The FDA's 2023 final rule on cybersecurity for medical devices (Section 524B of FD&C Act) requires manufacturers to submit a Software Bill of Materials (SBOM). The primary purpose of the SBOM is to:
-
A
Replace the need for penetration testing
-
B
Enable identification of software components and their known vulnerabilities
-
C
Satisfy FDA's Unique Device Identifier (UDI) requirements
-
D
Document the software development lifecycle process