FDA eSTAR Cybersecurity Documentation
Every cybersecurity artifact your 510(k) or De Novo eSTAR submission requires — authored from scratch, completed from partial drafts, or rewritten to clear an FDA deficiency. Revisions and responses to FDA's cybersecurity questions are part of the engagement, at no additional cost.
The full cybersecurity section of the submission
FDA's premarket cybersecurity guidance defines a specific set of documentation the reviewers expect through eSTAR submission — and reviewers issue deficiencies when any one of them is thin, inconsistent, or disconnected from the device's actual design. We produce all of it as one coherent package. Select a document to see what it covers.
Document 01 of 11
Threat Model
Threat modeling across the entire device system and every connection into and out of it — hospital network, cloud, update infrastructure, and other functions included, and a rationale for the methodology used.
Wherever your documentation stands today
The work looks different depending on whether you are starting out, partway through, or responding to an FDA deficiency.
Create every document
Starting from a blank page. We work from your design inputs, architecture, and test data to author the full cybersecurity section of the eSTAR — every plan, report, view, and summary a 510(k) or De Novo submission needs.
Review and finish partial drafts
You already have some of it written. We assess what exists against the current FDA guidance and the eSTAR structure, complete the missing pieces, and bring the whole package to a consistent submission grade.
Remediate FDA deficiencies
You received a cybersecurity deficiency — Additional Information request or a hold. We diagnose why the original content fell short, rewrite the affected sections, and prepare a response the review team can accept.
We stay on it until cybersecurity review is cleared
The work isn't finished when the package is filed, it's finished when the cybersecurity content is accepted.
For submissions we prepared or completed, that means no change orders and no hourly add-ons for the revision cycles that follow — and for related work, see Regulatory Compliance Consulting and Post-Market Services.
No additional charge for
- Revisions to any document we deliver, through as many cycles as review takes
- Drafting responses to FDA cybersecurity deficiencies and Additional Information requests on the package we supported
- Reworking affected sections when a response prompts follow-up questions
A fixed price for one device, a custom quote for everything else
Documentation for a single, standard-complexity device is a known scope, so it's priced as a fixed fee. Complex systems and deficiency remediation vary too much to quote blind — we scope those on a call first.
Single-device package
$20,000
Fixed price, agreed in full before work starts
The complete cybersecurity section for one device of standard complexity — single product, conventional architecture and connectivity.
- All eSTAR cybersecurity documents authored
- Threat model, architecture views, and risk assessment
- SBOM support with component vulnerability assessment
- Test documentation assembly and gap review
- Revisions and FDA question responses included
Complex device or remediation
Custom pricing
Scoped after a review call
Multi-function or multi-device systems, novel or AI/ML architectures, or reworking an existing submission to clear an FDA cybersecurity deficiency.
- Multi-function and multi-device system coverage
- Novel architecture, connectivity, or AI/ML components
- Deficiency diagnosis and targeted section rewrites
- Response package for Additional Information requests
- Revisions and follow-up responses included
All engagements include revision cycles and responses to FDA's cybersecurity questions on the package we supported, at no additional cost.
Filing soon, or holding an FDA deficiency letter?
Tell us where the submission stands and what's already written — we'll scope what it takes to get the cybersecurity content cleared.
