Contains Nonbinding Recommendations 
 
 
 
 17 
important tool for transparency with users of potential risks as part of labeling as addressed later 
in Section VI.  
 
(b) 
Documentation Supporting Software Bill of Materials 
FDA’s guidance document “Off-The-Shelf (OTS) Software Use in Medical Devices” describes 
information that should be provided in premarket submissions for software components for 
which a manufacturer cannot claim complete software lifecycle control. In addition to the 
information recommended in that guidance, manufacturers should provide machine-readable 
SBOMs consistent with the minimum elements (also referred to as “baseline attributes”) 
identified in the October 2021 National Telecommunications and Information Administration 
(NTIA) Multistakeholder Process on Software Component Transparency document “Framing 
Software Component Transparency: Establishing a Common Software Bill of Materials 
(SBOM).” 
 
In addition to the minimum elements identified by NTIA, for each software component 
contained within the SBOM, manufacturers should include in the premarket submission: 
 
• The software level of support provided through monitoring and maintenance from the 
software component manufacturer (e.g., the software is actively maintained, no longer 
maintained, abandoned); and 
• The software component’s end-of-support date. 
 
When provided, manufacturers may choose to provide these additional elements as part of the 
SBOM, or they may provide it separately, such as in an addendum. Industry-accepted formats of 
SBOMs are encouraged.  
 
If a manufacturer is unable to provide the SBOM information to FDA, the manufacturer should 
provide a justification for why the information cannot be included in the premarket submission.  
 
As part of the premarket submission, manufacturers should also identify all known 
vulnerabilities associated with the device and the software components, including those 
identified in CISA’s Known Exploited Vulnerabilities Catalog. For each known vulnerability, 
manufacturers should describe how the vulnerabilities were discovered to demonstrate whether 
the assessment methods were sufficiently robust. For components with known vulnerabilities, 
device manufacturers should provide in premarket submissions: 
 
• A safety and security risk assessment of each known vulnerability (including device and 
system impacts); and 
• Details of applicable safety and security risk controls to address the vulnerability. If risk 
controls include compensating controls, those should be described in an appropriate level 
of detail. 
 
For additional information and discussion regarding proprietary and third-party components, see 
Section V.B.2, Security Architecture Views, below. 
 
