Bill of Materials (BOM)

A Bill of Materials (BOM) is a controlled, structured list of every component, material, subassembly and quantity required to build a medical device. It connects product design with procurement, manufacturing, quality control and regulatory documentation.

In medical-device development, a BOM is more than a purchasing list. It identifies the approved configuration of the product and supports component traceability, change control, supplier management and production consistency.

What Is a Bill of Materials?

A medical-device BOM typically identifies each item by part number, description, revision and required quantity. It may include mechanical parts, electronic components, software-controlled assemblies, adhesives, labels, packaging and manufacturing consumables.

The BOM is generally hierarchical. The finished device appears at the highest level, followed by assemblies, subassemblies and individual components.

For an electronic medical device, for example, the BOM may include the enclosure, display, cables, sensors, battery and Printed Circuit Board Assembly (PCBA), followed by the components used within each assembly.

Why the BOM Matters in Medical Devices

An inaccurate BOM can lead to the wrong component being installed in a device. An uncontrolled resistor, adhesive, sensor or polymer substitution may affect electrical safety, performance, biocompatibility, sterilization or service life.

The BOM therefore functions as a controlled design output. It helps ensure that every production unit is built using approved components and specifications.

During an audit, records for a finished device may be traced back to the released BOM, purchasing information and supplier documentation. Mismatched revisions or unidentified substitutions can indicate weaknesses in design control and manufacturing traceability.

The BOM also affects:

  • Product cost and profitability
  • Material availability and production scheduling
  • Supplier and component traceability
  • Regulatory compliance
  • Design transfer and manufacturing readiness
  • Component obsolescence and supply continuity
  • Product maintenance and field service

What Information Should a Medical Device BOM Include?

A complete BOM may contain:

  • Internal part number
  • Component or material description
  • Revision level
  • Quantity and unit of measure
  • Assembly level
  • Controlled drawing or specification reference
  • Manufacturer and manufacturer part number
  • Approved supplier
  • Approved alternate parts
  • Reference designator for electronic components
  • Material grade and finish
  • Lead time and lifecycle status
  • RoHS, REACH and material-compliance information
  • Critical-component designation
  • Notes concerning handling, storage or sterilization

The exact fields depend on the device’s complexity and the organization’s quality-management procedures.

Engineering BOM Versus Manufacturing BOM

An Engineering Bill of Materials, or eBOM, represents the product as designed. It is normally organized according to the engineering structure and links components to drawings, specifications and design outputs.

A Manufacturing Bill of Materials, or mBOM, represents the product as it is built. It may include packaging, labels, consumables, intermediate assemblies and other items required during production.

Both views must describe the same approved device configuration. Differences between the eBOM and mBOM should be reviewed and controlled, especially when information is transferred from medical device design and engineering into production.

How a BOM Is Developed and Released

1. Create the Initial BOM

The BOM begins during product design as components and materials are selected. Early versions may contain provisional parts, but unresolved placeholders should be closed before design transfer.

2. Review Components and Suppliers

Each item should be assessed for technical suitability, availability, quality, regulatory compliance and lifecycle risk. Critical items may require qualified alternate suppliers or substitute components.

3. Verify the Product Configuration

BOM components must align with drawings, specifications, software versions and assembly documentation. The finished device should then be evaluated through the planned verification and validation activities.

4. Approve and Release the BOM

Engineering, manufacturing, quality, supply-chain and regulatory representatives should review the BOM before release. Once approved, it becomes a controlled record used for purchasing and manufacturing.

5. Maintain the BOM Through Change Control

Released BOMs should not be edited informally. A proposed modification begins with an Engineering Change Request (ECR), which records the reason for the change and initiates an impact assessment.

When approved, an Engineering Change Order (ECO) authorizes implementation and identifies the affected parts, drawings, procedures and inventory.

Managing BOM Changes

A component substitution may affect more than purchasing. Before implementation, the manufacturer should consider its impact on:

  • Device safety and performance
  • Risk controls
  • Biocompatibility
  • Electrical safety and EMC
  • Software compatibility
  • Manufacturing processes
  • Verification or validation evidence
  • Product labelling
  • Regulatory approvals
  • Existing inventory and field-service parts

The impact assessment should determine whether additional testing or a regulatory submission is required.

The effective date and applicable serial, lot or batch numbers should also be documented so the organization can identify which device units contain each configuration.

BOM and Obsolescence Management

Medical devices may remain in production or service longer than many commercial components remain available. Electronic parts, displays, sensors, polymers and software dependencies may become unavailable during the device’s lifecycle.

Proactive obsolescence management monitors component status, supplier notifications and end-of-life announcements. Possible responses include qualifying an alternate, making a last-time purchase or redesigning part of the device.

Linking lifecycle monitoring to the BOM allows the organization to identify every product affected by an obsolete or changed component.

Hardware BOM Versus Software BOM

A hardware BOM lists the physical parts and materials used in a device. A Software Bill of Materials, or SBOM, identifies software components, third-party libraries, versions and dependencies.

An SBOM supports cybersecurity monitoring and software maintenance. When a vulnerability is identified in a third-party component, the manufacturer can use the SBOM to determine which products and versions are affected.

Devices containing embedded systems may therefore require coordinated control of hardware, firmware and software configurations.

Common BOM Management Problems

Common issues include:

  • Inconsistent eBOM and mBOM revisions
  • Duplicate or unclear part numbers
  • Unresolved “TBD” components
  • Unapproved supplier substitutions
  • Missing material or compliance information
  • Single-source critical components
  • Poor linkage between parts and specifications
  • Failure to assess changes across affected documents
  • Continued production using an obsolete revision
  • BOMs maintained in uncontrolled spreadsheets

Using a controlled PLM or ERP environment helps establish approval workflows, access controls and a single source of released product information.

How SJML Supports BOM Management

SJML manages BOM development and control across design transfer, sourcing, manufacturing and product lifecycle management.

Its teams support component selection, design-for-manufacturing reviews, supplier qualification, alternate sourcing, cost optimization and obsolescence management. Through its medical-device contract manufacturing services, SJML also maintains component traceability and alignment between engineering and production records.

Contact SJML to discuss BOM development, design transfer or lifecycle support for your medical device.

Frequently asked questions

What is the difference between an eBOM and an mBOM?

An engineering BOM (eBOM) lists parts as the design defines them, grouped by function and tied to drawings. A manufacturing BOM (mBOM) lists what the factory actually consumes to build the device, including packaging, consumables, and assembly steps. Both describe the same product, but mismatches between them cause build errors, so teams keep the two synchronized through change control.

Is a BOM a controlled document under ISO 13485?

Yes. Under ISO 13485 and FDA 21 CFR Part 820, the BOM is part of design outputs and the Device Master Record, so it must be reviewed, approved, version-controlled, and changed only through documented change control. Auditors trace finished devices back to the released BOM, which makes its accuracy and revision history part of your compliance evidence.

What is an SBOM and how does it relate to a hardware BOM?

A software bill of materials (SBOM) lists the software components, libraries, and dependencies inside a device. It complements the hardware BOM and supports IEC 62304 lifecycle management and cybersecurity. Regulators increasingly expect an SBOM for connected and software-containing devices, so that vulnerabilities in third-party code can be tracked and patched over the product’s life.

How does BOM management affect medical device cost?

The BOM drives most of a device’s direct cost and much of its supply risk. Accurate quantities prevent over-purchasing, qualified alternates avoid line stoppages, and early obsolescence tracking prevents costly redesigns. Value engineering on the BOM, done without compromising verified specifications, is one of the main levers for reducing total cost of ownership.


Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries