FDA SBOM Requirements for Medical Devices: What Every MedTech Company Must Know

The Consolidated Appropriations Act, 2023, signed in December 2022, amended the Federal Food, Drug, and Cosmetic Act to add Section 524B: Ensuring Cybersecurity of Medical Devices. This provision requires medical device manufacturers to submit a software bill of materials with every premarket device submission. The FDA published detailed guidance implementing these requirements in March 2023. For medical device companies, SBOM compliance is now a condition of market access.

What the FDA Requires

Section 524B requires medical device manufacturers to provide: a Software Bill of Materials (SBOM) for each device, including commercial, open source, and off-the-shelf software components; a plan for addressing postmarket cybersecurity vulnerabilities and exploits; procedures for coordinated vulnerability disclosure; and a plan for providing updates and patches. The SBOM must include all components used in the device, including third-party and open source components, with version information sufficient to identify them in vulnerability databases.

The October 2023 Enforcement Deadline

The FDA began refusing to accept submissions that did not include the required cybersecurity documentation — including SBOMs — from October 1, 2023. Submissions for devices that are not solely hardware, that contain software, and that are intended for use in healthcare settings are subject to these requirements. This creates a hard deadline: new medical device submissions without SBOMs are not accepted.

SBOM Content Requirements for FDA

The FDA's guidance specifies that the SBOM must include: manufacturer and component names, version numbers, unique identifiers, dependency relationships, and the author of the SBOM data. This maps closely to the NTIA minimum elements. The FDA additionally recommends including license information and cryptographic hashes for components where available. The SBOM should be in a machine-readable format (SPDX or CycloneDX are explicitly acceptable).

Postmarket Monitoring: The Ongoing Obligation

Unlike a one-time submission requirement, the FDA's cybersecurity framework creates ongoing postmarket obligations. Manufacturers must monitor for newly disclosed vulnerabilities in their device's components, assess the impact of vulnerabilities on device safety and effectiveness, and update the SBOM when software changes occur. This postmarket monitoring requirement is where continuous SBOM monitoring platforms provide their most significant value for medical device manufacturers — automating the surveillance that otherwise requires manual tracking of vulnerability databases for every component in every device.

// Recommended Tool

FDA-Compliant SBOM Programs for Medical Device Manufacturers

Fossity — Fossity supports the full lifecycle of FDA SBOM compliance — generating SBOMs for device submissions, continuously monitoring deployed device components for newly disclosed vulnerabilities, and maintaining the version-controlled SBOM records that FDA postmarket monitoring requires.

Visit Fossity.com →
// Author: Esteban C.