Medical Device Software Bill of Materials Reaches a Turning Point: Peering Under the Hood at Security Challenges
The software bill of materials (SBOM), as a tool to enhance cybersecurity in medical devices, has entered a critical development phase driven by the Biden executive order and NTIA initiatives. The FDA plans to incorporate SBOM into premarket submission requirements and is exploring a broader cybersecurity bill of materials (CBOM). However, the industry has concerns about information leakage risks and implementation burdens, with NTIA and AdvaMed debating access control and standardization.

For years, the U.S. Food and Drug Administration (FDA) has emphasized the need for a software bill of materials (SBOM)—an electronically readable inventory of third-party components in medical devices—to address pervasive cybersecurity vulnerabilities. The concept gained significant momentum in May 2021 when President Joe Biden signed an executive order aimed at bolstering the nation's cybersecurity posture, including by strengthening the security of the software supply chain.
That executive order's momentum, combined with a multi-stakeholder initiative led by the National Telecommunications and Information Administration (NTIA) within the U.S. Department of Commerce to improve transparency of software components across industries, including health technology, may have created a turning point for SBOMs.
Kevin Fu, acting director of cybersecurity for devices at the FDA's Center for Devices and Radiological Health (CDRH), told MedTech Dive in June that it is critical for medical device manufacturers to provide SBOMs so that they can "better understand the exposure to known and future vulnerabilities of third-party software in legacy devices." Many older medical devices still in use—running outdated or insecure software—were not designed with cyber protections in mind. SBOM proponents argue that without this visibility, healthcare providers like hospitals often do not realize that the devices they use contain components that could be easily exploited by hackers. By standardizing the data-sharing process, device users can gain a clearer picture of what exactly is running on their networks and how to protect it, the logic goes.
The FDA supported the NTIA's SBOM initiative from its start in 2018, helping to develop the program's models, formats, and other outputs that could eventually be used by the National Institute of Standards and Technology (NIST) for its software integrity guidance to implement Biden's executive order. Suzanne Schwartz, director of the CDRH's Office of Strategic Partnerships and Technology Innovation, told MedTech Dive in August that the agency wants to require health technology companies to provide SBOMs in premarket submissions ahead of time. The FDA's decision to push for this requirement in 2021 is based on Biden's executive order and the growing number of ransomware and other cyberattacks targeting healthcare organizations.
"An SBOM that only sits in the manufacturer's records does not help; the opportunity for risk mitigation is in transparency," Schwartz said. "The owners and operators of the device—whether it's a hospital, a healthcare organization, a provider, or a patient—should be aware of the SBOM, and that is a requirement that we are working toward, involving future legislative proposals." However, the FDA's intent goes beyond simply mandating a list of third-party software components in devices. The HHS Fiscal Year 2021 Congressional Budget Justification states that the FDA is seeking a statutory requirement for a "phased-in implementation of a cybersecurity bill of materials (CBOM)," which would include, but not be limited to, a list of commercial, open-source, and off-the-shelf software and hardware components that "are or could be susceptible to vulnerabilities." According to the FDA, the software-focused SBOM would be part of the broader CBOM requirement, which would include managing third-party cybersecurity risks that are hardware-centric.
Healthcare organizations' ignorance about their own medical devices is alarming, leaving them vulnerable to cyberattacks. A recent Ponemon Institute survey found that only 36% of surveyed groups believed they were effective in knowing the location of all their medical devices, while only 35% said they knew when device vendors' operating systems reached end-of-life or became outdated. Allan Friedman, former director of cybersecurity programs at NTIA and now at the Cybersecurity and Infrastructure Security Agency (CISA), warned that without a list of third-party components, healthcare providers would find it difficult to know which medical devices are affected and how to implement mitigation strategies once a vulnerability is discovered.
"You can't defend what you don't know."
— Allan Friedman, Cybersecurity and Infrastructure Security Agency
Friedman praised Biden's executive order (which will change federal acquisition regulations) for "elevating the status of SBOMs and software supply chain transparency" and for "setting the stage for the positive standards developed over the past three years at NTIA." When asked whether the FDA's requirement for SBOMs as part of premarket submissions was a good idea, Friedman declined to answer. But he suggested that knowing what is "under the hood" of medical devices allows healthcare providers to quickly determine whether they are affected by newly discovered cyber vulnerabilities.
A roadmap for hackers or defenders?
The premise of the SBOM concept is that third-party component information is presented in a machine-readable format, making it easy to share with stakeholders such as healthcare providers. But this data could also be accessed and exploited by cybercriminals, potentially making medical devices more vulnerable to attacks—at least that is a concern within the medical device industry. Zach Rothstein, vice president of technology and regulatory affairs at AdvaMed (the Advanced Medical Technology Association), said: "We just want to make sure from a common-sense perspective that certain guardrails are in place. When SBOMs are released, they really should be in a secure environment so that the general public cannot access them." Although NTIA calls this a common misconception and concern, the agency acknowledges that theoretically it is possible because "all information is a double-edged sword." NTIA believes that "the defensive benefits of transparency far outweigh this common concern, because an SBOM is more like a 'roadmap for defenders' than a dangerous sensitive data source for hackers to target medical devices."
The FDA, in its 2018 Medical Device Safety Action Plan, already alerted the industry that it was considering requiring companies to develop SBOMs as part of premarket submissions and provide them to medical users. AdvaMed's formal comments questioned the benefits of SBOMs, given the inherent risk of information falling into the wrong hands, and warned of an excessive implementation burden on healthcare providers. The lobbying group also expressed concerns about the lack of proper controls for sharing and maintaining SBOMs, warning that if these electronically readable files were stored in a public central database, they could let hackers know what software is running inside devices and put patients at risk of potential harm. "In the period after a vulnerability is discovered, a device may be at higher risk of exploitation—until the vulnerability is mitigated—if the information contained in the SBOM is obtained by malicious actors," AdvaMed warned. AdvaMed recommended that "access to SBOM information should be restricted, for example, to hospital network operators only," to ensure that "appropriate risk management is in place and unintended consequences are mitigated."
NTIA appears open to such access controls and included them in the agency's minimum elements guidance for SBOMs released in July. "Many vendors, including open-source maintainers and vendors of widely available software, may find it in their best interest to make SBOM data public," NTIA said. "Other organizations, especially in the early stages, may want to keep this data confidential and restrict access to specific customers or users." Overall, Rothstein said the health technology industry "by and large" supports SBOMs, particularly as a potential solution to help protect legacy medical devices from growing cyber threats. But AdvaMed also wants to see uniform standards to ensure device manufacturers provide the same information and "don't have to create 10 different versions to meet SBOM requirements," Rothstein said. Ultimately, NTIA concluded that successful implementation of SBOMs across multiple industries will require both broad rules and policies and sector-specific flexibility. Friedman acknowledged this fundamental tension: a "one-size-fits-all" approach to SBOMs "is easier to scale and easier to build tools and policies around," while "sector-specific" approaches for industries like health technology remain to be worked out.
