logo

SBOMs and medical devices: An essential step — but no security cureall

ID: 52a99d59-00fd-5ae3-a7b5-17894f00e525

STIX ID: report--52a99d59-00fd-5ae3-a7b5-17894f00e525

Feed Name: ReversingLabs Blog

Date Published: 2024-03-11

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

The report explains recent U.S. federal actions to secure the healthcare software supply chain, highlighting the FDA’s 2023 “Cybersecurity in Medical Devices” guidance aligned with H.R.2617, which requires medical device manufacturers to submit SBOMs, vulnerability management plans, and secure development procedures to the FDA. It clarifies that the guidance offers recommended approaches for compliance and stresses that SBOMs are only a starting point, urging the industry to address wider risks such as malware, tampering, and secrets exposure across medical device ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.