FDA PCCP Beyond AI: Cybersecurity, Firmware Uses | Blue Goat
The FDA PCCP guidance isn't AI-only. Use a predetermined change control plan for cybersecurity patches, firmware updates, and SBOM component swaps.
Read articleEvery article in our archive tagged SBOM.
Showing 12 of 12 articles tagged SBOM
The FDA PCCP guidance isn't AI-only. Use a predetermined change control plan for cybersecurity patches, firmware updates, and SBOM component swaps.
Read article
How to wire SAST, SBOM, secrets, container, and signature gates into a medical-device CI/CD pipeline so the SPDF produces the evidence FDA reviewers.
Read article
A subsection-by-subsection walkthrough of FDA Section 524B for cyber medical devices: what §524B(a), (b)(1), (b)(2), (b)(3), (b)(4), and (c) require.
Read article
What the CISA Known Exploited Vulnerabilities (KEV) catalog is, how medical device manufacturers should use it in SBOM/VEX triage, and how the FDA treats.
Read article
How Health Canada regulates medical device cybersecurity in 2026: pre-market license expectations, MDEL obligations, and how to reuse an FDA Section 524B.
Read article
How the TGA regulates medical device cybersecurity in Australia in 2026: ARTG entry expectations, the TGA cybersecurity guidance, and how to reuse FDA.
Read article
Where containers appear in medical devices, the testing the FDA expects under the Feb 3, 2026 guidance, and how container evidence maps to eSTAR v7.0.
Read article
When a chip vendor's SBOM is enough, when it isn't, and what changes the moment a MedTech team modifies modem, radio, or SoC firmware in the device.
Read article
EOS vs EOL vs Level of Support in your medical device SBOM: what Section 524B requires, how to express it in CycloneDX and SPDX, and how to defend it.
Read article
The concrete SBOM elements FDA reviewers verify at RTA screening: format, identifiers, vulnerability disposition, and update process, based on 250+ reviews.
Read article
How MedTech teams should identify, triage, and document VxWorks RTOS vulnerabilities (URGENT/11 and beyond) for FDA Section 524B premarket and postmarket.
Read article
SBOM + SAST explained: how component transparency and static code scanning strengthen medical device cybersecurity and align with FDA guidance.
Read article30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.