Overview: The FDA now expects device manufacturers to provide a Software Bill of Materials (SBOM) detailing all third-party, open-source, and proprietary components. This includes their version, supplier, known vulnerabilities, and support status. A complete SBOM is foundational for identifying inherited risks, evaluating software provenance, and responding to vulnerabilities throughout the device lifecycle. It must be machine-readable, maintained over time, and linked to testing, patching, and disclosure processes.