1import{r as n,j as e,c as x,m as c,cg as g,D as w}from"./index-BYbhg4ys.js";import{P as v}from"./PageHero-EZf0LIzX.js";import{R as k}from"./RelatedLinks-Coe6FqNi.js";import{T as S,S as j,a as C,b as R}from"./StickyResultCta-DpTPeKP5.js";import{b as A}from"./download-DRYtNyt6.js";import{C as N}from"./checkbox-J1_--hIj.js";import{P as y}from"./progress-DxAorOqC.js";import{R as T}from"./Infographics-DJweTjhn.js";import{F as P}from"./FromReadinessBanner-2--eS6m_.js";import{R as D}from"./RecentRegActivity-Cpf1hDb7.js";import{R as p}from"./rotate-ccw-D5SeRsA_.js";import{P as M}from"./printer-qsPBNyWu.js";import"./safe-href-BLNcU9sr.js";import"./external-link-vqVjt2sU.js";import"./check-DPYtEcn6.js";import"./link-2-CYwhRO1E.js";import"./linkedin-B4DHPo73.js";import"./twitter-BRsfzm2H.js";import"./calendar-check-rmgmTOvO.js";import"./index-jmwvnPfJ.js";import"./arrow-left-f7NYukZw.js";const o=[{id:"covlet",section:"Cover Letter",artifact:"Cybersecurity cover-letter section mapping each §524B artifact to its eSTAR location",why:"Reviewers triage by cover letter; a missing map = AI request."},{id:"ifu",section:"Labeling (IFU)",artifact:"Cybersecurity section of the IFU: intended environment, user responsibilities, security update process",why:"Required for §524B-eligible devices and any networked device."},{id:"mds2",section:"Labeling",artifact:"Completed MDS² (Manufacturer Disclosure Statement for Medical Device Security)",why:"Hospital procurement and reviewers both expect this."},{id:"rmfile",section:"Risk Analysis",artifact:"ISO 14971 risk file with cybersecurity hazards linked to threat model",why:"Cyber risk must roll into the device risk file, not live separately."},{id:"tm",section:"Cybersecurity - Threat Model",artifact:"STRIDE or PASTA threat model with traceability to interfaces, assets, and controls",why:"AAMI TIR57 / SW96 aligned - the #1 deficiency-letter trigger."},{id:"arch",section:"Cybersecurity - Architecture",artifact:"Security architecture views: data flow, trust boundaries, interfaces, third-party components",why:"Reviewers need a picture before they read controls."},{id:"controls",section:"Cybersecurity - Controls",artifact:"Security controls table mapped to threats, with verification evidence per control",why:"'We use TLS' is not a control; the mapping is the control."},{id:"sbom",section:"Cybersecurity - SBOM",artifact:"Machine-readable SBOM (SPDX 2.3+ or CycloneDX 1.5+) covering all components incl. transitive + OS",why:"Statutory under §524B."},{id:"vex",section:"Cybersecurity - SBOM",artifact:"VEX statements (or equivalent) for known CVEs in the SBOM",why:"Without VEX, every CVE looks open."},{id:"pentest",section:"Cybersecurity - Testing",artifact:"Independent penetration test report with CVSS-rated findings and remediation evidence",why:"Reviewers expect third-party, not internal-only, testing."},{id:"fuzz",section:"Cybersecurity - Testing",artifact:"Fuzz and abuse-case testing evidence for interfaces and parsers",why:"Required for cyber devices, called out in 2026 guidance."},{id:"mon",section:"Cybersecurity - Postmarket",artifact:"Postmarket monitoring & patching plan with SLAs by severity",why:"Statutory under §524B."},{id:"cvd",section:"Cybersecurity - Postmarket",artifact:"Published Coordinated Vulnerability Disclosure (CVD) policy + security contact",why:"Statutory under §524B; reviewers will check the URL."},{id:"update",section:"Cybersecurity - Postmarket",artifact:"Secure software update mechanism description (signing, rollback, customer notification)",why:"Must show how patches actually reach the field safely."},{id:"pccp",section:"Cybersecurity - AI/ML (if applicable)",artifact:"PCCP that explicitly covers cybersecurity impact of authorized changes",why:"AI/ML modifications can change attack surface; PCCP must address it."},{id:"trace",section:"Cybersecurity - Traceability",artifact:"Traceability matrix: requirement â threat â control â verification",why:"Most efficient way to pre-empt deficiency questions."}],ee=()=>{const[i,d]=n.useState({}),[f,m]=n.useState(!1),b=t=>d(h=>({...h,[t]:!h[t]})),r=o.length,s=n.useMemo(()=>o.filter(t=>i[t.id]).length,[i]),l=n.useMemo(()=>o.filter(t=>!i[t.id]),[i]),a=Math.round(s/r*100),u=()=>{d({}),m(!1)};return e.jsxs(e.Fragment,{children:[e.jsx(x,{title:"eSTAR Cybersecurity Section Checklist",description:"Free eSTAR cybersecurity checklist for 510(k) submissions. 16 artifacts mapped to the eSTAR sections reviewers expect, with a readiness score.",path:"/tools/estar-cyber-checklist",keywords:["eSTAR cybersecurity checklist","510(k) eSTAR cyber","FDA eSTAR sections","premarket cybersecurity artifacts","Section 524B eSTAR"]}),e.jsx(v,{eyebrow:"eSTAR cyber readiness",title:"eSTAR Cybersecurity Section Checklist",subt
1itle:"Sixteen artifacts FDA reviewers look for in the eSTAR cybersecurity sections. Check what you have; we show you what's missing and where it goes."}),e.jsx(S,{}),e.jsx(P,{}),e.jsx("section",{className:"container-x py-12 lg:py-16",children:f?e.jsx("div",{className:"mx-auto max-w-4xl",children:e.jsxs("div",{className:"rounded-2xl border border-border/60 bg-card/60 p-6 md:p-8",children:[e.jsxs("div",{className:"grid items-center gap-8 md:grid-cols-[auto_1fr]",children:[e.jsx(T,{value:s,max:r,label:"Ready",sublabel:`${s} of ${r} artifacts`,tone:a>=80?"emerald":a>=50?"amber":"destructive"}),e.jsxs("div",{children:[e.jsxs("div",{className:"flex items-center gap-3",children:[e.jsx(g,{className:"h-8 w-8 text-primary","aria-hidden":!0}),e.jsxs("div",{children:[e.jsx("p",{className:"text-sm uppercase tracking-wider text-foreground/60",children:"eSTAR cyber readiness"}),e.jsxs("h2",{className:"font-display text-2xl font-semibold",children:[s," of ",r," artifacts ready"]})]})]}),e.jsx(y,{value:a,className:"mt-4"}),e.jsxs("div",{className:"mt-4 grid gap-3 sm:grid-cols-3 text-center",children:[e.jsxs("div",{className:"rounded-xl border border-border/60 bg-background/40 p-3",children:[e.jsx("p",{className:"text-xs uppercase tracking-wider text-foreground/60",children:"Ready"}),e.jsx("p",{className:"font-display text-xl font-bold text-emerald-400",children:s})]}),e.jsxs("div",{className:"rounded-xl border border-border/60 bg-background/40 p-3",children:[e.jsx("p",{className:"text-xs uppercase tracking-wider text-foreground/60",children:"Missing"}),e.jsx("p",{className:"font-display text-xl font-bold text-destructive",children:l.length})]}),e.jsxs("div",{className:"rounded-xl border border-border/60 bg-background/40 p-3",children:[e.jsx("p",{className:"text-xs uppercase tracking-wider text-foreground/60",children:"Total"}),e.jsx("p",{className:"font-display text-xl font-bold text-foreground",children:r})]})]})]})]}),e.jsxs("div",{className:"mt-8",children:[e.jsx("p",{className:"font-display text-lg font-semibold",children:"Gaps to close before submission"}),l.length===0?e.jsx("p",{className:"mt-3 text-sm text-foreground/70",children:"No gaps. Run an independent gap audit before filing to validate."}):e.jsx("ul",{className:"mt-3 space-y-3",children:l.map(t=>e.jsxs("li",{className:"rounded-xl border border-border/60 bg-background/40 p-4 text-sm",children:[e.jsx("p",{className:"font-medium text-foreground",children:t.artifact}),e.jsxs("p",{className:"mt-1 text-foreground/70",children:[t.section," · ",t.why]})]},t.id))})]}),e.jsx(j,{className:"mt-6",title:`eSTAR cyber readiness: ${s}/${r} artifacts ready`,summary:"Score your 510(k) cybersecurity artifacts against the eSTAR template in 4 minutes."}),e.jsxs("div",{className:"mt-4 flex flex-wrap gap-3",children:[e.jsxs(c,{onClick:()=>A("estar-cyber-checklist.csv",[["Section","Artifact","Status","Why it matters"],...o.map(t=>[t.section,t.artifact,i[t.id]?"Ready":"Missing",t.why])]),variant:"outline",children:[e.jsx(w,{className:"mr-1 h-4 w-4"})," Download .csv"]}),e.jsxs(c,{onClick:()=>window.print(),variant:"outline",children:[e.jsx(M,{className:"mr-1 h-4 w-4"})," Print / save as PDF"]}),e.jsxs(c,{onClick:u,variant:"ghost",children:[e.jsx(p,{className:"mr-1 h-4 w-4"})," Start over"]})]})]})}):e.jsxs("div",{className:"mx-auto max-w-3xl",children:[e.jsxs("div",{className:"mb-4 flex items-center justify-between text-sm text-foreground/60",children:[e.jsxs("span",{children:[s," of ",r," artifacts ready"]}),e.jsxs("span",{children:[a,"% complete"]})]}),e.jsx(y,{value:a,className:"mb-6"}),e.jsxs("div",{className:"rounded-2xl border border-border/60 bg-card/60 p-6 md:p-8 space-y-3",children:[o.map(t=>e.jsxs("label",{className:"flex items-start gap-3 rounded-lg border border-border/50 bg-background/30 p-3 text-sm cursor-pointer hover:border-primary/60",children:[e.jsx(N,{checked:!!i[t.id],onCheckedChange:()=>b(t.id),className:"mt-0.5"}),e.jsxs("div",{children:[e.jsx("p",{className:"font-medium text-foreground",children:t.artifact}),e.jsxs("p",{className:"mt-0.5 text-xs text-foreground/60",children:[t.section," · ",t.why]})]})]},t.id)),e.jsxs("div",{className:"flex gap-3 pt-2",children:[e.jsx(c,{onClick:()=>m(!0),children:"See gap list"}),e.jsxs(c,{variant:"ghost",onClick:u,children:[e.jsx(p,{className:"mr-1 h-4 w-4"})," Reset"]})]})]})]})}),e.jsx(C,{preview:{title:"Check what you have - see the eSTAR cyber readiness ring",items:["RingScore infographic showing the percentage of the 16 cyber artifacts you have ready.","Per-artifact list of what's ready vs. missing, with the eSTAR section number for each.","Reviewer-aligned definition of 'ready' so a half-done draft doesn't count as complete.","Print-to-PDF audit trail for your internal submission-readiness review."]},misconceptions:[{claim:"eSTAR auto-validates our cybersecurity content.",reality:"eSTAR validates structure and required attachments, not content quality. A PDF named 'SBOM.pdf' that's actually a screenshot will pass eSTAR and fail RTA review."},{claim:"All 16 artifacts must be one document each.",reality:"Some sections accept consolidated documents (e.g., security risk management report can roll up threat model + SBOM analysis). The checklist shows acceptable consolidations."},{claim:"The architecture diagram is for context, not review.",reality:"Reviewers literally trace threats and controls on your diagram. A vague network diagram is the #1 cause of follow-up AI letters in cybersecurity sections."},{claim:"If we use a Premarket Cybersecurity Decoder, eSTAR is done.",reality:"Decoders map content to sections; they don't generate the content. You still need each artifact to exist, be current, and match the rest of the submission."}],references:[{label:"eSTAR Program - Overview and Templates",publisher:"FDA",url:"https://www.fda.gov/medical-devices/how-study-and-market-your-device/estar-program"},{label:"Cybersecurity in Medical Devices Guidance (Feb 3, 2026 final) - eSTAR mapping appendix",publisher:"FDA",url:"https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket"},{label:"Content of Premarket Submissions for Device Software Functions (June 2023)",publisher:"FDA",url:"https://www.fda.gov/regulatory-information/search-fda-guidance-documents/content-premarket-submissions-device-software-functions"},{label:"Refuse-to-Accept Policy for 510(k)s",publisher:"FDA",url:"https://www.fda.gov/regulatory-information/search-fda-guidance-documents/refuse-accept-policy-510ks"}]}),e.jsx(D,{tags:["estar","premarket"]}),e.jsx(k,{eyebrow:"Build the package",heading:"Close the gaps with the right partner.",links:[{label:"FDA premarket cybersecurity services",to:"/services/fda-premarket-cybersecurity-services",blurb
1:"Full SPDF + eSTAR-ready submission."},{label:"Premarket cybersecurity checklist",to:"/guides/fda-premarket-cybersecurity-submission-checklist",blurb:"Long-form companion to this tool."},{label:"FDA §524B explained",to:"/guides/fda-524b-cybersecurity-requirements-explained",blurb:"What §524B actually requires, in plain English."},{label:"More tools",to:"/tools",blurb:"PCCP, threat model, CVD policy, deficiency triage."}]}),e.jsx(R,{toolSlug:"estar-cyber-checklist",secondaryHref:"/services/fda-premarket-cybersecurity-services",secondaryLabel:"FDA premarket services"})]})};export{ee as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.