
- 01Section 524B of the FD&C Act, in force since March 2023, imposed cybersecurity requirements on submissions for 'cyber devices.' The FDA refused-to-accept policy gave the requirements teeth. The SBOM mandate alone has reshaped how manufacturers manage their software supply chain.
- 02What must be in the submission: plan to monitor/identify/address postmarket cybersecurity vulnerabilities, procedures and processes that provide reasonable assurance of cybersecurity, Software Bill of Materials (commercial, open-source, off-the-shelf components), and any other information FDA may require.
- 03Postmarket obligations: vulnerability monitoring across the SBOM, coordinated disclosure procedures, patch and update mechanisms, communication to clinicians and patients. The submission is the start; postmarket discipline is the ongoing commitment.
- 04What this means for suppliers: manufacturers will demand SBOMs and security attestations from every software component supplier. If you sell a software library to a medical device manufacturer, you are now part of their FDA submission. The bar for what 'security' means in your dependencies has risen accordingly.
Section 524B of the Federal Food, Drug, and Cosmetic Act, in force since March 2023, imposed cybersecurity requirements on submissions for 'cyber devices.' The FDA refused-to-accept-policy gave the requirements teeth. The SBOM mandate alone has reshaped how manufacturers manage their software supply chain.
What must be in the submission
- 01Plan to monitor, identify, and address postmarket cybersecurity vulnerabilities
- 02Procedures and processes that provide reasonable assurance of cybersecurity
- 03Software Bill of Materials, including commercial, open-source, and off-the-shelf components
- 04Other information FDA may require to demonstrate reasonable assurance
Postmarket obligations
Vulnerability monitoring across the SBOM. Coordinated disclosure procedures. Patch and update mechanisms. Communication to clinicians and patients. The submission is the start; the postmarket discipline is the ongoing commitment.
What this means for suppliers
Manufacturers will demand SBOMs and security attestations from every software component supplier. If you sell a software library to a medical device manufacturer, you are now part of their FDA submission. The bar for what 'security' means in your dependencies has risen accordingly.


