MTEC Educational Webinar
What FDA Actually Wrote: Eight Cybersecurity Deficiencies, Taken From the Letters
1-2 pm EST

Date & Time
September 23, 2026
Description
Christian Espinosa, Founder and CEO of Blue Goat Cyber, analyzed ten FDA deficiency letters written on submissions his firm did not prepare — software-only and AI-enabled devices, cloud and on-premise deployments, wearables, vital signs monitors, and capital equipment, spanning both CDRH and CBER. Eight findings account for most of what came back, across every device type and both centers.
The session puts redacted excerpts from those letters on screen. For each finding: what the reviewer actually wrote, the root cause in the submission, and the specific artifact that closes it. Topics include Software Bill of Materials (SBOM) support status and end-of-support data, traceability from security controls to requirement identifiers to test cases, cybersecurity labeling content, penetration testing scope and reporting, risk assessment methodology, unresolved anomalies, and threat model completeness.
Two things worth noting for members with active work in this area. First, attendees may send anonymized deficiency language in advance, and Christian will work through as many as time allows during the discussion block. Second, every registrant receives Blue Goat's map of the 18 premarket cybersecurity deliverables against the current final guidance and eSTAR v7.0.