AI / SaMD
Software Lifecycle, Cybersecurity, and FDA AI expectations, packaged for review.
Software and AI submissions don’t fail because “the code is bad.” They fail because documentation is incomplete, inconsistent, or not aligned to FDA expectations. We build submission-ready software artifacts (including IEC 62304 alignment), define a controlled software lifecycle, implement a PCCP / ML change protocol, and package a defensible cybersecurity story—so your eSTAR and reviewer experience is clean and coherent.
Traceability
Requirements → risks → architecture → verification evidence.
Change control
Release governance and controlled updates for regulated software.
Cybersecurity
Threats, controls, SBOM planning, and reviewer-readable evidence.
Reviewer clarity
Clean eSTAR mapping and consistency across exhibits and labeling.
What you get
Submission-ready artifacts that reduce review friction.
These are the core topics we build into your regulatory strategy and submission artifacts. Each item is designed to reduce review friction and prevent the common “software documentation gap” that triggers additional information requests.
IEC 62304 alignment
Lifecycle documentation scaled to your risk class
- Software safety classification + rationale
- Documentation level determination (Basic vs Enhanced)
- Traceability structure (requirements → design → code → tests)
Software lifecycle
Design controls for software teams
- Requirements + architecture baselining
- Verification/validation strategy + evidence packaging
- Release management + change control for regulated updates
PCCP / ML change protocol
A controlled plan for model updates
- Define “what can change” vs “what can’t” without new review
- Update triggers, monitoring, and rollback criteria
- Data boundaries + validation approach
Cybersecurity
Threats, controls, and evidence
- Threat model (STRIDE) + AAMI SW96 security risk management
- Rated cybersecurity risk assessment + architecture views
- SBOM framework, vulnerability handling, update strategy
FDA AI expectations
Defensibility and transparency
- Performance framing and dataset considerations
- Clinical workflow, bias considerations, labeling boundaries
- Post-market monitoring plan (drift, complaints, CAPA linkage)
eSTAR / submission packaging
Make software review easy
- Section mapping + exhibit structure and naming
- Consistency checks across software, risk, labeling, performance
- Final QA to reduce avoidable AI requests
Why submissions stall
Most delays are preventable.
Missing traceability, unclear lifecycle controls, weak cybersecurity narrative, or performance evidence that doesn’t align with claims. We connect artifacts across risk, requirements, verification, labeling, and post-market plans.
Common failure modes
- Traceability gaps: requirements and hazards don’t map cleanly to tests and releases.
- Uncontrolled updates: no defined change protocol—especially for ML models.
- Cybersecurity omissions: threats/controls/evidence not packaged reviewer-first.
- Claims outpace evidence: performance doesn’t support intended use + labeling language.
How we prevent it
- Artifact map: what FDA expects for your software risk profile and submission type.
- Consistency QA: align software docs, risk file, labeling, and performance package.
- Cyber narrative: threat model → controls → verification evidence → post-market plan.
- Change governance: release controls and ML update protocol designed to be defensible.
Programs & pricing
Fee schedule effective October 1, 2026 (FY2027)Engagements scoped to maturity and risk.
Choose the level of support that matches your timeline, software maturity, and submission pathway. Fees quoted as “from” reflect a minimum scope and are confirmed in writing after intake.
01 — Software readiness sprint
- FDA Pathway & Readiness Diagnostic$6,500
- Predicate & SE Landscape Memo (SaMD / AI)$5,500
- Predicate Verification (confirm one you have)$2,500
- IEC 62304 deliverables map + documentation level determination
- SDLC + change control recommendations
- Cyber strategy outline (threats/controls/evidence)
02 — Software & AI artifact packages
- Cybersecurity documentation package$12,500
- SW96 security risk mgmt, threat model, rated risk assessment, architecture views, SBOM framework
- ISO 14971 risk management file$8,500
- IEC 62304 software documentation package$12,500–$22,500
- Documentation level evaluation, SRS, architecture, SDLC description, V&V summary
- PCCP / ML change protocol package$12,500–$28,500
- Change scope, triggers, validation, rollback, drift monitoring
All four are included in a full SaMD submission engagement — buy them separately only if you are self-authoring the rest.
03 — Submission — full build
- SaMD / AI-enabled 510(k)from $45,000
- De Novo requestfrom $65,000
- Software/cyber sections only (co-authoring)$12,500–$28,500
- eSTAR build + QA (packaging only)$6,500–$18,500
- AI (Additional Information) response$4,500–$12,500
The full-build fee includes the IEC 62304 documentation package, cybersecurity package, ISO 14971 risk file, Small Business Determination filing, and predicate watch through clearance.
Prefer to spread it out? The 510(k) Build Plan runs at $7,500/month over a six-month minimum.
04 — Pre-Sub for AI / SaMD
- Standard Q-Sub — single topic, evidence in hand$9,500
- AI / SaMD Q-Sub — multi-question, evidence strategy$12,500–$22,500
- Performance framing, dataset and endpoint questions, PCCP scope, cybersecurity expectations
- Question strategy + meeting objectives
- Briefing package drafting + exhibits
- Meeting prep + minutes support
A Pre-Sub is the cheapest way to find out that FDA disagrees with you. There is no FDA user fee — the entire cost is the briefing package, and the questions are the deliverable. The AI/SaMD band reflects the analysis required to ask them well.
Also available: 513(g) Request for Information — $4,500 plus the FDA fee, when you want FDA’s own written classification answer rather than our analysis.
What we need to start
Intended use/claims, software description + architecture overview, current SDLC practices, release history, any threat modeling work, and any performance validation results (including datasets/metrics if ML is involved).
Start async
Share your product details and we’ll respond with a scoped plan and a prioritized artifact list (what to build now vs later), mapped to your likely submission type and risk profile.
• Fee schedule effective October 1, 2026 (FY2027). Existing clients are held at prior-year pricing through their next renewal.
• Fees are for consulting services and document preparation. FDA user fees, penetration/security testing, and clinical study costs are billed at cost and are separate.
• We do not fabricate test results. Software V&V execution, SBOM generation from your build, and security test reports remain your engineering team’s deliverables; we define, structure, and package them.
• Ongoing coverage is available through the AI & SaMD Regulatory Intelligence Club ($1,500–$2,500/mo) and the Device Growth Partner program ($6,500–$11,000/mo).
Process
Engineering-friendly workflow. Regulator-friendly outputs.
A practical flow that produces consistent documentation and reviewer-ready packaging.
Claims + risk
Stabilize intended use/claims and define risk boundaries that drive documentation depth.
Lifecycle + traceability
Set IEC 62304-aligned artifacts and traceability from requirements to verification evidence.
Cyber + updates
Implement cybersecurity documentation and define controlled change protocols (including ML updates).
eSTAR + QA
Assemble exhibits for reviewer readability and run consistency QA across software, risk, labeling, and performance.
FAQs
Clear answers for software teams.
What FDA tends to care about, and how to package it cleanly.
Do we need IEC 62304 even if we’re “just software”?
If your product is regulated as a device (including SaMD), you should expect lifecycle documentation and traceability consistent with FDA software expectations. We scale depth to your risk profile and product type, starting with the documentation level determination (Basic vs Enhanced), which decides whether a Software Design Specification is owed at all.
Why does a SaMD 510(k) start at $45,000 when other 510(k)s start lower?
Because the artifact list is longer and none of it is optional. A software submission carries IEC 62304 lifecycle documentation, an SRS, architecture and data-flow documentation, software V&V packaging, a full cybersecurity set (threat model, security risk management, rated risk assessment, architecture views, SBOM), and a risk file that connects software failure to clinical harm. Bought individually those packages alone exceed $30,000.
What is a PCCP / ML change protocol?
A controlled plan defining how a model can change over time—what can update, how performance is validated, what triggers review, and how drift is monitored—so post-market updates remain defensible without a new submission for every retrain.
Will cybersecurity be required?
If your device connects to networks, exchanges data, uses third-party libraries, or could impact clinical decisions, cybersecurity documentation is typically expected. Scope depends on whether the device was previously authorized. We build the narrative and evidence package appropriate to your design and risk.
Is the assessment fee credited if we move forward?
Yes. One assessment fee — the Predicate Memo, Predicate Verification, or Pathway Diagnostic — is credited in full against a 510(k) or De Novo engagement opened within 90 days. If you purchased more than one, the highest is credited. Pre-Submission and 513(g) fees are execution work and are not credited.
Can you generate our SBOM and run our software testing?
No—and you should be cautious of anyone who says yes. The authoritative SBOM must be machine-generated from your build, and V&V results must come from your development records. We build the documentation framework, the security and safety risk analyses, and the submission packaging around them.
