Refuse to Accept
FDA administrative decision that a submission is incomplete and won't be substantively reviewed.
Definition
Refuse to Accept (RTA) is FDA's administrative review of 510(k) submissions to determine whether they meet a minimum threshold of acceptability for substantive review based on a checklist.What this means in practice
RTA decisions occur in the first 15 calendar days of the review clock. If FDA finds missing checklist items, the submission is held (RTA hold) and the 90-day review clock stops until the sponsor submits the missing content. Two consecutive RTA holds can effectively add 60 to 120 days to the timeline. Similar acceptance reviews exist for De Novo (Acceptance Review) and PMA (Filing Review). The most common RTA triggers in 2024-2025 have shifted from labeling and administrative gaps to cybersecurity content: missing SBOM, no threat model, no vulnerability management plan, no coordinated disclosure policy under Section 524B.Examples
- A connected wearable 510(k) is held RTA on day 12 because the SBOM only lists top-level components without transitive dependencies, and no CVD policy is documented.
- A traditional Class II 510(k) is held RTA because the indications for use statement in Section 4 does not match the labeling in Section 12.
- •Ignoring the eCopy or eSTAR technical validation errors before submission. Technical failures cause immediate RTA.
- •Treating cybersecurity content as optional for 510(k). Under 524B, any cyber device submission without SBOM, CVD policy, and vulnerability management triggers RTA.
- •Inconsistent indications-for-use wording across the cover letter, Section 4, and labeling. This is the single most common non-cyber RTA reason.
- •Submitting near a quarter-end deadline without a full internal RTA checklist review. FDA follows the checklist strictly; sponsors should too.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsPathway to classify novel low- to moderate-risk devices that lack a predicate.
FDA submission demonstrating a device is substantially equivalent to a legally marketed predicate.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
FDA Cybersecurity 101
· From this learning pathAn industry-standard 0–10 score that quantifies the severity of a software vulnerability.
A globally unique identifier for a publicly disclosed cybersecurity vulnerability.
A lightweight, OWASP-maintained SBOM format designed for application security and supply-chain use cases.
A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
510(k) Fundamentals
· From this learning pathDescription of the disease or condition the device will diagnose, treat, prevent, cure, or mitigate.
The objective intent of the manufacturer regarding the use of the device.
A legally marketed device used as the comparator in a 510(k) submission.
The legal standard a 510(k) device must meet versus a predicate.
Where this term appears across MedTech Terms.
- FDA Cybersecurity 101Lesson 11 of 11
- 510(k) FundamentalsLesson 6 of 7
Primary references
3 sources- 1FDA 510(k) RTA Policy (final guidance)VerifiedFDAfda.gov
- 2Acceptance Review for De Novo Classification RequestsUncheckedFDAfda.gov
- 3RAPS Regulatory FocusVerifiedRAPSraps.org
Inline markers like [1] jump to the matching reference above.