From Scan Output to Reviewable Evidence
SBOMator does not promise certification. It reduces the engineering work needed to assemble, update, and defend the technical evidence behind regulated products — connecting inventory, vulnerability intelligence, VEX, and monitoring history into CRA and FDA evidence packages. Enablement, not certification.
EU Cyber Resilience Act (CRA)
The CRA requires manufacturers to know what is inside their software, identify and remediate vulnerabilities, maintain security through the support period, and retain defensible technical documentation.
Traceable Evidence Chain
Source and product identity → component inventory → vulnerability intelligence → engineering disposition → monitoring history → CRA technical-file evidence.
Technical-File Index
Annex VII technical-file index and evidence manifest organize the package for review.
Declaration Drafts
Draft Declaration of Conformity and simplified DoC — the human signing boundary is preserved.
Support-Period Record
Support-period metadata and concise SBOM/VEX summary keep lifecycle obligations visible.
Post-Market Monitoring
Rescan, compare, alert, and archive with a hash-chained audit ledger.
Six-Step Workflow
Identify · Inventory · Enrich · Decide (VEX) · Monitor · Package.
FDA Section 524B — Medical Device Cybersecurity
Section 524B requires manufacturers to connect secure-development plans, vulnerability operations, and machine-readable product inventory. Aligned to the February 2026 final guidance context and QMSR / ISO 13485.
(b)(1)(A) SBOM
Generate and maintain product software inventory.
(b)(1)(B) Monitor
Monitor, identify, and address vulnerabilities.
(b)(1)(C) Patch
Design, develop, and maintain patch/update processes.
(b)(1)(D) Communicate
Support coordinated vulnerability disclosure.
(b)(3) Machine-Readable
CycloneDX/SPDX SBOM with NTIA minimum elements.
CVSS v4.0
Recognized by the FDA as consensus standard STG #13 (2026); SBOMator parses vectors and ratings.
Honest Status View
A clear boundary between implemented evidence tooling and decisions that remain with the manufacturer.
Implemented: Evidence Foundation
SBOM & component evidence · vulnerability discovery & prioritization · VEX disposition.
Implemented: Monitoring & Packages
Continuous post-market monitoring (with limits) · CRA technical-file drafts & templates · FDA 524B evidence package.
Manufacturer Owns: Security Operations
Cybersecurity risk assessment · security-update delivery · ENISA 24h/72h reporting.
Manufacturer Owns: Formal Decisions
Signed Declaration of Conformity · CE marking & conformity route · risk acceptance and formal approval.
Build Defensible CRA & FDA Evidence
Connect product inventory, vulnerability decisions, and monitoring history into reviewable evidence packages while preserving every required human approval boundary.