Since March 2023 every cyber device submission has needed a plan to monitor, identify, and address postmarket vulnerabilities, evidence of secure development, and an SBOM. ELTON discharges the part reviewers probe hardest: cybersecurity vulnerability testing and management, premarket and postmarket, with every disposition evidenced.
Section 524B of the FD&C Act applies to any device with software that connects to the internet. The obligations are short to state and hard to operate.
A plan to monitor, identify, and address postmarket cybersecurity vulnerabilities and exploits in a reasonable time, including coordinated vulnerability disclosure and the procedures behind it. Not a policy on a shelf: a plan you can show operating.
Processes that provide reasonable assurance the device and related systems are cybersecure, with updates and patches on a justified regular cycle, and out of cycle when a critical vulnerability creates uncontrolled risk.
A software bill of materials covering commercial, open source, and off-the-shelf components. FDA treats it as a living inventory rather than a submission artifact, so it has to survive contact with your release cadence.
Our claim is deliberately exact. ELTON meets FDA premarket (Section 524B) and postmarket cybersecurity vulnerability testing and management requirements. Nothing broader, nothing less.
ELTON builds a digital twin of the device from documentation your quality system already produces. No new documentation burden, no waiting on a lab. The twin is the map every test runs against.
Continuous discovery runs across hardware, firmware, software, web, mobile, and network. AI then verifies which findings are exploitable on the running product, so you fix the 1 percent that matter and hold proof for why the other 99 percent do not need fixing.
Each finding and each dismissal carries its reasoning, scored against the MDDT-recognized CVSS rubric FDA qualified with MITRE and published as VEX in CycloneDX. A reviewer can trace any conclusion back to the test that produced it.
The same evidence set serves the premarket submission and the postmarket plan. ELTON evidence has supported 600+ regulatory submissions, so documentation arrives shaped the way reviewers expect to read it.
Vulnerability testing documentation formatted for eSTAR: methods, coverage, findings, dispositions, and the rationale behind each one. When a reviewer asks why a CVE was left in place, the answer is already in the file, with the test that justified it.
524B's plan has to run for the life of the device. Continuous discovery, verified triage of new CVEs and inbound disclosure reports, and living VEX output give you a plan that is demonstrably in motion, not filed and forgotten.
Start with one device. We build the twin from documentation you already have, run discovery and verification, and hand your regulatory team dispositions written for review.