FDA's New Cybersecurity Guidance: SBOMs Are Now Mandatory for Medical Device Submissions

The U.S. Food and Drug Administration has issued final guidance requiring Software Bill of Materials as part of all premarket submissions for 'cyber devices' — medical devices that contain software, use wireless connectivity, or rely on network communications. The effective date is March 29, 2023. This is not proposed guidance or industry best practice — it is a mandatory requirement for all new device submissions.

What Is a Cyber Device Under FDA Guidance

The FDA defines a cyber device as any device that contains software validated, installed, or authorized by the sponsor; has the ability to connect to the internet; and contains any software or programming that could be susceptible to cybersecurity threats. This definition is intentionally broad and covers the vast majority of modern medical devices: insulin pumps, pacemakers, patient monitors, infusion systems, diagnostic imaging equipment, hospital information systems, and connected health applications.

What the SBOM Must Contain

FDA's guidance specifies that the SBOM must include a comprehensive inventory of all software components present in the device — including commercial, open source, and off-the-shelf software. The SBOM must meet the NTIA minimum elements (all seven mandatory fields) and be provided in a machine-readable format. The FDA expects that SBOMs be updated when significant software changes occur and that manufacturers maintain processes for monitoring their SBOM components for newly disclosed vulnerabilities.

The Broader Cybersecurity Submission Package

The SBOM is one component of a broader cybersecurity submission package that FDA now requires. The package must also include: a plan for monitoring, identifying, and addressing cybersecurity vulnerabilities and exploits post-market; processes for coordinating vulnerability disclosures; and a software update and patch management capability. The FDA expects device manufacturers to operate software update processes that can address critical vulnerabilities within a defined timeframe.

Implications for Legacy Products

The March 2023 deadline applies to new submissions — but FDA has made clear that its expectations for post-market cybersecurity apply to devices already on the market as well. The agency has indicated it will increasingly scrutinize the cybersecurity posture of legacy devices during inspections and may require remediation for devices with known unmitigated vulnerabilities. The practical effect is that medical device manufacturers need an SBOM program that covers their entire product portfolio, not just new submissions.

Building a Compliant Medical Device SBOM Program

Medical device manufacturers should: implement automated SBOM generation for all software components in each device, including OS, RTOS, middleware, and application layers; maintain SBOMs with version history for all product releases; establish continuous vulnerability monitoring against the SBOMs; and build a post-market surveillance process that can respond to newly disclosed CVEs affecting device components. Documentation of these processes should be included in quality management systems and Design History Files.

// Recommended Tool

Meet FDA SBOM Requirements with Fossity

Fossity — Fossity supports medical device manufacturers in building FDA-compliant SBOM programs — from automated generation across hardware and software components to continuous post-market vulnerability monitoring. Generate the SBOM documentation FDA requires in SPDX and CycloneDX formats.

Visit Fossity.com →
// Author: Esteban C.