Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
Cybersecurity

What Is an FDA Cybersecurity Deficiency Letter? (2026)

By Open Door Salon · July 27, 2026
What Is an FDA Cybersecurity Deficiency Letter? (2026)

An FDA cybersecurity deficiency letter is the agency's formal notice that a medical-device submission has failed to meet its cybersecurity requirements, and it has become one of the most common reasons a device stalls before market. The lists can run to 37 pages, they start a 180-day response clock, and roughly one in five companies cannot close them in time and has to submit all over again. On Open Door Salon, Christian Espinosa, founder and CEO of the medical-device cybersecurity firm Blue Goat Cyber, described a sudden surge in these letters and what they actually demand.

Why are FDA cybersecurity deficiency letters suddenly everywhere?

The volume has jumped, not crept. Espinosa said his team had about ten discovery meetings in a single two-week stretch with companies that had just been hit with cybersecurity deficiencies, and the FDA is raising the bar on its due diligence across the board, part of a wider pattern in how the agency is being judged as a global standard.

"Literally in the past two weeks, we've had probably ten discovery meetings with prospects that have received deficiencies from the FDA in terms of cybersecurity."

He tied it to a simple reality the industry has been slow to accept: a connected device is a cyber device, and the days of clearing one with a thin layer of security documentation are over.

How long is a 37-page deficiency list, in real time?

The page count is the shock, but the timeline is the damage. The FDA gives a company 180 calendar days by default to respond, and a submission that misses that window is considered withdrawn. Espinosa estimates about 80 percent of companies close the gaps inside that window. The other 20 percent cannot, and they have to file an entirely new submission, which resets the clock and the cost.

"The FDA gives you 180 days by default to respond… 80% can submit within the 180 days and get things fixed. The other 20% have to do an entirely new submission."

Most manufacturers underestimate the effort a deficiency list represents. Closing it usually means re-engaging the software team to fix things that were never addressed, which is expensive and slow, and it lands on an agency already absorbing the cost of reviewer turnover. The same late-discovery pattern shows up on the commercial side, where reimbursement strategy left until after clearance costs years rather than months.

Why is cybersecurity only the tip of the iceberg?

Edwin Lindsay, principal consultant and managing director at the regulatory consultancy CS Lifesciences, made the point that a cyber deficiency rarely stays contained. If the fix requires redesigning part of the device, the knock-on work is far larger than the letter suggests.

"If they have to go back in and redesign, redevelop aspects of the device to meet the cyber, we may have to go back in and redo some of the other V&V type testing, product testing."

In other words, a cybersecurity change can force a fresh round of verification and validation to prove the device still operates safely and effectively. Teams that see only the deficiency list miss the testing tail attached to it.

What separates the companies that clear it from the ones that don't?

The dividing line is planning. Lindsay pointed out that many of the companies buried under a 37-page list never held a pre-submission meeting with the FDA on their software or cybersecurity, so they walked in blind. For anything with connected software, artificial intelligence, or a real cyber surface, his firm often expects several pre-subs with the FDA before testing even begins.

The companies that struggle treat cybersecurity as an afterthought, something bolted on near the end. The ones that clear the letter built security into the requirements and the design from the start, so the deficiency, when it comes, is narrow rather than existential.

What should a founder do before the letter arrives?

The practical takeaway is to move the work earlier. Engage the FDA through pre-submissions on the cybersecurity plan, follow a recognized software-development standard rather than improvising, and treat it as part of the same discipline as mapping sub-tier supply chain risk, and treat any means of connection as an attack surface that has to be assessed. A deficiency letter is far cheaper to answer when the underlying work already exists and only needs to be documented, rather than built from scratch under a 180-day clock.

Before any of that applies, a team has to settle whether the device is a cyber device at all, and the bar is lower than most manufacturers expect. The same controls decide the question teams often ask first, which is whether a device made in China carries more risk.

These forces came up in a wider conversation on Open Door Salon about the three things that make or break a medtech launch, drawn from the recorded, on-the-record discussion with Christian Espinosa and Edwin Lindsay. If you are building a connected device, the deficiency letter is not a formality to clear at the end. It is a signal of how seriously the FDA now treats software as a matter of patient safety. Companies weighing their own readiness can work with Open Door Salon to reach the people navigating exactly these questions.

← Back to the Blog