Start with the installed product

Connect each requested inventory to the device model, application, installed software version and responsible technical owner. Clinical engineering, IT, security and procurement often hold different pieces of that record. Establish a shared product and release mapping before importing inventories at scale.

Separate clinical systems, medical devices and general enterprise software. The ability to generate a local inventory, the supplier’s support terms and permissible changes can differ. An SBOM does not authorize modification of a supported device.

Request a usable supplier delivery

RequestWhy it matters
Exact product, model and versionAvoid applying the newest inventory to older installations.
Machine-readable format and versionEnable validated ingestion rather than manual transcription.
Generation context and coverage limitsUnderstand what the supplier observed.
Delivery for supported releasesCover the actual installed base.
Correction and update processReceive revisions and resolve gaps.
Security advisory / VEX channelObtain product-specific applicability evidence.
Support and replacement informationPlan response when an update is unavailable.

FDA guidance recommends ongoing access to SBOM information for users. Buyer terms should still specify the actual access, delivery and support arrangements; do not assume a general recommendation defines your vendor’s service commitment.

Source: FDA · Cybersecurity guidance, February 2026 · Section VI.

An intake workflow for buyers

  1. Authenticate the supplier and identify the purchased product.
  2. Validate format and metadata in a restricted receiving environment.
  3. Associate the inventory with supported and installed versions.
  4. Record gaps and questions in the supplier-risk queue.
  5. Correlate component findings with vulnerability intelligence.
  6. Request product-specific applicability and remediation information.
  7. Coordinate response with the product owner and established change process.

Retain inventories for retired versions according to the organization’s policy. A historical artifact can explain exposure during an earlier incident even when no current installation uses that release.

When a vulnerable component is reported

Treat an initial match as a candidate for investigation. Ask whether the relevant version and vulnerable functionality are present in the installed product, which configurations are affected, and what supplier-supported updates or mitigations exist.

Record evidence and ownership. If the installed software version is unknown, exposure remains unresolved. If a supplier asserts not affected, evaluate the statement’s version scope and rationale. Route uncertainty through the organization’s established cybersecurity and device-governance process.

This page addresses software inventory and supplier coordination, not clinical decisions or instructions to modify devices.

Build supplier obligations into acquisition

  • Define inventory access for the support period, including historical supported versions.
  • Require timely correction and notification of changed applicability.
  • Permit processing by authorized security tools and service providers.
  • Specify authenticated delivery and a durable security contact.
  • Agree on update, replacement and escalation responsibilities.
  • Address access continuity, data export and support termination.

Evaluate whether the supplier can meet the terms before purchase. Procurement can use a controlled sample: receive one inventory, map it to an installed version and ask a real component question. A promise to provide an SBOM “on request” has limited value if the request cannot reach an accountable team.

A practical healthcare pilot

Choose one device family, one clinical application and one general enterprise application. Identify versions, request inventories and rehearse an advisory investigation. Document which handoffs fail: ownership, version mapping, supplier access, quality or response evidence.

Expand after the pilot produces a verified product-to-component query and a documented supplier-response path. Measure unresolved-version assets and the age of unanswered supplier questions. These reveal readiness more clearly than the number of inventories collected.

Primary sources