Regulatory Evidence — CRA & FDA | ESL SBOMator
Regulatory Evidence — CRA & FDA

From Scan Output to Reviewable Evidence

SBOMator does not promise certification. It reduces the engineering work needed to assemble, update, and defend the technical evidence behind regulated products — connecting inventory, vulnerability intelligence, VEX, and monitoring history into CRA and FDA evidence packages. Enablement, not certification.

EU Cyber Resilience Act (CRA)

The CRA requires manufacturers to know what is inside their software, identify and remediate vulnerabilities, maintain security through the support period, and retain defensible technical documentation.

Traceable Evidence Chain

Source and product identity → component inventory → vulnerability intelligence → engineering disposition → monitoring history → CRA technical-file evidence.

Technical-File Index

Annex VII technical-file index and evidence manifest organize the package for review.

Declaration Drafts

Draft Declaration of Conformity and simplified DoC — the human signing boundary is preserved.

Support-Period Record

Support-period metadata and concise SBOM/VEX summary keep lifecycle obligations visible.

Post-Market Monitoring

Rescan, compare, alert, and archive with a hash-chained audit ledger.

Six-Step Workflow

Identify · Inventory · Enrich · Decide (VEX) · Monitor · Package.

FDA Section 524B — Medical Device Cybersecurity

Section 524B requires manufacturers to connect secure-development plans, vulnerability operations, and machine-readable product inventory. Aligned to the February 2026 final guidance context and QMSR / ISO 13485.

(b)(1)(A) SBOM

Generate and maintain product software inventory.

(b)(1)(B) Monitor

Monitor, identify, and address vulnerabilities.

(b)(1)(C) Patch

Design, develop, and maintain patch/update processes.

(b)(1)(D) Communicate

Support coordinated vulnerability disclosure.

(b)(3) Machine-Readable

CycloneDX/SPDX SBOM with NTIA minimum elements.

CVSS v4.0

Recognized by the FDA as consensus standard STG #13 (2026); SBOMator parses vectors and ratings.

524B evidence report. HTML + Markdown + manifest, color-coded severity and VEX-state badges, and per-row CVE ID / CVSS / justification / remediation, with COMPLIANT / PARTIAL / NON-COMPLIANT / NEEDS INPUT status mapping — printable and submission-ready.

Honest Status View

A clear boundary between implemented evidence tooling and decisions that remain with the manufacturer.

Implemented: Evidence Foundation

SBOM & component evidence · vulnerability discovery & prioritization · VEX disposition.

Implemented: Monitoring & Packages

Continuous post-market monitoring (with limits) · CRA technical-file drafts & templates · FDA 524B evidence package.

Manufacturer Owns: Security Operations

Cybersecurity risk assessment · security-update delivery · ENISA 24h/72h reporting.

Manufacturer Owns: Formal Decisions

Signed Declaration of Conformity · CE marking & conformity route · risk acceptance and formal approval.

Positioning. SBOMator is a compliance-enablement and evidence platform — not a certification system or legal guarantee. It supports evidence preparation; manufacturer review, validation, risk acceptance, formal approval, conformity assessment, signatures, reporting, and CE marking remain required. This is informational and not legal advice.

Build Defensible CRA & FDA Evidence

Connect product inventory, vulnerability decisions, and monitoring history into reviewable evidence packages while preserving every required human approval boundary.