity sections.
Myth: If we use a Premarket Cybersecurity Decoder, eSTAR is done.
Reality: Decoders map content to sections; they don't generate the content. You still need each artifact to exist, be current, and match the rest of the submission.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
Full SPDF + eSTAR-ready submission.
Read FDA premarket cybersecurity servicesLong-form companion to this tool.
Read Premarket cybersecurity checklistWhat §524B actually requires, in plain English.
Read FDA §524B explainedPCCP, threat model, CVD policy, deficiency triage.
Read More tools