What the FDA Requires
Section 524B requires medical device manufacturers to provide: a Software Bill of Materials (SBOM) for each device, including commercial, open source, and off-the-shelf software components; a plan for addressing postmarket cybersecurity vulnerabilities and exploits; procedures for coordinated vulnerability disclosure; and a plan for providing updates and patches. The SBOM must include all components used in the device, including third-party and open source components, with version information sufficient to identify them in vulnerability databases.
The October 2023 Enforcement Deadline
The FDA began refusing to accept submissions that did not include the required cybersecurity documentation — including SBOMs — from October 1, 2023. Submissions for devices that are not solely hardware, that contain software, and that are intended for use in healthcare settings are subject to these requirements. This creates a hard deadline: new medical device submissions without SBOMs are not accepted.
SBOM Content Requirements for FDA
The FDA's guidance specifies that the SBOM must include: manufacturer and component names, version numbers, unique identifiers, dependency relationships, and the author of the SBOM data. This maps closely to the NTIA minimum elements. The FDA additionally recommends including license information and cryptographic hashes for components where available. The SBOM should be in a machine-readable format (SPDX or CycloneDX are explicitly acceptable).
Postmarket Monitoring: The Ongoing Obligation
Unlike a one-time submission requirement, the FDA's cybersecurity framework creates ongoing postmarket obligations. Manufacturers must monitor for newly disclosed vulnerabilities in their device's components, assess the impact of vulnerabilities on device safety and effectiveness, and update the SBOM when software changes occur. This postmarket monitoring requirement is where continuous SBOM monitoring platforms provide their most significant value for medical device manufacturers — automating the surveillance that otherwise requires manual tracking of vulnerability databases for every component in every device.
FDA-Compliant SBOM Programs for Medical Device Manufacturers
Fossity — Fossity supports the full lifecycle of FDA SBOM compliance — generating SBOMs for device submissions, continuously monitoring deployed device components for newly disclosed vulnerabilities, and maintaining the version-controlled SBOM records that FDA postmarket monitoring requires.
Visit Fossity.com →