CYBERSECURITY

Enbio: FDA 510(k) Cybersecurity Documentation

For Enbio Group AG, we produced the full set of cybersecurity documents needed for the Enbio PRO autoclave - the exact proof a first US FDA 510(k) submission now asks for. From zero into a complete, ready-to-send package.

READ MORE
ISO 13485:2016Top Medical Software Developers - ClutchISO 9001:2015

About the client

COMPANY NAME

Enbio Group AG

LOCATION

Switzerland & Poland

SERVICES

Medical Device Cybersecurity | FDA 510(k) Regulatory Documentation | IEC 62304

Enbio Group AG designs and makes small, fast Class B autoclaves for the medical, dental, and beauty sectors. Its devices - including the Enbio S and the Enbio PRO - run sterilization cycles in minutes, not the tens of minutes common in the category. The Enbio PRO runs embedded control firmware on an microcontroller, which handles all sterilization, monitoring, and communication functions of the device.

The challenge

Enbio already made a modern device, and had a bigger plan: a new generation of autoclaves. But a more urgent problem sat in front of that plan - the company's first submission to the US market.

Everything for the 510(k) was ready except one thing: cybersecurity documentation was no longer optional.

  • According to Section 524B of the FD&C Act, any "cyber device" submission must include cybersecurity proof. Since October 1, 2023, the FDA rejects submissions that are missing it.
  • A hard, immediate deadline. The documents had to be produced to a standard the FDA would accept, on the timeline of a submission that was already moving.

What we delivered

Expertise, and time saved

As the most important outcome, Somco's consultant not only provided the expertise, but also freed up our customer's time - all at short notice, in just two weeks.

A machine-readable Software Bill of Materials

A CycloneDX SBOM listing the Enbio PRO firmware and every component it depends on, in the form Section 524B asks for.

Cybersecurity management plan

A plan setting out how vulnerabilities are watched for, found, and fixed over the device's life - the ongoing side of the 524B rule.

A full vulnerability review, easy to follow

A register and log recording which components were checked, what was found, and how each item was handled.

A plain account of remaining risk

A document naming the risks that could not be fully removed, with the reasoning behind each.

A submission that could go in

We provided whole package Enbio required to finish 510(k) submission and get FDA acceptance. Without push backs.

Who did the work

The work was led personally by Lukas Kosiński, one of Somco Software's principal consultants for cybersecurity and regulatory documentation and a three-time Qt Champion.

He works hands-on with medical device teams on the documents regulators expect - SBOMs, cybersecurity management plans, and vulnerability reviews in line with IEC 62304 and ISO 13485. His clients on this kind of work include names such as Bio-Rad Laboratories .

Talk to us about your project

Adam Sowa

Adam Sowa

Chief Technology Officer

Our team can help you choose the right Renesas hardware and push forward your project or  demo

The administrator of the personal data is Somco Software sp. z o.o., 13 Gen. Ottokara Brzoza-Brzeziny St., 05-220 Zielonka, KRS: 855688. The personal data are processed in order to answer the question contained in the contact form. More information, including a description of data subjects rights, is available in the information clause .