Compliance & Regulation

When does a vulnerability require patching?

Not every vulnerability in your SBOM requires a patch. The FDA's 2016 postmarket guidance is clear that the question is whether a vulnerability is actually exploitable and whether it presents uncontrolled risk to safety, not whether it exists in a component somewhere.

New CVE in SBOMmatched to a componentReachable?mapped on the twinExploitable?verified on devicePatch or evidencefix, or defensible no-fix
Most findings exit at 'not reachable' or 'not exploitable', with the reasoning captured.

The mistake manufacturers make is treating a CVSS base score as a patch trigger. A network-scored 9.8 can be a local 2.4 on your device once TLS blocks the path or the component sits behind a trust boundary the attacker never reaches. Patching all of them is expensive, destabilizing, and, ironically, harder to defend than a well-evidenced no-fix.

The defensible answer is not "we patched everything." It is "here is why this one did not need it."

What the FDA wants is a controlled, documented decision. If a vulnerability is not exploitable in your product, say so, show the reasoning, and monitor it. That is compliance without unnecessary patching.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about when patching is required.

Does every vulnerability in an SBOM require a patch?

No. The FDA's 2016 postmarket guidance is clear that the question is whether a vulnerability is actually exploitable and whether it presents uncontrolled risk to safety, not whether it exists in a component somewhere. Presence in the SBOM starts an assessment. It does not by itself create a patching obligation.

Can a CVSS base score be used as a patch trigger?

No, and treating it as one is the common mistake. A network-scored 9.8 can be a local 2.4 on your device once TLS blocks the path or the component sits behind a trust boundary the attacker never reaches. The base score describes the vulnerability in the abstract, not in your product.

Is patching everything the safest regulatory position?

No. Patching all of them is expensive, destabilizing and, ironically, harder to defend than a well-evidenced no-fix. The defensible answer is not that you patched everything. It is that you can show why a particular vulnerability did not need it.

What does FDA want when a vulnerability is not patched?

A controlled, documented decision. If a vulnerability is not exploitable in your product, say so, show the reasoning and keep monitoring it. That is compliance without unnecessary patching, and it holds up better than a fix applied to make a scanner go quiet.

Where do most vulnerability findings end up?

Most exit at not reachable or not exploitable, with the reasoning captured at the point of decision. Only the remainder needs a code change. That is why the number of CVEs in an SBOM and the number of patches a manufacturer ships are never the same figure.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON