← All resourcesCybersecurity Standards

Cybersecurity standards that impact the medical device lifecycle

Meeting regulatory expectations means aligning with an ecosystem of international cybersecurity, software, risk management, and quality standards — not just the regulations themselves. Here's the current landscape.

Coverage
Category
StandardYearCoveragePrimary FocusDescription
IEC 81001-5-12021Full lifecycleProduct cybersecurityFoundational standard for health software and software-containing devices.
ANSI/AAMI SW962023Full lifecycleSecurity risk managementSecurity risk management methods aligned with ISO 14971.
AAMI TIR572023Full lifecycleSecurity risk managementPractical guidance linking cybersecurity to patient safety.
AAMI TIR972023Post-marketOperational cybersecurityCovers vulnerability intake, remediation, patching, and communication.
ISO 149712019Full lifecycleRisk managementCybersecurity risks evaluated as hazard sources.
ISO/TR 249712020Full lifecycleRisk management guidanceCompanion guidance document explaining how to apply ISO 14971 in practice.
ISO/IEC 238942023Full lifecycleAI risk managementAdapts ISO 31000 risk management principles to AI-specific risks — robustness, bias, algorithmic transparency, human-AI interaction — relevant for risk assessment of AI-enabled devices.
ISO 310002018OrganizationRisk management principlesOutlines a comprehensive approach to identifying, analyzing, evaluating, treating, monitoring and communicating risks across an organization — the parent framework ISO/IEC 23894 adapts specifically for AI.
ISO/TS 24971-22026Full lifecycleAI/ML risk management guidanceGuidance on applying ISO 14971 to machine-learning-enabled devices — data management, bias, model drift, and continuous learning risks not addressed in ISO 14971 or ISO/TR 24971. Does not cover LLM or generative-AI-enabled devices.
AAMI TIR349712023Full lifecycleAI/ML risk management guidanceThe US/UK-origin guide (also published as BS/AAMI 34971) that ISO/TS 24971-2 was harmonized from — same ML-specific hazards: data bias, overtrust, and adaptive algorithms that change after deployment.
ISO/IEC 5259 (Parts 1-5)2024-2025Full lifecycleAI/ML data qualityDefines data quality terminology, measurable characteristics, management requirements, and a governance framework for the training and validation data behind AI/ML models.
ISO/IEC 81832023Full lifecycleAI data life cycle frameworkBroader than the data-quality focus of ISO/IEC 5259 — governs AI data handling from acquisition through decommissioning across the full system life cycle.
IEC PAS 636212026Full lifecycleAI/ML data managementPublicly Available Specification giving medical device manufacturers a data-lifecycle blueprint for AI/ML training data — suitability, quality, bias mitigation, versioning, and traceability — supporting MDR/IVDR data-governance expectations.
ISO 134852016Full lifecycleQuality management systemStandard for quality management systems in the design and manufacture of medical devices. It outlines specific requirements that help organizations ensure their medical devices meet both customer and regulatory demands for safety and efficacy.
IEC 623042006+A1:2015Full lifecycleSoftware lifecycleMedical-device software lifecycle processes; provides a foundation for integrating cybersecurity into software development, not itself a security standard.
IEC 82304-12016Full lifecycleHealth software safety & securityApplies to the safety and security of health software products designed to operate on general computing platforms and intended to be placed on the market without dedicated hardware, and its primary focus is on the requirements for manufacturers. It covers the entire lifecycle including design, development, validation, installation, maintenance, and disposal of health software products.
NIST CSF 2.02024Organization & productRisk-based frameworkOffers a taxonomy of high-level cybersecurity outcomes that can be used by any organization to better understand, assess, prioritize, and communicate its cybersecurity efforts. Accepted by FDA and healthcare stakeholders.
NIST AI RMF 1.02023Organization & productAI risk-based frameworkVoluntary framework for managing AI risk and promoting trustworthy, responsible AI — the AI sibling to NIST CSF 2.0, relevant for AI-enabled device risk governance.
NIST SP 800-532020Full lifecycleSecurity & privacy controlsProvides a catalog of security and privacy controls for information systems and organizations.
NIST SP 800-302012Full lifecycleRisk assessmentGuide for Conducting Risk Assessments. Complements ISO 14971 methodology.
NIST SP 800-612025Post-marketIncident responseRevision 3 reframes it as a CSF 2.0 community profile for incident response, superseding the original Incident Handling Guide.
NIST SP 800-218 (SSDF)2022Pre-marketSecure software developmentSecure Software Development Framework — practices referenced by FDA guidance for aligning a Secure Product Development Framework (SPDF).
NIST SP 800-40 Rev. 42022Post-marketPatch managementEnterprise patch management planning, referenced for postmarket vulnerability remediation timelines and patching capability.
ISO/IEC 270012022OrganizationInformation security managementGovernance and secure development policies.
ISO/IEC 270022022OrganizationSecurity controlsImplementation guidance for controls.
ISO/IEC 270052022OrganizationInformation security risk managementCompanion guidance to ISO/IEC 27001 for identifying, assessing, and treating information security risks — the enterprise-ISMS counterpart to ISO 14971 for device safety risk.
ISO/IEC 420012023OrganizationAI management systemCertifiable AI governance framework — the AI counterpart to ISO/IEC 27001, covering how an organization manages AI risk, oversight, and lifecycle controls.
ISO 277992025ProvidersSecurity controlsHealth organization-specific guidance, based on ISO/IEC 27002.
ISO/IEC 291472018Post-marketVulnerability disclosureCoordinated disclosure principles.
ISO/IEC 301112019Post-marketVulnerability handlingOperational processes for remediation.
ANSI/NEMA HN 1 (MDS2)2019ProcurementSecurity disclosureStandardized form manufacturers complete to disclose a device's security control features to healthcare delivery organizations.
IEC TS 81001-2-22025Full lifecycleHealth software security disclosureGuidance for implementing, disclosing, and communicating health software and medical device security needs, risks, and controls between manufacturers and healthcare delivery organizations, applied across the software lifecycle — supersedes IEC TR 80001-2-2:2012 and IEC TR 80001-2-8:2016, complements the MDS2 disclosure form above.
ANSI/CAN/UL 2900-2-12023Full lifecycleProduct cybersecurity testingParticular requirements for network-connectable components of healthcare and wellness systems, building on the UL 2900-1 general requirements.
IEEE 2621.2 / UL 2621-22022Full lifecycleConnected diabetes deviceDefines the security functional requirements (protection profile) for connected diabetes devices — insulin pumps, continuous glucose monitors, and their companion controllers/apps — covering authentication, encryption, and secure communication between paired devices. Part 2 of the multi-part IEEE/UL 2621 series; Part 1 covers the security evaluation program and Part 3 covers mobile-device use in diabetes control.
IEC 62443-4-12018Pre-marketSecure product development lifecycleSecure development lifecycle (SDL) requirements for products used in industrial automation and control systems — requirements definition, secure design, secure implementation, verification/validation, defect and patch management, and end-of-life; relevant to connected medical device components built to IACS-adjacent expectations.

Need help mapping standards to your program?

We'll help you decide which standards matter most for your device and markets.

Schedule a Consultation