The February guidance
The SPDF era: the full artifact set reviewers expect — threat models, pen-test evidence, labeling, and ISO 14971 linkage.
Free field guide · PDF
The February guidance, the SBOM mandate, and the postmarket duty — with the cybersecurity practice you need.
Sourced from verified 2026 publications.
Enter your work email and we'll send the PDF straight to your inbox.
What's inside
Every figure in this guide traces to a named source — verified 2026 publications.
The SPDF era: the full artifact set reviewers expect — threat models, pen-test evidence, labeling, and ISO 14971 linkage.
Section 524B federal law: SPDX/CycloneDX, CPE/PURL identifiers, VEX, transitive dependencies — and keeping it current under QMSR.
The vulnerability management plan: cadence, decision criteria, customer communication, and lifetime security updates.
This guide is market-access intelligence, not regulatory, legal, or engineering advice. FDA cybersecurity expectations, SBOM practice, and vulnerability rules change — professional review is required before business use.
Market Access Strategy Session
A Market Access Strategy Session maps your cybersecurity route — SPDF setup, SBOM generation, and postmarket planning.
Professional review is required before business use.
Back to ghmap.io Questions? Talk to our team