The 510(k) journey, end to end

Every phase of getting a connected device cleared — who does what, what it costs, and exactly where 510sec fits. We draft the cybersecurity package and guard the eSTAR gate; we guide the rest and tell you when you need a human expert. No overclaiming — that's the point.

20–35%
below consultant authoring plus deficiency documentation — and a redesign does not re-bill
6–10 wks → ~1 wk
cybersecurity annex timeline, consultant vs. 510sec + expert review
180 days
the eSTAR hold a complete annex protects you from

Phase 0 — A finished, verified device

guided — you + your advisor 6–18 months · your engineering budget

A 510(k) is a claim about a finished device: working product, design controls under QMSR/ISO 13485, and verification & validation with acceptance criteria.

  • Build under design controls from day one (requirements ↔ risks ↔ tests, traceable).
  • For AI devices: algorithm performance on held-out, annotated clinical data.
  • Where we fit: run the 510sec gap report iteratively from month one — design the security architecture in instead of reconstructing it at filing time.
Tip from an FDA-submissions expert who reviewed this product: the biggest struggle for small companies is knowing what will be required — that is what the early, iterative gap report is for.

Phase 1 — Classification & predicate

guided — you + your advisor ~1–2 weeks desk work · $0–5K (advisor hours)

Find your product code in FDA's classification database and choose cleared predicate device(s) for the substantial-equivalence argument.

  • Search the Product Classification database for your device type.
  • Find predicates in the 510(k) database.
  • AI/ML device with model updates planned? Plan a Predetermined Change Control Plan (PCCP) now — it pre-authorizes retraining within bounds.

Phase 2 — Pre-Submission meeting (free, recommended)

guided — you + your advisor ~75 days for FDA feedback · $5–20K advisor prep

A Q-Submission gets FDA's written answers to your riskiest questions before you spend real money: right product code? acceptable validation plan? PCCP scope?

  • Prepare a briefing document with your device description and specific questions.
  • First-time AI-SaMD filers who skip this step are the ones who get surprised at review.

Phase 3 — Fees & accounts

guided — you + your advisor 2–8 weeks (parallel) · $6,517 small-biz fee (FY2026)

Money and logins — do these early, in parallel.

  • File the Small Business Determination (Form 3602 + tax returns) → 75% fee discount.
  • Pay the MDUFA user fee; keep the Payment ID.
  • Create your submission account at the CDRH Customer Collaboration Portal.

Phase 4 — Assemble the eSTAR submission

510sec helps · human completes cyber annex: ~1 week (vs 6–10 weeks) · annex $18–30K reviewed (vs $22–47K authoring)

The eSTAR is a guided PDF that IS the submission. Most sections are your RA consultant's craft. The cybersecurity section — threat model, security risk assessment, SBOM, postmarket plan — is ours.

  • Download the free eSTAR template.
  • 510sec generates: threat model (§V.A.1), security risk assessment (§V.A.2), CycloneDX SBOM with FDA's support-status fields (§V.A.4), nine-element postmarket plan (§VI.B), and the review checklist.
  • Humans complete (we specify exactly what's needed): penetration-test report, architecture diagrams, labeling, metrics, anomalies assessment.
  • Your RA consultant writes the SE discussion, software documentation, and labeling — or a 510(k)-builder tool assists.
Why this section matters most: the cybersecurity annex is the single most expensive per-page section of a 510(k) — published consultant pricing runs $25–75K+ for it, more than an entire AI-assisted 510(k) costs elsewhere.

Phase 5 — Submit, screening, review

510sec helps · human completes 4–9 months wall-clock · ~$10K advisor support

Upload the eSTAR via the portal. Days 1–15: technical screening — any cybersecurity question without a relevant attachment can trigger a hold of up to 180 days. Then substantive review (~70% of filers get questions back).

  • Our review checklist maps every attachment to its eSTAR question before you file.
  • Cyber-deficiency letters average ~15 findings — a complete annex is the cheapest insurance in the whole process.
  • Outcome: Substantial Equivalence letter → you may market.

After clearance — the obligations don't stop

510sec helps · human completes ongoing · registration ~$10K/yr + upkeep

Establishment registration, device listing, UDI, adverse-event reporting — and §524B's postmarket duties continue for the life of the device.

  • Your postmarket cybersecurity plan is a statutory living document: monitoring, CVD process, patch timelines.
  • Where we fit: the postmarket upkeep subscription keeps the plan and your SBOM current after clearance.

The math for a typical first-time filer

8-person startup, cloud-connected Class II SaMD, small-business fee status.

Line itemStatus quoWith 510sec
Classification, predicate, Pre-Sub (RA consultant)~$15K · 3–4 mosame
Small-business determination + MDUFA fee$6.5Ksame
510(k) body: SE argument, software docs, labeling~$30–50K · 2–3 mosame
Cybersecurity annex (documents)$22–47K · 6–10 weeks
re-billed on every redesign
$18–30K · ~1 week (draft + independent expert review)
fixed — regenerations included
Penetration test (real-world work — no software can generate it)~$20–30Ksame (we specify exactly what the report must contain)
Review support & AI-request responses~$10K · 4–9 mo wall-clock~$10K, with far lower deficiency risk
Total≈ $105–160K · 14–20 months≈ $100–140K · 12–16 months

Honest framing: we don't shrink the whole pipeline — nothing software-shaped can. We remove the most expensive per-page section, and the single biggest schedule risk (the technical-screening hold).