eSTAR Cybersecurity Section Checklist
Sixteen artifacts FDA reviewers look for in the eSTAR cybersecurity sections. Check what you have; we show you what's missing and where it goes.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
What you'll see after you submit
Check what you have - see the eSTAR cyber readiness ring
- RingScore infographic showing the percentage of the 16 cyber artifacts you have ready.
- Per-artifact list of what's ready vs. missing, with the eSTAR section number for each.
- Reviewer-aligned definition of 'ready' so a half-done draft doesn't count as complete.
- Print-to-PDF audit trail for your internal submission-readiness review.
Common misconceptions
What teams usually get wrong
-
Myth: eSTAR auto-validates our cybersecurity content.
Reality: eSTAR validates structure and required attachments, not content quality. A PDF named 'SBOM.pdf' that's actually a screenshot will pass eSTAR and fail RTA review.
-
Myth: All 16 artifacts must be one document each.
Reality: Some sections accept consolidated documents (e.g., security risk management report can roll up threat model + SBOM analysis). The checklist shows acceptable consolidations.
-
Myth: The architecture diagram is for context, not review.
Reality: Reviewers literally trace threats and controls on your diagram. A vague network diagram is the #1 cause of follow-up AI letters in cybersecurity sections.
-
Myth: If we use a Premarket Cybersecurity Decoder, eSTAR is done.
Reality: Decoders map content to sections; they don't generate the content. You still need each artifact to exist, be current, and match the rest of the submission.
References & further reading
Primary sources behind this tool
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
Close the gaps with the right partner.
FDA premarket cybersecurity services
Full SPDF + eSTAR-ready submission.
Read FDA premarket cybersecurity servicesPremarket cybersecurity checklist
Long-form companion to this tool.
Read Premarket cybersecurity checklistFDA 524B explained
What §524B actually requires, in plain English.
Read FDA 524B explainedMore tools
PCCP, threat model, CVD policy, deficiency triage.
Read More tools