Interlynk · Medical Device SBOM Compliance
Interlynk · Medical Device SBOM Compliance
Interlynk · Medical Device SBOM Compliance

Submission-ready SBOM for FDA 524B.

Submission-ready SBOM for FDA 524B.

Submission-ready SBOM for FDA 524B.

The FDA requires a machine-readable SBOM in every 524B submission. Interlynk builds yours from the firmware you actually ship, with the component detail and exploitability data a reviewer will check. The same evidence supports your EU MDR technical file.

The FDA requires a machine-readable SBOM in every 524B submission. Interlynk builds yours from the firmware you actually ship, with the component detail and exploitability data a reviewer will check. The same evidence supports your EU MDR technical file.

The FDA requires a machine-readable SBOM in every 524B submission. Interlynk builds yours from the firmware you actually ship, with the component detail and exploitability data a reviewer will check. The same evidence supports your EU MDR technical file.

CycloneDX + SPDX • NTIA minimum elements • VEX • Lifecycle • Support status • FDA Metric

CycloneDX + SPDX • NTIA minimum elements • VEX • Lifecycle • Support status • FDA Metric

Interlynk turns firmware builds and vendor SBOMs into submission-ready FDA 524B evidence, with premarket export and postmarket vulnerability monitoring.

Trusted by medical device teams in

SiMD
SaMD
AISaMD
SiMD

Trusted by medical device teams in

MedTech
MedTech
BIOTRONIK
STERIS
Matillion
Empo Health
MedQAIR
MICSI
THE PROBLEM
THE PROBLEM
THE PROBLEM

FDA 524B turns SBOMs into submission evidence.

FDA 524B turns SBOMs into submission evidence.

Section 524B requires manufacturers to submit a software bill of materials for cyber devices, keep vulnerability processes active, and provide evidence that cybersecurity was addressed across the product lifecycle.

The hard part is not producing one SBOM. The hard part is proving it matches the device build, stays current after release, and can be exported when a reviewer asks for the evidence trail.

Interlynk connects generation, validation, vulnerability intelligence, VEX, supplier SBOMs, and reporting so the 524B evidence is ready before the submission deadline.

WHAT FDA EXPECTS
WHAT FDA EXPECTS
WHAT FDA EXPECTS

The 524B evidence package, automated.

The 524B evidence package, automated.

From premarket submission under Section 524B to postmarket vulnerability response, Interlynk keeps the SBOM evidence tied to the device you actually shipped.

From premarket submission under Section 524B to postmarket vulnerability response, Interlynk keeps the SBOM evidence tied to the device you actually shipped.

Machine-readable SBOM

Generate CycloneDX or SPDX SBOMs with NTIA minimum elements, supplier names, versions, PURLs, hashes, and per-component evidence.

Vulnerability monitoring

Continuously watch every component for new CVEs, enrich findings with EPSS and KEV, and filter applicability with VEX.

Secure-by-design evidence

Map SBOM generation, review, vulnerability response, and supplier evidence into a traceable record for reviewers and auditors.

Audit & submission readiness

Export submission-ready SBOMs, vulnerability summaries, VEX status, and evidence for each device version in one queryable record.

524B CHECKLIST
524B CHECKLIST
524B CHECKLIST

What reviewers ask for, and what Interlynk produces.

What reviewers ask for, and what Interlynk produces.

FDA expectation

Interlynk output

Audit value

Machine-readable SBOM

CycloneDX or SPDX with component metadata, PURLs, hashes, suppliers, and versions.

Traceable artifact for each submitted device build.

Vulnerability process

Continuous CVE monitoring with EPSS, KEV, CWE, and VEX status.

Shows how you identify, assess, and act on postmarket risk.

Secure-by-design evidence

Quality checks, policy results, supplier SBOMs, and evidence history.

Connects development records to regulatory claims.

Submission and audit export

Reviewer-ready package per product, release, and device family.

Reduces spreadsheet assembly and one-off evidence collection.

IN THE SUBMISSION
IN THE SUBMISSION
IN THE SUBMISSION

How your SBOM fits the FDA submission

How your SBOM fits the FDA submission

Section 524B decides whether you need an SBOM. Where it goes depends on your pathway.

Section 524B decides whether you need an SBOM. Where it goes depends on your pathway.

Which pathway are you filing, and where does the SBOM go?

The 524B cybersecurity requirement runs across premarket pathways: 510(k), PMA, De Novo, PDP, and HDE. For 510(k) and De Novo you attach the SBOM and cybersecurity documentation in the FDA's eSTAR template, which has a dedicated cybersecurity section. PMAs carry the same requirement inside the application. Interlynk exports the SBOM as a validated CycloneDX or SPDX file that drops straight into eSTAR.

What changed under QMSR (February 2026)?

Since February 2, 2026, device quality systems operate under the FDA's Quality Management System Regulation (QMSR, 21 CFR Part 820), which incorporates ISO 13485:2016. QMSR expects cybersecurity evidence, including your SBOM, to come out of controlled design and quality processes rather than being assembled once at submission time. Because Interlynk generates an SBOM on every build, that evidence is already a byproduct of your process, not a last-minute deliverable. The SBOM mandate itself still comes from Section 524B.

OBLIGATIONS

OBLIGATIONS

OBLIGATIONS

What 524B requires before and after clearance

Section 524B is two jobs, and the SBOM runs through both.

Premarket

Prove the device is secure and submit the evidence: secure-by-design architecture, testing, labeling, and the machine-readable SBOM covering commercial, open-source, and off-the-shelf components.

Postmarket

Keep it secure after clearance. Monitor and disclose new vulnerabilities, patch known issues on a justified cycle, and fix critical ones out-of-cycle, as soon as possible. (Section 524B(b)(1) and (b)(2))

Living SBOM

A component that's clean at submission can become a known exploited vulnerability later. Interlynk rebuilds the SBOM on every build and matches it to CISA KEV, so new exploits map to the exact device.

Note: Your submission SBOM and your postmarket monitoring run on the same inventory, so it has to stay live.

Note: An importer or distributor becomes a manufacturer if they place a product under their

own name or substantially modify it.

HOW INTERLYNK HELPS
HOW INTERLYNK HELPS
HOW INTERLYNK HELPS

One workflow from build evidence to FDA response.

One workflow from build evidence to FDA response.

01

Generate

Create deterministic SBOMs from your shipped software and supplier inputs.

02

Validate

Check SBOM completeness, identity quality, and minimum-element coverage before submission.

03

Monitor

Watch every released component for new vulnerabilities and maintain VEX applicability.

04

Report

Export reviewer-ready SBOM, risk, VEX, and evidence packages for each product version.

FAQ
FAQ
FAQ

FDA 524B questions, answered.

FDA 524B questions, answered.

FDA 524B questions, answered.

Does the FDA require an SBOM for medical devices?

For cyber devices, yes. Section 524B(b)(3) requires a machine-readable SBOM in the premarket submission, and has since March 2023. From October 2023 the FDA can refuse a submission that arrives without one.

What is a cyber device under Section 524B?

What SBOM format does the FDA accept?

What does a compliant medical-device SBOM have to contain?

What cybersecurity metrics does the FDA want?

Does the EU MDR require an SBOM?

Does the EU Cyber Resilience Act apply to medical devices?

Can one SBOM satisfy both the FDA and the EU?

What happens if I submit to the FDA without an SBOM?

Trusted by security and compliance teams at 100+ regulated companies

Audit-ready SBOM. With every build.

Interlynk automates SBOMs, manages open source risks, monitors suppliers, and prepares you for the post-quantum era, all in one trusted platform.

Trusted by security and compliance teams at 100+ regulated companies

Interlynk automates SBOMs, manages open source risks, monitors suppliers, and prepares you for the post-quantum era, all in one trusted platform.

Audit-ready SBOM. With every build.

Trusted by security and compliance teams at 100+ regulated companies

Interlynk automates SBOMs, manages open source risks, monitors suppliers, and prepares you for the post-quantum era, all in one trusted platform.

Audit-ready SBOM. With every build.