Section 524B requires manufacturers to submit a software bill of materials for cyber devices, keep vulnerability processes active, and provide evidence that cybersecurity was addressed across the product lifecycle.
The hard part is not producing one SBOM. The hard part is proving it matches the device build, stays current after release, and can be exported when a reviewer asks for the evidence trail.
Interlynk connects generation, validation, vulnerability intelligence, VEX, supplier SBOMs, and reporting so the 524B evidence is ready before the submission deadline.
Machine-readable SBOM
Generate CycloneDX or SPDX SBOMs with NTIA minimum elements, supplier names, versions, PURLs, hashes, and per-component evidence.
Vulnerability monitoring
Continuously watch every component for new CVEs, enrich findings with EPSS and KEV, and filter applicability with VEX.
Secure-by-design evidence
Map SBOM generation, review, vulnerability response, and supplier evidence into a traceable record for reviewers and auditors.
Audit & submission readiness
Export submission-ready SBOMs, vulnerability summaries, VEX status, and evidence for each device version in one queryable record.
01
Generate
Create deterministic SBOMs from your shipped software and supplier inputs.
02
Validate
Check SBOM completeness, identity quality, and minimum-element coverage before submission.
03
Monitor
Watch every released component for new vulnerabilities and maintain VEX applicability.
04
Report
Export reviewer-ready SBOM, risk, VEX, and evidence packages for each product version.
Does the FDA require an SBOM for medical devices?
For cyber devices, yes. Section 524B(b)(3) requires a machine-readable SBOM in the premarket submission, and has since March 2023. From October 2023 the FDA can refuse a submission that arrives without one.
