---
title: "RTA (cyber) Definition &amp; Meaning | MedTech Terms"
description: "FDA's authority to reject a premarket submission outright when required cybersecurity content is missing. Plain-English Cybersecurity definition for MedTech tea"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/rta-cyber#term",
        "name": "Refuse to Accept (Cybersecurity)",
        "alternateName": "RTA (cyber)",
        "description": "Refuse to Accept (RTA) is FDA's authority to reject a premarket submission before substantive review when administrative or content requirements are not met. Under section 524B, FDA began RTA enforcement on October 1, 2023 for any cyber-device submission missing the statutory cybersecurity content (vulnerability monitoring plan, secure-by-design processes, SBOM, and any other required information). An RTA stops the review clock; the sponsor must resubmit with complete content.",
        "url": "https://medtechterms.com/terms/rta-cyber",
        "termCode": "rta-cyber",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/rta-cyber#article",
        "headline": "RTA (cyber), Refuse to Accept (Cybersecurity)",
        "description": "FDA's authority to reject a premarket submission outright when required cybersecurity content is missing.",
        "url": "https://medtechterms.com/terms/rta-cyber",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/rta-cyber"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/rta-cyber#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Refuse to Accept (Cybersecurity), RTA (cyber), Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Refuse to Accept Policy for 510(k)s",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/refuse-accept-policy-510ks",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA Cybersecurity Guidance (Sept 2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "CISA - Healthcare and Public Health Sector",
            "url": "https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/section-524b#term",
            "name": "Section 524B of the FD&C Act",
            "alternateName": "524B",
            "url": "https://medtechterms.com/terms/section-524b"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/rta#term",
            "name": "Refuse to Accept",
            "alternateName": "RTA",
            "url": "https://medtechterms.com/terms/rta"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/sbom#term",
            "name": "Software Bill of Materials",
            "alternateName": "SBOM",
            "url": "https://medtechterms.com/terms/sbom"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Refuse to Accept (Cybersecurity)",
            "item": "https://medtechterms.com/terms/rta-cyber"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/rta-cyber#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "How quickly does RTA happen?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "FDA's RTA review is typically completed within 15 calendar days of submission acceptance. If the package fails RTA, the clock never starts and the sponsor must resubmit."
            }
          },
          {
            "@type": "Question",
            "name": "Can we appeal an RTA decision?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "RTA letters can be addressed by promptly providing the missing content. Formal appeal mechanisms exist but are rarely faster than fixing the gap and resubmitting."
            }
          },
          {
            "@type": "Question",
            "name": "Is RTA different for De Novo or PMA?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The administrative process is similar; the cybersecurity content requirements are the same under section 524B. PMA RTAs trigger a longer remediation cycle because of the higher submission complexity."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Refuse to Accept (Cybersecurity)

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)[Global Markets](/ecosystems/global-markets)RTA (cyber) 

# Refuse to Accept (Cybersecurity)

FDA's authority to reject a premarket submission outright when required cybersecurity content is missing.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

[Refuse to Accept](/terms/rta) (RTA) is FDA's authority to reject a premarket submission before substantive review when administrative or content requirements are not met. Under section  [524B](/terms/section-524b), FDA began RTA enforcement on October 1, 2023 for any cyber-device submission missing the statutory cybersecurity content (vulnerability monitoring plan, secure-by-design processes,  [SBOM](/terms/sbom), and any other required information). An RTA stops the review clock; the sponsor must resubmit with complete content. 

What the regulation says

FDA's  [RTA](/terms/rta) checklists for 510(k),  [De Novo](/terms/de-novo),  [PMA](/terms/pma), and  [HDE](/terms/hde) submissions now include explicit cybersecurity items derived from section  [524B](/terms/section-524b) and the 2023 guidance. Reviewers run the checklist within the first 15 calendar days; missing or non-conforming cybersecurity content triggers RTA. The sponsor receives an RTA letter listing each deficiency. 

## What this means in practice

[RTA](/terms/rta) on cybersecurity content is fast and unforgiving. Most MedTech teams that have hit it underestimated the scope of what FDA expects in the  [SBOM](/terms/sbom), threat model, and vulnerability management plan, or treated the section  [524B](/terms/section-524b) requirements as guidance rather than statute. Build the cybersecurity package alongside the rest of the submission and pre-flight it against the RTA checklist. 

Common pitfalls

-   • Submitting an SBOM that lacks the CISA minimum elements or end-of-support information. 
-   • Including a generic vulnerability management plan with no resourcing detail. 
-   • Missing the cybersecurity labeling content required under 524B. 

## Frequently asked questions

How quickly does RTA happen? 

FDA's  [RTA](/terms/rta) review is typically completed within 15 calendar days of submission acceptance. If the package fails RTA, the clock never starts and the sponsor must resubmit. 

Can we appeal an RTA decision? 

Is RTA different for De Novo or PMA? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)[

Cybersecurity

Section 524B of the FD&C Act(524B) 

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.





](/terms/section-524b)[

Cybersecurity

Software Bill of Materials(SBOM) 

A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.





](/terms/sbom)[

Regulatory

Refuse to Accept(RTA) 

FDA administrative decision that a submission is incomplete and won't be substantively reviewed.





](/terms/rta)

### More in Cybersecurity

· Same category 

[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)[

Cybersecurity

Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.





](/terms/brainjacking)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)
-   [Global Markets](/ecosystems/global-markets)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

FDA· 2 CISA· 1 

1.  [1 
    
    Refuse to Accept Policy for 510(k)s
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/refuse-accept-policy-510ks)
2.  [2 
    
    FDA Cybersecurity Guidance (Sept 2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)
3.  [3 
    
    CISA - Healthcare and Public Health Sector
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

RTA (cyber)

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=rta-cyber)

Learn in 60 seconds

Card Lesson Quiz

FDA's authority to reject a premarket submission outright when required cybersecurity content is missing.

-   · RTA on cybersecurity content is fast and unforgiving. 
-   · Build the cybersecurity package alongside the rest of the submission and pre-flight it against the RTA checklist. 
-   · An RTA stops the review clock; the sponsor must resubmit with complete content. 

Remember this

Watch out: Submitting an SBOM that lacks the CISA minimum elements or end-of-support information.

Related terms

-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Refuse to Accept(RTA) ](/terms/rta)
-   [Software Bill of Materials(SBOM) ](/terms/sbom)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [IDE Annual Progress Report ](/terms/ide-annual-report)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Modular PMA ](/terms/pma-modular)
-   [AAMI SW96 ](/terms/aami-sw96)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [AI Act Technical Documentation (Annex IV) ](/terms/ai-act-technical-documentation)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)