Not every vulnerability in your SBOM requires a patch. The FDA's 2016 postmarket guidance is clear that the question is whether a vulnerability is actually exploitable and whether it presents uncontrolled risk to safety, not whether it exists in a component somewhere.
The mistake manufacturers make is treating a CVSS base score as a patch trigger. A network-scored 9.8 can be a local 2.4 on your device once TLS blocks the path or the component sits behind a trust boundary the attacker never reaches. Patching all of them is expensive, destabilizing, and, ironically, harder to defend than a well-evidenced no-fix.
The defensible answer is not "we patched everything." It is "here is why this one did not need it."
What the FDA wants is a controlled, documented decision. If a vulnerability is not exploitable in your product, say so, show the reasoning, and monitor it. That is compliance without unnecessary patching.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.