Refuse to Accept (Cybersecurity)
FDA's authority to reject a premarket submission outright when required cybersecurity content is missing.
Definition
Refuse to Accept (RTA) is FDA's authority to reject a premarket submission before substantive review when administrative or content requirements are not met. Under section 524B, FDA began RTA enforcement on October 1, 2023 for any cyber-device submission missing the statutory cybersecurity content (vulnerability monitoring plan, secure-by-design processes, SBOM, and any other required information). An RTA stops the review clock; the sponsor must resubmit with complete content.What this means in practice
RTA on cybersecurity content is fast and unforgiving. Most MedTech teams that have hit it underestimated the scope of what FDA expects in the SBOM, threat model, and vulnerability management plan, or treated the section 524B requirements as guidance rather than statute. Build the cybersecurity package alongside the rest of the submission and pre-flight it against the RTA checklist.- •Submitting an SBOM that lacks the CISA minimum elements or end-of-support information.
- •Including a generic vulnerability management plan with no resourcing detail.
- •Missing the cybersecurity labeling content required under 524B.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
FDA administrative decision that a submission is incomplete and won't be substantively reviewed.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
Refuse to Accept Policy for 510(k)sVerifiedFDAfda.gov
- 2
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 3
CISA - Healthcare and Public Health SectorVerifiedCISAcisa.gov
Inline markers like [1] jump to the matching reference above.