Don’t Wait for SBOM Finalization: Fu

Share

University of Michigan professor Kevin Fu, who was the CDRH acting director of medical device cybersecurity, says companies don’t have to wait for FDA to finalize its guidance before starting to develop and submit software bills of materials (SBOM). In an interview posted in a ReversingLabs blog, Fu says some medical device firms are doing well with SBOMs, while others could use some serious guidance.

“It’s just so important to have SBOM in medical device design for the whole reason that SBOM exists in the first place,” Fu said. “If you don’t have an ingredient list of the third-party software, how can you even begin to answer the question, what risks are we taking? What’s the residual risk? What is our plan when software starts to get out of date? You can’t even begin until you know what you have there. So it’s just so important.”

Fu referenced an FDA draft guidance on SBOMs, noting that the comment period has closed and it’s pretty clear what the agency’s thinking is. He said he does anticipate major changes to the draft.

For companies submitting a 510(k) or PMA, he said, FDA does not technically recommend an SBOM but nothing is stopping a company from submitting one, and the best companies are submitting them. “So, if you want to have smoother sailing, you don’t have to wait…. It’s just so obvious it’s going to make your life easier when you can discuss the risk not only in broad strokes but down to the individual software packages. I view SBOM actually helping with efficiency for getting things through.”

Read more