This post is part of our research archive and is a selected publication. Although Armatyr was founded in 2026, members of our team have been conducting and publishing research in medical device and hospital IT security for over a decade. We maintain this archive to provide context for our experience and contributions to the field.
The authors examine the gap between an SBOM that satisfies FDA premarket cybersecurity guidance on paper and one that is actually complete enough to support real vulnerability response. Using an anonymized medical device SBOM, they show that a document can technically meet the FDA’s baseline attributes while still omitting deeply embedded third-party components and hardware, leaving real risk invisible to reviewers. Expanding the SBOM to include those hardware and third-party components increased vulnerability visibility by 18% and surfaced four additional critical CVEs. Their full abstract is quoted below:
The U.S. Food and Drug Administration’s (FDA) premarket cybersecurity guidance emphasizes the inclusion of a Software Bill of Materials (SBOM) as part of medical device submissions. Although the guidance does not prescribe a specific SBOM standard, it requires manufacturers to provide component data aligned with the National Telecommunications and Information Administration (NTIA) baseline attributes, along with end-of-support dates and support level descriptions. This flexibility is intended to accommodate varying development practices, but can leave critical gaps in risk visibility. In this paper, we present a case study of an anonymized medical device SBOM that technically complies with FDA expectations but omits third-party components and dependencies deeply embedded in the software architecture. We also investigate how excluding hardware components exposes devices to overlooked risks. In particular, our analysis shows that expanding an SBOM to include hardware and third-party components increased vulnerability visibility by 18%, finding an additional four critical CVEs in the system. While medical devices may achieve regulatory compliance with an SBOM that includes only the attributes above, such an SBOM does not inherently ensure meaningful cybersecurity risk management.
Kostick, Logan, Michael Rushanan, and Tushar M. Jois. “Compliance v. Completeness: A Case Study on SBOMs in Consideration of FDA Premarket Cybersecurity Guidance.” Proceedings of the Healthcare Security Workshop (HealthSec), 2025.
External References
