Skip to main content
    MedTech Cyber Tips
    The Ultimate Guide
    All topics
    Submission

    Responding to FDA Deficiency Letters

    This guide provides actionable tips for medical device manufacturers on how to effectively respond to FDA cybersecurity deficiency letters and additional information requests, aiming for a cleared submission and market launch without delays.

    For: Medical device manufacturers facing FDA cybersecurity deficiency letters, additional information requests, or full holds. 2 min read Reviewed February 2026
    FDA deficiency response cadence

    From hold letter to cleared submission

    Step 1
    Receive letter
    Log clock start; route to PSIRT + RA lead
    Step 2
    Categorize items
    Split major vs minor; map each to submission section
    Step 3
    Build evidence
    Updated threat model, SBOM/VEX, test reports, traceability
    Step 4
    Respond on point
    Line-by-line reply, no scope creep, full re-pagination

    Major deficiencies typically allow 180 days to respond. Miss it and the submission is withdrawn.

    10 structured tips

    The walk-through

    01
    Strategic

    Understand the FDA Clock and Costs of Delay

    Recognize the 180-day FDA response window and the escalating costs of delays, including engineering hours, missed launches, and potential for additional deficiency rounds.

    02
    Strategic

    Prioritize Prompt Response

    Address deficiencies quickly to avoid extended FDA holds, which can lead to significant revenue impact and investor scrutiny.

    03
    Process

    Thoroughly Review and Analyze Deficiency Letters

    Dissect the FDA hold letter line by line to accurately identify specific reviewer requests and the exact evidence needed for a complete response.

    04
    Documentation

    Craft Precise and Complete Responses to AI Requests

    When the FDA requests additional information, provide precise and complete answers that directly address every question without oversharing unnecessary details.

    05
    Technical

    Remediate and Align Threat Models with FDA Expectations

    Rebuild or strengthen flagged threat models to meet FDA expectations, ensuring alignment with AAMI TIR57 and industry best practices.

    06
    Technical

    Perform Comprehensive Penetration Testing and Retesting

    Conduct or redo penetration testing to address any gaps identified by the FDA, providing clear and reviewer-grade evidence of vulnerability management.

    07
    Documentation

    Conduct Documentation Gap Analysis

    Identify and address missing documentation, such as incomplete SBOMs, SPDFs, or weak risk assessments, and build out the necessary artifacts.

    08
    Process

    Assemble a Full and Reviewer-Ready Response Package

    Compile and format the entire deficiency response package, ensuring it is ready for eSTAR upload and easy consumption by the FDA reviewer.

    09
    Compliance

    Ensure Traceability and Alignment with ISO 14971

    Update risk assessments with clear traceability to ISO 14971 and ensure all cybersecurity documentation, including threat models, are connected to patient harm.

    10
    Documentation

    Include Complete SBOM + VEX with Vulnerability Triage

    Provide a comprehensive Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) with evidence of vulnerability triage and remediation documentation.

    Common pitfalls

    • Submitting a rushed response with templated threat models, incomplete SBOM/VEX, and pen test scope that ignores critical areas (e.g., BLE/cloud) often leads to another deficiency round and prolonged delays.
    • Failing to provide line-by-line Section 524B traceability in the response will result in reviewer flags.
    • Having junior authors with no FDA review history prepare the response can lead to rejection and extended hold periods.
    • Over-sharing information that is not directly requested by the FDA can lead to new questions and further delays.

    Your next steps

    1. 1Schedule a discovery session with cybersecurity experts who specialize in FDA responses to analyze your deficiency letter and develop a response strategy.
    2. 2Immediately begin a detailed gap analysis to determine necessary evidence and documentation updates.
    3. 3Engage experienced MedTech cybersecurity engineers to build required artifacts like updated threat models, SBOM/VEX, and conduct penetration testing.

    Sources & references

    Authoritative guidance and standards underpinning this topic. Always confirm the latest revision with the publisher.

    Frequently asked questions

    Quick answers to the questions teams most often ask about this topic.

    It is the FDA's formal request for additional information when your premarket submission's cybersecurity package is incomplete or unclear. Receiving one pauses the review clock until you respond, so the quality and speed of your response directly affect time to clearance.

    Address each deficiency individually with a clear, evidence-backed answer. Reference the exact section of your submission you are updating, attach the new artifact (updated threat model, SBOM, test report, etc.), and avoid introducing scope changes the reviewer didn't ask for.

    Typically 180 days for a major deficiency, though this varies by submission type. Missing the deadline can result in your submission being placed on hold or withdrawn.

    Continue by phase

    Jump to all guides for the lifecycle phase that fits where you are.