Casebook Case 01 · Medical device SBOMs

Glossary.

The acronyms and terms you’ll see in a regulatory SBOM submission, defined in plain English for practitioners.

Alan ParkinsonAlan Parkinson
Last reviewed April 30, 20265 terms
Software Bill of Materialsaka SBOM

A structured, machine-readable inventory of every third-party software component in a product, including exact version numbers. The SBOM is the foundation that lets a manufacturer, regulator, or customer match what is inside a device against known cybersecurity vulnerabilities.

Common Vulnerabilities and Exposuresaka CVE

A public catalogue of disclosed cybersecurity vulnerabilities, each assigned a unique identifier (e.g. CVE-2014-0160 for Heartbleed). When a regulator or customer asks whether a device is affected by a specific CVE, the SBOM is what lets you answer.

SPDXaka Software Package Data Exchange

An open ISO-standardised file format for SBOMs, widely used in open-source ecosystems. SPDX documents can be expressed as JSON, YAML, or tag-value text and are accepted by both FDA and EU regulators.

CycloneDX

An OWASP-led SBOM file format with first-class support for vulnerability and exploitability data. CycloneDX is often preferred when an SBOM is paired with an ongoing post-market vulnerability process.

Vulnerability Exploitability eXchangeaka VEX

A companion document to an SBOM that records, for each known vulnerability, whether the device is actually affected and why. VEX is what turns a noisy SBOM-plus-CVE-list into a defensible regulatory and customer-facing answer.

Newsletter

Never miss an insight.
Subscribe to The Notebook.

Practical cybersecurity regulatory insights and guides for medical device teams. Free, no spam, unsubscribe anytime.