Linux vs Windows for Medical Devices: Security Comparison
Embedded Linux vs Windows IoT Enterprise LTSC for medical devices: attack surface, isolation, secure boot, patching, SBOM, and what FDA reviewers actually look at.
Read articleEvery article in our archive tagged SBOM.
Showing 12 of 14 articles tagged SBOM · Page 1 of 2
Embedded Linux vs Windows IoT Enterprise LTSC for medical devices: attack surface, isolation, secure boot, patching, SBOM, and what FDA reviewers actually look at.
Read article
The FDA PCCP guidance isn't AI-only. Use a predetermined change control plan for cybersecurity patches, firmware updates, and SBOM component swaps.
Read article
How to wire SAST, SBOM, secrets, container, and signature gates into a medical-device CI/CD pipeline so the SPDF produces the evidence FDA reviewers.
Read article
A subsection-by-subsection walkthrough of FDA Section 524B for cyber medical devices: what §524B(a), (b)(1), (b)(2), (b)(3), (b)(4), and (c) require.
Read article
What the CISA Known Exploited Vulnerabilities (KEV) catalog is, how medical device manufacturers should use it in SBOM/VEX triage, and how the FDA treats.
Read article
How Health Canada regulates medical device cybersecurity in 2026: device and IVDD classification, licence evidence routes, MDSAP reliance, and Section 59 reporting.
Read article
How the TGA regulates medical device cybersecurity in 2026: Essential Principles 12 and 12A, the TGA cyber security guidance v1.2, and reusing an FDA 524B package.
Read article
Where containers appear in medical devices, the testing the FDA expects under the Feb 3, 2026 guidance, and how container evidence maps to eSTAR v7.0.
Read article
When a chip vendor's SBOM is enough, when it isn't, and what changes the moment a MedTech team modifies modem, radio, or SoC firmware in the device.
Read article
EOS vs EOL vs Level of Support in your medical device SBOM: what Section 524B requires, how to express it in CycloneDX and SPDX, and how to defend it.
Read article
The four SBOM elements FDA reviewers verify at RTA screening under Section 524B: format (CycloneDX/SPDX), identifiers (PURL/CPE), vuln disposition, update process.
Read article
How MedTech teams should identify, triage, and document VxWorks RTOS vulnerabilities (URGENT/11 and beyond) for FDA Section 524B premarket and postmarket.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.