SBOM for Third-Party Chip Firmware
When a chip vendor's SBOM is enough, when it isn't, and what changes the moment a MedTech team modifies modem, radio, or SoC firmware in the device.
Read articleEvery article in our archive in SBOM & Supply Chain.
Looking for a quick answer instead? The FDA medical device cybersecurity FAQ covers Section 524B scope, SBOMs, threat models, CR515 and GMLP, deficiencies, and postmarket duties.
Showing 3 of 3 articles in SBOM & Supply Chain
When a chip vendor's SBOM is enough, when it isn't, and what changes the moment a MedTech team modifies modem, radio, or SoC firmware in the device.
Read article
EOS vs EOL vs Level of Support in your medical device SBOM: what Section 524B requires, how to express it in CycloneDX and SPDX, and how to defend it.
Read article
SBOM vs VEX explained for medical device submissions. What each document does, how they pair, and what the FDA actually expects in your 510(k) package.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.