Eleven questions mapped to FDA §524B and the current premarket cybersecurity guidance - now covering build provenance (SLSA), signing (Sigstore), AI-generated code, and dependency-confusion defenses. Get a score and a prioritized gap list.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
What you'll see after you submit
Common misconceptions
Myth: A top-level dependency list is an SBOM.
Reality: FDA expects transitive depth. The SBOM must include components your components depend on, down to the smallest unit you can practically resolve (NTIA 'minimum elements').
Myth: SPDX and CycloneDX are interchangeable for FDA.
Reality: Both are accepted, but each has different VEX maturity, hashing conventions, and tooling support. Pick one, document why, and stay consistent across premarket and postmarket.
Myth: Once we ship the SBOM, we're done.
Reality: §524B requires a maintained SBOM with monitoring and updates for the supported lifetime of the device. A static PDF in your submission is a postmarket deficiency in waiting.
Myth: VEX is optional.
Reality: It's not statutorily required, but without VEX every new CVE in your SBOM looks like an open issue. FDA reviewers and customers now expect VEX to disposition non-exploitable findings.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
CISA adds use-after-free in Linux kernel netfilter to KEV (CVE-2026-0511)
BLE pairing bypass in widely embedded Bluetooth stack added to KEV
CycloneDX 1.6.1 errata - clarifies VEX status semantics for medical devices
SLSA v1.1 published - tightened build-provenance language for regulated industries
SPDX/CycloneDX SBOMs generated each build with CVE/KEV/VEX maintenance.
Read FDA-compliant SBOM servicesWhat's actually required vs. legacy terminology reviewers still use.
Read SBOM vs CBOMWhich format to choose for a medical device submission.
Read SPDX vs CycloneDXPCCP, §524B checker, SaMD classifier, readiness quiz.
Read More tools