Skip to content

docs(fda): component support metadata and the cyber device evidence pack - #16017

Merged
devGregA merged 3 commits into
DefectDojo:bugfixfrom
devGregA:docs/fda-cyber-device-pack
Sep 21, 2026
Merged

devGregA merged 3 commits into
DefectDojo:bugfixfrom
devGregA:docs/fda-cyber-device-pack

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Description

Documents the FDA cyber device work: the component supplier and support metadata, how imports supply it, the properties the SBOM export emits, and the cyber device profile, lifecycle metrics and evidence pack.

Three changes.

Working with SBOMs gains the supplier and support fields a component now carries, and a section on where those facts come from. What each import format supplies, that unknown is a recorded answer rather than a guess, and the order a per snapshot override, a value on the component, and unknown resolve in. An edit made by hand survives a later import of the same component, and the support source field is what tells a reviewer whether a fact was imported or entered.

Exporting SBOMs and VEX gains the supplier and support properties each format emits, and says plainly that a component whose support level is unknown emits no support property at all. A consumer reading a property named support level should be reading a claim somebody made, not a placeholder.

A new page covers the cyber device profile, the three lifecycle metrics, the assessment and the evidence pack. It describes each of the seven elements in our own words with the statute section cited, gives the table of which controls are evidenced from which data, and names the four that are the manufacturer's own paperwork and are answered by hand.

The new page states plainly that DefectDojo records and reports what the manufacturer supplies, does not assess whether a software bill of materials is complete or accurate, and does not determine whether a submission satisfies the FDA.

Documentation only. No code changes.

Three changes, covering the cyber device work end to end.

The Locations SBOM page gains the supplier and support fields a component now
carries, and a section on where those facts come from: what each import format
supplies, that unknown is a valid recorded answer rather than a guess, and the
order a per-snapshot override, a recorded value and unknown resolve in. An edit
made by hand survives a later import, and the support source field is what tells
a reviewer which case applies.

The SBOM export page gains the supplier and support properties each format emits,
and says plainly that a component with an unknown support level emits no property
at all, because a consumer reading a support level should be reading a claim
somebody made rather than a placeholder.

A new page covers the cyber device profile, the three lifecycle metrics, the
assessment and the evidence pack. It describes each of the seven elements in our
own words with the statute cited, says which nine controls are evidenced from
data and which four are the manufacturer's paperwork, and states plainly that
DefectDojo records and reports what the manufacturer supplies, does not assess
whether a bill of materials is complete or accurate, and does not determine
whether a submission satisfies the FDA.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the docs label Sep 21, 2026
@devGregA devGregA added this to the 3.3.300 milestone Sep 21, 2026
The page sits one level down, so reaching another top-level section takes two
levels up rather than one. The sibling link inside this section is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@devGregA
devGregA enabled auto-merge September 21, 2026 13:41
@devGregA
devGregA added this pull request to the merge queue Sep 21, 2026
@Maffooch Maffooch modified the milestones: 3.3.300, 3.3.200 Sep 21, 2026
Merged via the queue into DefectDojo:bugfix with commit 598b537 Sep 21, 2026
35 of 36 checks passed
@devGregA
devGregA deleted the docs/fda-cyber-device-pack branch September 21, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants