At the end of June 2026 FDA added a Medical Device Innovation Consortium white paper on penetration-testing validation methods to its cybersecurity page. It follows two FDA-funded MITRE papers from April, one on cyber risk analysis for evolving technologies and one on the pain of normalizing SBOM data.

None of these are guidance. They are the closest FDA gets to saying out loud what good evidence looks like, which makes them scoping hints for the testing and SBOM sections of a 524B submission. The pen-test paper matters because "we did a penetration test" is not a disposition, and a reviewer wants scope, method and validation.

Align your pen-test scoping and your SBOM data quality to these papers before your next submission. It is cheaper than a deficiency letter, and FDA is telling you where it will look.