Section 524B requires manufacturers to submit a software bill of materials for cyber devices, keep vulnerability processes active, and provide evidence that cybersecurity was addressed across the product lifecycle.
The hard part is not producing one SBOM. The hard part is proving it matches the device build, stays current after release, and can be exported when a reviewer asks for the evidence trail.
Interlynk connects generation, validation, vulnerability intelligence, VEX, supplier SBOMs, and reporting so the 524B evidence is ready before the submission deadline.
Machine-readable SBOM
Generate CycloneDX or SPDX SBOMs with NTIA minimum elements, supplier names, versions, PURLs, hashes, and per-component evidence.
Vulnerability monitoring
Continuously watch every component for new CVEs, enrich findings with EPSS and KEV, and filter applicability with VEX.
Secure-by-design evidence
Map SBOM generation, review, vulnerability response, and supplier evidence into a traceable record for reviewers and auditors.
Audit & submission readiness
Export submission-ready SBOMs, vulnerability summaries, VEX status, and evidence for each device version in one queryable record.
Which pathway are you filing, and where does the SBOM go?
The 524B cybersecurity requirement runs across premarket pathways: 510(k), PMA, De Novo, PDP, and HDE. For 510(k) and De Novo you attach the SBOM and cybersecurity documentation in the FDA's eSTAR template, which has a dedicated cybersecurity section. PMAs carry the same requirement inside the application. Interlynk exports the SBOM as a validated CycloneDX or SPDX file that drops straight into eSTAR.
What changed under QMSR (February 2026)?
Since February 2, 2026, device quality systems operate under the FDA's Quality Management System Regulation (QMSR, 21 CFR Part 820), which incorporates ISO 13485:2016. QMSR expects cybersecurity evidence, including your SBOM, to come out of controlled design and quality processes rather than being assembled once at submission time. Because Interlynk generates an SBOM on every build, that evidence is already a byproduct of your process, not a last-minute deliverable. The SBOM mandate itself still comes from Section 524B.
What 524B requires before and after clearance
Section 524B is two jobs, and the SBOM runs through both.
Premarket
Prove the device is secure and submit the evidence: secure-by-design architecture, testing, labeling, and the machine-readable SBOM covering commercial, open-source, and off-the-shelf components.
Postmarket
Keep it secure after clearance. Monitor and disclose new vulnerabilities, patch known issues on a justified cycle, and fix critical ones out-of-cycle, as soon as possible. (Section 524B(b)(1) and (b)(2))
Living SBOM
A component that's clean at submission can become a known exploited vulnerability later. Interlynk rebuilds the SBOM on every build and matches it to CISA KEV, so new exploits map to the exact device.
01
Generate
Create deterministic SBOMs from your shipped software and supplier inputs.
02
Validate
Check SBOM completeness, identity quality, and minimum-element coverage before submission.
03
Monitor
Watch every released component for new vulnerabilities and maintain VEX applicability.
04
Report
Export reviewer-ready SBOM, risk, VEX, and evidence packages for each product version.
Does the FDA require an SBOM for medical devices?
For cyber devices, yes. Section 524B(b)(3) requires a machine-readable SBOM in the premarket submission, and has since March 2023. From October 2023 the FDA can refuse a submission that arrives without one.











