MTEC Educational Webinar

webinar

What FDA Actually Wrote: Eight Cybersecurity Deficiencies, Taken From the Letters

1-2 pm EST

What FDA Actually Wrote: Eight Cybersecurity Deficiencies, Taken From the Letters

Date & Time

September 23, 2026

Description

Christian Espinosa, Founder and CEO of Blue Goat Cyber, analyzed ten FDA deficiency letters written on submissions his firm did not prepare — software-only and AI-enabled devices, cloud and on-premise deployments, wearables, vital signs monitors, and capital equipment, spanning both CDRH and CBER. Eight findings account for most of what came back, across every device type and both centers.

The session puts redacted excerpts from those letters on screen. For each finding: what the reviewer actually wrote, the root cause in the submission, and the specific artifact that closes it. Topics include Software Bill of Materials (SBOM) support status and end-of-support data, traceability from security controls to requirement identifiers to test cases, cybersecurity labeling content, penetration testing scope and reporting, risk assessment methodology, unresolved anomalies, and threat model completeness.

Two things worth noting for members with active work in this area. First, attendees may send anonymized deficiency language in advance, and Christian will work through as many as time allows during the discussion block. Second, every registrant receives Blue Goat's map of the 18 premarket cybersecurity deliverables against the current final guidance and eSTAR v7.0.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.

What FDA Actually Wrote: Eight Cybersecurity Deficiencies, Taken From the Letters | MTEC