You Got an FDA Cybersecurity Deficiency Letter. Now What?
You have 180 calendar days from the date of the letter, and no extensions are granted. FDA's own 510(k) submission process page is unambiguous: an Additional Information request "places the submission on hold", the submitter "has 180 calendar days from the date of the AI Request to submit a complete response", and if FDA does not receive a complete response to all deficiencies within that window "the submission will be considered withdrawn and deleted from our review system." The word doing the most work in that sentence is complete. The instinct after a cybersecurity deficiency letter is to answer fast and answer partially, on the theory that momentum helps. It does the opposite. The clock does not restart for a second attempt, and a response that resolves four of six deficiencies is, procedurally, not a response at all.
Below: which of the three FDA holds you are actually in, what the clock does to your review timeline, how to read a deficiency the way it was written, why cybersecurity deficiencies cluster in the same three places, and when the right move is to withdraw rather than respond.
Key takeaways
- An Additional Information request gives you 180 calendar days, with no extensions, and a missed deadline means the submission is withdrawn and deleted.
- FDA calls these letters "additional information letters" for 510(k) and De Novo submissions and "major deficiency letters" for PMA and HDE.
- The MDUFA decision goal is 90 FDA Days, and days on hold for an AI request are excluded from that count, so the hold is your delay, not FDA's.
- FDA's deficiency guidance says an effective deficiency includes an explicit request plus "potential alternate ways of satisfying the issue, if applicable", and that qualifier is the sentence most responses ignore.
- The current premarket cybersecurity guidance is the February 2026 edition. If your team is working from the June 2025 one, it is working from a superseded document.
First, work out which hold you are in
Three different FDA actions get called a deficiency letter in hallway conversation, and they are not the same thing. Confusing them wastes days you do not have.
Technical screening hold on an eSTAR. FDA states that eSTAR submissions "are not anticipated to undergo a refuse to accept (RTA) process", but that an incomplete eSTAR draws an email identifying the incomplete information, with the 510(k) placed and remaining on hold until a complete replacement eSTAR is submitted. If a replacement is not received within 180 days of the technical screening deficiency notification, the submission is considered withdrawn and closed. This is a completeness check, not a review finding: nobody has evaluated your cybersecurity content yet, and the fix is a complete replacement rather than an argument.
RTA hold. For eCopy submissions, a lead reviewer runs an acceptance review against FDA's Refuse to Accept checklist, and the submitter receives the result within 15 days of receipt. A submission not accepted goes on RTA Hold with 180 calendar days to fully address the cited deficiencies, failing which it is withdrawn and deleted. Again, a threshold check rather than a substantive review.
The AI request or major deficiency letter. This is the one this article is about. It arrives out of substantive review, after a reviewer has read your content and formed a view. FDA's least burdensome deficiencies guidance sets out the naming: deficiency letters "generally include at least one major issue and place the marketing application on hold pending FDA's receipt of the requested additional information", and FDA "refers to PMA and HDE deficiency letters as 'major deficiency letters' and 510(k) and De Novo deficiency letters as 'additional information letters' or 'requests for additional information.'"
If you are not sure which you received, the tell is timing and content. A technical screening or acceptance letter arrives early and lists missing items. An AI request arrives out of substantive review and argues with your content.
What the hold does to your timeline
FDA's stated goal is a MDUFA decision within 90 FDA Days, and FDA Days are calculated as calendar days between receipt and decision "excluding the days the submission was on hold for an AI request." If FDA misses 100 FDA days, it issues a Missed MDUFA Communication with written feedback and an estimated completion date.
Read the exclusion carefully, because it is the whole economics of the situation. Once the letter lands, the agency's clock stops and yours starts. Every day your team spends deciding who owns the response, whether to re-test, and whether to argue or comply is a day added to your submission with no corresponding pressure on the reviewer. The 180-day allowance is generous precisely because it is entirely yours to burn.
Two consequences follow. First, the interactive route is worth protecting. FDA's substantive interaction, which should occur within 60 calendar days of receipt, is either an email saying outstanding deficiencies will be resolved through interactive review without a hold, or an AI request that imposes one. A submission whose cybersecurity documentation is coherent enough that remaining questions can be handled by email keeps the clock running. That is not a reason to over-document; it is a reason to make the traceability legible.
Second, the response deadline is a project deadline, not a paperwork deadline. If a deficiency requires new penetration testing evidence on a device build, the scheduling of that testing is the critical path, not the writing.
Read the deficiency the way it was written
FDA's deficiency guidance describes the structure reviewers are asked to use, and knowing it turns an opaque letter into a checklist. An effective deficiency should concisely include four elements: acknowledgment of what was submitted, "identification of a specific issue or concern with information that was submitted, is missing, or is inadequate", a statement of the basis for the deficiency including its effect or impact on the marketing authorization decision, and "explicit request for the additional information needed to address the issue and potential alternate ways of satisfying the issue, if applicable."
Three practical moves fall out of that structure.
Answer element two, not element four alone. The explicit request tells you what FDA asked for. The identified concern tells you what FDA is worried about. Responses that supply the requested artifact without addressing the concern come back, because the concern was the point.
Take the alternate ways seriously when they are offered. That clause exists because the least burdensome provisions oblige FDA to consider alternative approaches to resolving regulatory issues. If the letter names an alternative that is cheaper for you than the primary request, taking it is not a lesser answer.
Distinguish deficiencies from additional considerations. FDA's guidance notes that additional considerations may be included in a deficiency letter if unresolved after interactive review "but would not require an applicant response". Answering everything on the page as though it were a deficiency is common, and it inflates the response without improving it.
The response format FDA publishes, and almost nobody uses
FDA does not leave the shape of your response to taste: it recommends that applicants restate the identified Agency issue and then provide one of exactly three things, "the information or data requested", "an explanation why the issue does not affect or impact the marketing authorization decision", or "alternative information and an explanation describing why the information adequately addresses the issue", together with "the deficiency number and an identical restatement of the Agency's question". Use their numbering, not yours.
The middle option is the one cybersecurity responses underuse. Where a deficiency rests on a premise that does not hold for your device, an explanation of why the issue does not affect the marketing authorization decision is a sanctioned answer rather than a fight to be avoided.
The third carries a burden worth knowing before you pick it. FDA's words are that where an alternative approach is taken, "you should discuss how the included information satisfies applicable statutory and regulatory criteria for the marketing authorization decision." Alternative information without that discussion reads as non-responsive.
Where cybersecurity deficiencies actually cluster
We are describing where questions land, not making a claim about rates, which nobody outside FDA can substantiate.
The current guidance, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, was issued on February 3, 2026 and supersedes the June 27, 2025 edition of the same guidance under its previous title. Check which edition your regulatory file cites before you respond to anything, because a response arguing from a superseded document is an avoidable own goal.
Three areas in that guidance are where the documentation obligations interlock, and interlocking obligations are where gaps show.
Traceability. The guidance asks manufacturers to "provide traceability between the threat model, cybersecurity risk assessment, SBOM, and testing documentation" as well as other risk management documentation. Each artifact can be individually excellent and the set can still fail this, because traceability is a property of the relationships between them. It is also the single hardest thing to retrofit inside a 180-day window.
Testing evidence, including who did the testing. The guidance asks for penetration test reports containing the independence and technical expertise of testers, the scope of testing, the duration, the methods employed, and the results, findings and observations. It also asks manufacturers to indicate by whom testing was performed and what level of independence those responsible for testing had from the developers who designed the device, and to provide the original third-party report where third parties were used. A report that lists findings but not scope, duration or tester independence is missing elements FDA named. That is penetration testing delivered to a documentation standard, and it is worth scoping the test against the report format before the test rather than after.
Rationale for what you did not fix. The guidance asks for the manufacturer's assessment of findings including rationales for not implementing or deferring any of them. Silence on a finding reads as an omission; a documented rationale reads as a decision.
Underneath all three sits the statutory floor of section 524B, the postmarket vulnerability plan, the cybersecure processes and the software bill of materials, which our FDA cybersecurity practice covers and this article deliberately does not restate.
The honest part: what nobody can promise you
Several things are true here that a firm selling remediation would rather not say.
No consultant can promise clearance, and none can promise a single review cycle. The decision is FDA's, the review is substantive, and a well-built response can still draw a second AI request if the reviewer's concern was not what everyone assumed. Anyone quoting you a guaranteed outcome is describing something FDA has never offered.
Sometimes the right answer is to withdraw and resubmit. If the deficiencies point at an architectural decision rather than a documentation gap, and fixing it means changing the device, 180 days of writing will not close it. A deliberate withdrawal with a rebuilt submission is occasionally cheaper than a doomed response followed by an automatic deletion, and the difference is that you control the timing in one case and not the other. This is a regulatory strategy call for your regulatory lead, not a security call.
If your deficiencies are purely documentation, you may not need us. A team with an accurate threat model, a maintained SBOM and a real test report often needs an editor and a project manager, not a security firm. Our own service page states a typical turnaround of four to eight weeks depending on scope, and a good chunk of the engagements that reach us at that size are ones the manufacturer could have run internally with a cleared calendar.
Where Top Floor fits
Our FDA cybersecurity practice does the artifacts and the connective tissue between them: threat modeling, SBOM generation and maintenance, the cybersecurity management plan, coordinated vulnerability disclosure procedures, and the traceability that ties them to testing evidence. Device and system testing sits under penetration testing, scoped so the report contains the elements the guidance names rather than a generic findings list. Where a manufacturer needs the postmarket side to keep running after the submission clears, that is compliance as a service work.
We do not clear devices and we do not speak for FDA.
How to decide this week
Find the date on the letter and count 180 calendar days forward. Put that date in front of everyone who touches the response, because it is the only date that matters and no extension exists behind it.
Then classify each numbered item: deficiency requiring a response, or additional consideration that does not. Then classify each deficiency again: document we can write, or evidence we have to generate. The second list drives the schedule.
Then confirm which guidance edition your regulatory file cites. If it names June 27, 2025, update it before drafting.
Then, before anyone writes prose, put the threat model, the risk assessment, the SBOM and the test reports on one page and draw the links between them. If you cannot draw them, that is the deficiency behind the deficiencies, and it is the one that takes longest.
Frequently asked questions
How long do I have to respond to an FDA Additional Information request?
180 calendar days from the date of the AI Request. FDA states that no extensions beyond 180 days are granted, and that if it does not receive a complete response to all deficiencies within that window, the submission is considered withdrawn and deleted from the review system, at which point a new submission is required to pursue clearance. The same 180-day allowance applies to an RTA Hold and to an incomplete eSTAR after a technical screening deficiency notification, but those are threshold checks rather than substantive review findings.
Does the FDA review clock keep running while my submission is on hold?
No, and that is the point of the mechanism. FDA's goal is a MDUFA decision within 90 FDA Days, and FDA Days are counted as calendar days between receipt of the submission and the decision, excluding the days the submission was on hold for an AI request. Time you spend preparing the response therefore adds to your total elapsed timeline without counting against FDA's performance goal. If FDA does not reach a decision within 100 FDA Days it issues a Missed MDUFA Communication with written feedback and an estimated date of completion.
Can I respond to some deficiencies now and the rest later?
Not usefully. FDA must receive a complete response to all deficiencies within the 180-day window, so a partial submission does not stop the clock and does not preserve the submission. The practical approach is to sequence the work internally, starting with anything that requires new evidence such as testing on a current device build, and to file once. FDA's guidance also notes that additional considerations included in a deficiency letter would not require an applicant response, so identifying which numbered items are actually deficiencies is worth doing before the drafting starts.
Which FDA cybersecurity guidance should we be citing?
The February 2026 edition, titled "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions", issued on February 3, 2026 under docket FDA-2021-D-1158. Its cover page states that it supersedes the June 27, 2025 edition of the guidance under the earlier title "Quality System Considerations and Content of Premarket Submissions". Much of the content carries across, so citing the older one is not automatically a substantive error, but it is visible to a reviewer and it signals that the material has not been refreshed.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.