How Long Does FDA Premarket Cybersecurity Review Take?
There is no separate FDA cybersecurity review clock. The cybersecurity section of a cyber device submission is reviewed inside the pathway's ordinary timeline, and FDA publishes those timelines: a goal of 90 FDA Days for a 510(k), 150 review days for a De Novo request, and 180 days from the filing date for a PMA, with Pre-Submission written feedback within 70 calendar days if you ask for it first (FDA, 510(k) Submission Process; De Novo Classification Request; PMA Review Process; Q-Submission Program guidance). The number that matters is not on that list. It is the days a submission spends off the clock, because FDA Days exclude time on hold for an Additional Information request, and a cybersecurity section is one of the more reliable ways to earn a hold. So the honest answer to "how long does the cybersecurity review take" is: as long as the pathway, plus every day you spend on hold, plus the preparation time for the two artifacts that cannot be produced under a deadline.
Below: the clocks FDA publishes for each pathway, the two gates where cybersecurity content stops the clock, the preparation items with lead times, and when the right move is to ask FDA first.
Key takeaways
- FDA publishes its review goals: 90 FDA Days for a 510(k), 150 review days for a De Novo, 180 days from filing for a PMA, and Pre-Submission written feedback within 70 calendar days.
- FDA Days exclude time on hold for an Additional Information request, so a hold adds to your elapsed time without counting against the agency's goal.
- Two gates stop the clock for cybersecurity reasons: technical screening within 15 days, which holds an eSTAR whose Cybersecurity section lacks accurate responses and attachments, and the substantive interaction within 60 calendar days, which either continues interactively or issues an AI request.
- A hold gives you up to 180 calendar days to submit a complete response, and every one of those days is calendar time the FDA Days accounting does not count; what happens when the window is missed belongs to the deficiency-letter article.
- The preparation items with real lead times are independent security testing with the report elements FDA names, and the SBOM support and end-of-support fields, neither of which can be produced in the response window.
The clocks FDA publishes, by pathway
Every figure in this table is from an FDA page or guidance read in August 2026, and every one of them is a goal or a procedural window rather than a promise. FDA's own pages say so in their wording, and its process for a missed goal is described below.
| Pathway | Front gate | Substantive milestone | Decision goal |
|---|---|---|---|
| Pre-Submission | Acceptance review or technical screening within the first 15 days of the review clock | Meeting typically on day 70 to 75, with written feedback at least 5 days before it | Written feedback within 70 calendar days of the review clock start |
| 510(k) | Hold letter for a missing fee or invalid eSTAR usually within 7 days; acceptance review result, or technical screening, within 15 days of receipt | Substantive Interaction within 60 calendar days of receipt: interactive review, or an AI request that places the submission on hold | MDUFA Decision within 90 FDA Days; a Missed MDUFA Communication at 100 FDA Days |
| De Novo | Technical screening within 15 calendar days of receipt, once the user fee is paid | Interactive review, or an Additional Information letter that places the request on hold | Decision within 150 review days |
| PMA | Filing decision within 45 days of receipt | Day-100 meeting available; the request must be made no later than 70 days from filing | Review completed within 180 days of the filing date |
Three details in that table decide the cybersecurity timeline more than the headline goals do.
The review clock starts at receipt for a submission that passes screening, and does not start at all for one that does not. FDA's De Novo page states that "for a submission that passes technical screening, the review clock starts on the day the submission was received by FDA", and the 510(k) page's FDA Days likewise run from the date the submission was received. Screening time is free if you pass and open-ended if you do not.
FDA Days are not calendar days. The 510(k) page defines them as "the number of calendar days between the date the 510(k) was received and the date of a MDUFA decision, excluding the days the submission was on hold for an AI request". The same page says that if FDA does not reach a decision within 100 FDA Days it issues a Missed MDUFA Communication with an estimated date of completion. That is what happens when FDA is late. Nothing corresponding happens when you are.
The Pre-Submission is the only clock you can choose to run before the others, and FDA's Q-Submission guidance, issued May 29, 2025, states that written feedback "will be provided within 70 calendar days from the review clock start date" where no meeting is requested, and no later than 70 days with a meeting typically on day 70 to 75. For a cyber device with a contested scoping question or an unusual architecture, that is 70 days spent before filing rather than 180 spent on hold after it.
Gate one: screening, where the clock has not started yet
FDA's cybersecurity FAQ states that since October 1, 2023 the agency "expects that sponsors of cyber devices will have had sufficient time to prepare premarket submissions that contain information required by section 524B", the refuse-to-accept policy for cyber devices having expired on that date, and that "an eSTAR submission will be put on a Technical Screening hold if it does not contain accurate responses and relevant attachments in the Cybersecurity section of eSTAR" (FDA, Cybersecurity in Medical Devices FAQs).
For the timeline that means the first cybersecurity gate is a presence check that happens before the review clock exists. A held eSTAR is not being reviewed slowly; it is not being reviewed. FDA's 510(k) page states that if a replacement eSTAR is not received "within 180 days of the date of technical screening deficiency notification", the 510(k) is considered withdrawn and closed. What screening checks, and what belongs in the section it is checking, is covered in what goes in the cybersecurity section of a 510(k); the scheduling point is that every attachment-type question in the Cybersecurity section needs a real attachment on the day of submission, because a missing one costs the round trip before day one.
Gate two: substantive interaction, where the clock stops
The 510(k) page describes the Substantive Interaction, which "should occur within 60 calendar days of receipt", as typically one of two things: an email saying outstanding deficiencies will be resolved through interactive review without a hold, or an Additional Information request that places the submission on hold. A lead reviewer chooses interactive review when "any outstanding deficiencies may be adequately addressed within the Medical Device User Fee Amendment (MDUFA) timeframe".
That sentence is the economics of a cybersecurity section. A reviewer who can see how the threat model, the risk assessment, the SBOM and the test report relate to each other can ask small questions by email and keep the clock running. A reviewer who cannot has to ask big questions, and a big question is an AI request. The hold that follows gives you "180 calendar days from the date of the AI Request to submit a complete response". Responding to an FDA cybersecurity deficiency letter covers what a hold is, how to read the deficiencies, how to respond once, and what happens to a submission that misses the window; this page only adds the arithmetic. Every day of the hold is added to your elapsed timeline and subtracted from nobody else's, and a response that takes 120 days has turned a 90 FDA Day review into a 210 calendar day one before FDA has resumed reading.
Whether a cybersecurity section draws an email or a letter is not something anyone outside FDA can predict for you, and we are not going to claim otherwise. What is knowable is which artifacts a reviewer needs in order to ask small questions rather than large ones, and those are the ones with lead times.
The two preparation items with real lead times
Most of a cybersecurity section can be written by a competent team under deadline pressure. Two things cannot, and they set the preparation timeline regardless of pathway. What Section 524B requires covers the statutory content itself; this page is only about which parts of it consume calendar.
Independent security testing. The report elements FDA's guidance names, including the statement of how independent the testers were from the developers, are listed in the 510(k) documentation article. The timeline consequence is what this page owns: independence cannot be added to a test after it was run, and a test on a device build has to be scheduled against that build. If a deficiency asks for it, the testing is the critical path of the response, not the writing. That is why penetration testing for a device is booked before the submission is drafted, with the report format agreed before the test starts.
The SBOM support fields. The same article lists the per-component fields FDA asks for beside the inventory. Of everything in the section, those fields are the one item whose answer sits with your suppliers rather than your build system, and the outreach to get them runs at the pace of the slowest supplier, which is why device teams most often discover they cannot fill them quickly. The timeline consequence is that the supplier outreach starts months before the eSTAR is assembled, or it becomes the thing a hold is spent on.
Everything else in the section, the threat model, the architecture views, the risk assessment, the management plan and the traceability between them, is authorable on a schedule you control, provided the underlying engineering decisions have been made. The one that is not authorable is traceability over artifacts that do not agree with each other, which is why the reviewer's small-question path depends on the set being coherent before filing.
When to ask FDA first
A Pre-Submission costs 70 calendar days of waiting for written feedback and is worth it in three situations we would name in any scoping call.
When the cyber device determination is genuinely contested, because a scoping disagreement discovered at substantive interaction becomes a hold rather than a conversation. When the architecture is unusual enough that the four security architecture views do not map obviously onto it, so that the question "which views do you expect for this" is better asked before the file is built. And when a prior submission for the device family drew cybersecurity deficiencies, because the Q-Submission guidance's own logic is that early feedback shortens total time to decision, and the previous letter tells you which questions to ask.
A Pre-Submission is not worth it when the device is plainly a cyber device with a conventional connected architecture and the team has filed one before. In that case the 70 days are better spent booking the independent test and chasing the supplier support dates.
Where Top Floor fits
Our FDA cybersecurity practice works to the calendar above: the threat model, the risk assessment, the SBOM with its support and end-of-support fields, the management plan and the traceability that lets a reviewer ask small questions, sequenced so that the two lead-time items start first. The device, firmware, API and cloud testing that produces the evidence sits under penetration testing, scoped so the report carries the elements the guidance names. Where a manufacturer needs the postmarket side to keep running after clearance rather than a team for one filing, that is compliance as a service work.
We do not clear devices, we do not speak for FDA, and no one can promise you an interactive review rather than a hold. Anyone who does is describing something FDA has never offered.
How to decide this week
Take your target submission date and count backwards. Put the independent test on the calendar first, against a device build that will exist, with the report elements agreed. Then start the supplier outreach for component support status and end-of-support dates, because that is the item with a lead time you cannot see the end of.
Then decide the Pre-Submission question honestly. If the cyber device determination, the architecture views or a prior deficiency letter make it worth asking, file the Q-Submission now and use the 70 days to build the file.
Then, before the eSTAR is assembled, check every attachment-type question in the Cybersecurity section against a real attachment. Screening is a presence check that happens before the clock starts, and it is the cheapest gate to pass and the most expensive one to fail.
Frequently asked questions
How long does FDA take to review a 510(k) with a cybersecurity section?
FDA's stated goal for a 510(k) is a MDUFA Decision within 90 FDA Days, with a Substantive Interaction within 60 calendar days of receipt and an acceptance review or technical screening within 15 days. There is no separate cybersecurity review clock; the cybersecurity section is reviewed inside that timeline. What changes the elapsed time is a hold: FDA Days exclude time on hold for an Additional Information request, and the submitter has 180 calendar days to respond completely to one, so the calendar time depends on whether the cybersecurity content keeps the review interactive or draws a hold.
What are the FDA review timelines for De Novo and PMA cyber devices?
FDA's De Novo page states a goal of a decision within 150 review days, with technical screening of the eSTAR within 15 calendar days of receipt and a hold of up to 180 calendar days if an Additional Information letter is issued. FDA's PMA review page states that the agency will notify the applicant within 45 days of receipt whether the application has been filed, and that the 180-day review period starts on the date of filing, with a Day-100 meeting available if requested no later than 70 days from filing. De Novo review days exclude the days the request was on hold for an Additional Information letter; for a PMA, the same page notes that a major amendment can extend the review period by up to 180 days.
Does a Pre-Submission shorten the FDA cybersecurity review?
It front-loads the questions rather than shortening the review clock. FDA's Q-Submission guidance states that written feedback on a Pre-Submission is provided within 70 calendar days from the review clock start, or at least 5 days before a meeting typically scheduled on day 70 to 75. For a cyber device with a contested scoping question, an unusual architecture or a prior deficiency letter, spending those 70 days before filing is usually cheaper than discovering the same question as an Additional Information request and spending part of a 180-day hold on it. For a conventional connected device from a team that has filed before, the time is better spent on the independent test and the SBOM support fields.
What cybersecurity work has the longest lead time before an FDA submission?
Two items. Independent security testing has to be run on a real device build by testers whose independence from the developers can be stated in the report, with the report elements the 510(k) documentation article lists, and none of that can be added afterwards. The SBOM support fields that same article lists depend on supplier responses, and that outreach takes as long as the slowest supplier. Both should start before the eSTAR is drafted, because both are the items a hold gets spent on when they are missing.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.