Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Playbook · SBOM & Supply Chain

    The FDA-Compliant SBOM + VEX Playbook

    How to generate, validate, and continuously update a CycloneDX SBOM with VEX statements that survives FDA review and powers your postmarket program.

    All playbooks
    Updated April 2026 6 pages 14-min read Download PDF

    Why this matters

    Under the FDA's 2026 final premarket guidance, every cyber device submission must include a machine-readable SBOM in SPDX 2.3+ or CycloneDX 1.4+ format, plus an ongoing process for monitoring vulnerabilities in those components. PDF SBOMs and spreadsheets are no longer acceptable as the SBOM itself.

    Key takeaway: An SBOM without VEX is noise. VEX is what turns 'this CVE matched a component' into 'and here's whether it's actually exploitable in our device' - which is the question reviewers and customers actually ask.

    SPDX vs. CycloneDX - pick one

    What MUST be in your SBOM

    VEX status values (CycloneDX)

    What's in the full PDF

    Want the full 6-page playbook?

    Includes every checklist, table, and template - formatted for printing and sharing.

    Download PDF
    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.