FDA §524B (PATCH Act)

524B asks for a plan. Reviewers want proof.

Since March 2023 every cyber device submission has needed a plan to monitor, identify, and address postmarket vulnerabilities, evidence of secure development, and an SBOM. ELTON discharges the part reviewers probe hardest: cybersecurity vulnerability testing and management, premarket and postmarket, with every disposition evidenced.

The statute

What §524B requires of a cyber device

Section 524B of the FD&C Act applies to any device with software that connects to the internet. The obligations are short to state and hard to operate.

A postmarket vulnerability plan

A plan to monitor, identify, and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time, including coordinated vulnerability disclosure and the procedures behind it. Not a policy on a shelf: a plan you can show operating.

Reasonable assurance, patches on cycle

Processes that provide reasonable assurance the device and related systems are cybersecure, with updates and patches on a justified regular cycle, and out of cycle when a critical vulnerability creates uncontrolled risk.

An SBOM that stays true

A software bill of materials covering commercial, open source, and off-the-shelf components. FDA treats it as a living inventory rather than a submission artifact, so it has to survive contact with your release cadence.

The ELTON mapping

The vulnerability testing and management portion, discharged

Our claim is deliberately exact. ELTON meets FDA premarket (Section 524B) and postmarket cybersecurity vulnerability testing and management requirements. Nothing broader, nothing less.

Model: a twin from your QMS

ELTON builds a digital twin of the device from documentation your quality system already produces. No new documentation burden, no waiting on a lab. The twin is the map every test runs against.

Discover and verify on the real device

Continuous discovery runs across hardware, firmware, software, web, mobile, and network. AI then verifies which findings are exploitable on the running product, so you fix the 1 percent that matter and hold proof for why the other 99 percent do not need fixing.

Evidence for every disposition

Each finding and each dismissal carries its reasoning, scored against the MDDT-recognized CVSS rubric FDA qualified with MITRE and published as VEX in CycloneDX. A reviewer can trace any conclusion back to the test that produced it.

Requirement to capability

Where each 524B obligation lands

The same evidence set serves the premarket submission and the postmarket plan. ELTON evidence has supported 600+ regulatory submissions, so documentation arrives shaped the way reviewers expect to read it.

524B obligation → ELTON capabilityPlan to monitor, identify, addresspostmarket vulnerabilities and exploitsContinuous discovery, verified triagefull stack, driven from the device twinCoordinated vulnerability disclosureprocedures behind the intakeOn-device verification of reportsexploitable, or provably notSBOM: commercial, open source, OTSkept current after clearanceTwin inventory with VEX (CycloneDX)living exploitability status per componentUpdates and patches on a justified cycleout of cycle for critical vulnerabilitiesFindings ranked by proven exploitabilitythe 1 percent first, evidence for the rest
Each 524B obligation maps to a platform capability that produces reviewable evidence.
Premarket

eSTAR without the deficiency loop

Vulnerability testing documentation formatted for eSTAR: methods, coverage, findings, dispositions, and the rationale behind each one. When a reviewer asks why a CVE was left in place, the answer is already in the file, with the test that justified it.

Postmarket

The plan, shown operating

524B's plan has to run for the life of the device. Continuous discovery, verified triage of new CVEs and inbound disclosure reports, and living VEX output give you a plan that is demonstrably in motion, not filed and forgotten.

Get started

Bring verified evidence to your next submission.

Start with one device. We build the twin from documentation you already have, run discovery and verification, and hand your regulatory team dispositions written for review.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo