Blog

Cybersecurity Field Notes for Medical Device Teams.

Notes on FDA, EU MDR and UK cybersecurity expectations for medical devices, written for QA/RA and software leads.

RSS Feed

Blog posts

Alan ParkinsonAlan Parkinson

Using GitHub Dependabot for your eSTAR SBOM: a practical guide (and where it falls short)

Quick answer: You can export an SBOM from GitHub's dependency graph and use Dependabot alerts to flag known vulnerabilities. For repositories using supported package managers (npm, pip, Maven, NuGet), this gives you a reasonable starting point. But an SBOM export and a list of dismissed alerts is not what the FDA expects in your eSTAR cybersecurity section. The gaps are significant, and they tend to surface at exactly the wrong moment.

Alan ParkinsonAlan Parkinson

FDA reviewers are now asking for VEX/VDR files with your SBOM

Recently a manufacturer received an AINN request asking for VEX and VDR data alongside their CycloneDX SBOM. This isn't in the premarket guidance, but you're almost certainly already doing the work. You just aren't packaging it in the format the FDA now wants.

Newsletter

Never miss an insight.
Subscribe to The Detective’s Notebook.

Practical cybersecurity regulatory insights and guides for medical device teams. Free, no spam, unsubscribe anytime.